Lock the state directory and write vault files atomically (closes #34)
check / check (push) Successful in 48s
check / check (push) Successful in 48s
Each command that changes the state directory holds one lock: flock(2) on `lock` in the state directory, dropped by the kernel if the process dies, or a process-wide mutex on the in-memory test filesystem. It covers the state directory, not each vault, because `currentvault`, `vault create` and cross-vault moves span vaults, and a lock file in a vault would be deleted by `vault remove` under a waiting command. Serializing changes across vaults costs a command-line tool nothing. Files go through `secret.WriteFileAtomic`; versions, new secrets and cross-vault copies are built in a temporary directory and renamed into place; removals rename out of the way first. Model: opus-5-5
This commit is contained in:
@@ -90,4 +90,10 @@ func TestAddSecretCleansUpOnFailure(t *testing.T) {
|
||||
secretDir := filepath.Join(vaultDir, "secrets.d", testSecretName)
|
||||
exists, _ := afero.DirExists(fs, secretDir)
|
||||
assert.False(t, exists, "Secret directory should not exist after failed AddSecret")
|
||||
|
||||
// Nor is the temporary directory the secret was assembled in left behind
|
||||
entries, err := afero.ReadDir(fs, vaultDir)
|
||||
require.NoError(t, err)
|
||||
require.Len(t, entries, 1)
|
||||
assert.Equal(t, "pub.age", entries[0].Name())
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user