Read secret environment variables once per command, then unset them (closes #60)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
init and vault create put the mnemonic into the process environment for vault.CreateVault to read back, so every program they ran, gpg included, inherited it, and SB_SECRET_MNEMONIC and SB_UNLOCK_PASSPHRASE were read at 13 places and never unset. Each command that may need them now reads both once, in its RunE, into locked buffers on the CLI Instance, and unsets them at once. The buffers are passed down: vault.CreateVault takes the mnemonic, a Vault carries Mnemonic and UnlockPassphrase, and the PGP, keychain and Secure Enclave unlocker constructors take both; CreatePGPUnlocker sets them on the vault it loads through SetMnemonic and SetUnlockPassphrase, new in VaultInterface. README warns against both variables. Model: opus-5-5
This commit was merged in pull request #94.
This commit is contained in:
@@ -286,7 +286,7 @@ func TestSecretManagerIntegration(t *testing.T) {
|
||||
// Test 25: Concurrent operations
|
||||
// Purpose: Test multiple simultaneous operations
|
||||
// Expected: Proper locking/synchronization, no corruption
|
||||
test25ConcurrentOperations(t, testMnemonic, runSecret, runSecretWithEnv)
|
||||
test25ConcurrentOperations(t, tempDir, secretPath, testMnemonic, runSecret)
|
||||
|
||||
// Test 26: Large secret values
|
||||
// Purpose: Test with large secret values (e.g., certificates)
|
||||
@@ -2009,28 +2009,35 @@ func test24EnvironmentVariables(t *testing.T, tempDir, secretPath, testMnemonic,
|
||||
assert.Equal(t, "env-test-value", strings.TrimSpace(string(cmdOutput2)))
|
||||
}
|
||||
|
||||
func test25ConcurrentOperations(t *testing.T, testMnemonic string, runSecret func(...string) (string, error), runSecretWithEnv func(map[string]string, ...string) (string, error)) {
|
||||
func test25ConcurrentOperations(t *testing.T, tempDir, secretPath, testMnemonic string, runSecret func(...string) (string, error)) {
|
||||
t.Helper()
|
||||
|
||||
// Make sure we're in default vault
|
||||
_, err := runSecret("vault", "select", "default")
|
||||
require.NoError(t, err, "vault select should succeed")
|
||||
|
||||
// Run multiple concurrent reads
|
||||
// Run multiple concurrent reads, as separate processes: within one
|
||||
// process the first command to read the mnemonic would unset it for
|
||||
// the others
|
||||
const numReaders = 5
|
||||
|
||||
errCh := make(chan error, numReaders)
|
||||
|
||||
for i := range numReaders {
|
||||
go func(id int) {
|
||||
output, err := runSecretWithEnv(map[string]string{
|
||||
secret.EnvMnemonic: testMnemonic,
|
||||
}, "get", "database/password")
|
||||
cmd := exec.CommandContext(t.Context(), secretPath, "get", "database/password")
|
||||
cmd.Env = []string{
|
||||
secret.EnvStateDir + "=" + tempDir,
|
||||
secret.EnvMnemonic + "=" + testMnemonic,
|
||||
"PATH=" + os.Getenv("PATH"),
|
||||
"HOME=" + os.Getenv("HOME"),
|
||||
}
|
||||
output, err := cmd.Output()
|
||||
|
||||
switch {
|
||||
case err != nil:
|
||||
errCh <- fmt.Errorf("reader %d failed: %w", id, err)
|
||||
case strings.TrimSpace(output) == "":
|
||||
case strings.TrimSpace(string(output)) == "":
|
||||
errCh <- fmt.Errorf("%w: reader %d", errEmptyValue, id)
|
||||
default:
|
||||
errCh <- nil
|
||||
|
||||
Reference in New Issue
Block a user