Delete .tmp- leftovers when the next command takes the lock (closes #75)
check / check (push) Failing after 3s
check / check (push) Failing after 3s
A command killed part-way could leave a temporary file or directory of secret.WriteFileAtomic or secret.TempDirFor, encrypted keys included, for good. LockStateDir now deletes them once it holds the lock, looking only in the directories those helpers make them in (the state directory, each vault, each secret, each version) and only at names that start with "." and hold ".tmp-". A vault may be named ".tmp-1", so vaults.d and the other listed directories are not searched. Commands that only read take no lock and delete nothing. A test shows that `unlocker remove` removes an unlocker directory with no metadata file. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,17 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: The next command that takes the state directory lock deletes
|
||||
what commands killed part-way left under a `.tmp-` name
|
||||
(https://git.eeqj.de/sneak/secret/issues/75): the temporary directories
|
||||
of `secret.TempDirFor` and the temporary files of
|
||||
`secret.WriteFileAtomic`, in the state directory, each vault, each secret
|
||||
and each version, the only directories those make them in. Before, they
|
||||
stayed, encrypted keys included, until deleted by hand. A command that
|
||||
only reads takes no lock and deletes nothing. A failure to delete is
|
||||
warned about and the command goes on. An unlocker directory with no
|
||||
metadata file was already removed by `secret unlocker remove` given its
|
||||
directory name; a test now shows it.
|
||||
- 2026-10-04: A crash while an unlocker is being replaced no longer leaves a
|
||||
current unlocker that cannot open the vault
|
||||
(https://git.eeqj.de/sneak/secret/issues/71). Every new unlocker gets a
|
||||
@@ -188,15 +199,10 @@ Bring the repo into policy compliance in one commit:
|
||||
cross-vault copies are built in a temporary directory and renamed
|
||||
into place, and removals rename out of the way first, so a version
|
||||
or secret is never half-added and never half-removed. An
|
||||
interrupted command can still leave:
|
||||
- from `init` or `vault create` killed after the passphrase prompt
|
||||
but before the unlocker is written, a vault with no unlocker,
|
||||
which `vault create` has already made the current vault;
|
||||
- data under a `.tmp-` name in the state directory: a secret,
|
||||
version or unlocker being added, or the secret, version, unlocker
|
||||
or vault being removed, encrypted keys included. Nothing deletes
|
||||
it; it must be deleted by hand
|
||||
(https://git.eeqj.de/sneak/secret/issues/75).
|
||||
interrupted command can still leave, from `init` or `vault create`
|
||||
killed after the passphrase prompt but before the unlocker is
|
||||
written, a vault with no unlocker, which `vault create` has already
|
||||
made the current vault.
|
||||
- 2026-10-03: The checks run before changing a vault now stop with an
|
||||
error naming the path and cause when they cannot read what they
|
||||
inspect, instead of reading the failure as "nothing there": the
|
||||
|
||||
Reference in New Issue
Block a user