Say the mnemonic still opens a vault its unlocker cannot (closes #47)
check / check (push) Failing after 2s

When a vault cannot be opened through its current unlocker, the error now
ends by naming the vault, saying that it still opens with its mnemonic,
and that 'secret unlocker add passphrase' run with SB_SECRET_MNEMONIC set
gives it a new unlocker, after 'secret vault select' when it is not the
current vault. Only when the vault metadata records the key the mnemonic
derives, and not when the passphrase could not be read. 'secret encrypt'
and 'secret decrypt' read the key secret through vault.GetSecret, and
Secret.GetValue with its helpers is removed. An unreadable 'current'
file's error names 'secret version list' and 'secret version promote'.
Causes stay wrapped.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:33:38 +00:00
parent 0e6a4afb71
commit c7d2e28f48
8 changed files with 445 additions and 264 deletions
+18 -2
View File
@@ -18,6 +18,24 @@ https://git.eeqj.de/sneak/secret/milestone/12
# Completed Steps
- 2026-10-04: When a vault cannot be opened through its current unlocker,
because a file the unlocker needs is missing or damaged, its keychain item
or Secure Enclave key is gone, or the passphrase is wrong, the error now
ends by naming the vault, saying that it still opens with its mnemonic,
and that `secret unlocker add passphrase`, run with `SB_SECRET_MNEMONIC`
set to it, gives the vault a new unlocker; for a vault that is not the
current one, as in `secret move` between vaults, it says to run
`secret vault select` first (https://git.eeqj.de/sneak/secret/issues/47).
Before, it ended with the bare cause. The advice is given only when the
vault metadata records the key the mnemonic derives, so not for a vault
created without a mnemonic, and not when the passphrase could not be read
at all. `secret vault import` is not named: it refuses a vault that has a
long-term key. `secret encrypt` and `secret decrypt` now read the key
secret through `vault.GetSecret`, as `secret get` does, so they give the
same advice; `Secret.GetValue`, the other way to get the long-term key, is
removed. When a secret's `current` file cannot be read, the error says
that `secret version list` lists its versions and `secret version promote`
makes one current. The causes stay wrapped.
- 2026-10-04: An unlocker's ID is the name of its directory in `unlockers.d`,
so no two unlockers of a vault share one
(https://git.eeqj.de/sneak/secret/issues/98). Before, a keychain or Secure
@@ -406,8 +424,6 @@ https://git.eeqj.de/sneak/secret/milestone/12
(`secret.IdentityToLockedBuffer` overwrites only the string itself).
- Medium priority:
- Standardize error messages; stop leaking internals.
- Graceful handling of corrupted or missing key files with recovery
suggestions.
- Split oversized CLI functions.
- Cleanups: read statedir from environment or default instead of
passing it around.