Leave no partial unlocker directory when adding an unlocker fails (closes #48)
check / check (push) Failing after 3s

CreatePGPUnlocker resolved the GPG key's fingerprint, and the keychain
unlocker got the long-term key, only after writing part of the unlocker,
so a failure there left a directory with no metadata. Both now do every
step that can fail before writing anything. All four unlocker types
write their files through the new secret.WriteDir, which builds a new
directory in a temporary directory, renames it into place when complete
and removes it on a failure. A directory that already exists, as when an
unlocker replaces one of the same name, is written in place and never
removed.

Model: opus-5-5
This commit is contained in:
2026-10-04 08:46:53 +00:00
parent 00713b8677
commit d2835cb1d4
8 changed files with 442 additions and 210 deletions
+14 -7
View File
@@ -25,6 +25,16 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-04: A failed unlocker add no longer leaves a partial unlocker
directory (https://git.eeqj.de/sneak/secret/issues/48).
`CreatePGPUnlocker` resolves the GPG key's fingerprint, and it and
`CreateKeychainUnlocker` get the long-term key and encrypt everything,
before writing anything. All four unlocker types write their files
through `secret.WriteDir`: a new unlocker is built in a temporary
directory, renamed into place when complete and removed on a failure.
One added under the directory name of an existing unlocker is still
written into that directory in place
(https://git.eeqj.de/sneak/secret/issues/71).
- 2026-10-04: The `Makefile` no longer sets `DOCKER_HOST`, so its docker
targets use the local docker daemon, or whatever `DOCKER_HOST` the
environment sets. `make build` calls the new `script/build`, which
@@ -103,13 +113,10 @@ Bring the repo into policy compliance in one commit:
- from `init` or `vault create` killed after the passphrase prompt
but before the unlocker is written, a vault with no unlocker,
which `vault create` has already made the current vault;
- from an unlocker add stopped before its metadata is written, a
directory that `unlocker list` warns about and `unlocker rm`
cannot remove;
- data under a `.tmp-` name in the state directory: a secret or
version being added, or the secret, version, unlocker or vault
being removed, encrypted keys included. Nothing deletes it; it
must be deleted by hand
- data under a `.tmp-` name in the state directory: a secret,
version or unlocker being added, or the secret, version, unlocker
or vault being removed, encrypted keys included. Nothing deletes
it; it must be deleted by hand
(https://git.eeqj.de/sneak/secret/issues/75).
- 2026-10-03: The checks run before changing a vault now stop with an
error naming the path and cause when they cannot read what they