Delete .tmp- leftovers when the next command takes the lock (closes #75)
check / check (push) Failing after 3s

A command killed part-way could leave a temporary file or directory of
secret.WriteFileAtomic or secret.TempDirFor, encrypted keys included,
for good. LockStateDir now deletes them once it holds the lock, looking
only in the directories those helpers make them in (the state
directory, each vault, each secret, each version) and only at names
that start with "." and hold ".tmp-". A vault may be named ".tmp-1", so
vaults.d and the other listed directories are not searched. Commands
that only read take no lock and delete nothing. A test shows that
`unlocker remove` removes an unlocker directory with no metadata file.

Model: opus-5-5
This commit is contained in:
2026-10-04 15:14:13 +00:00
parent 7e4e0f7806
commit ff721a87e6
5 changed files with 221 additions and 16 deletions
+15 -9
View File
@@ -25,6 +25,17 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-04: The next command that takes the state directory lock deletes
what commands killed part-way left under a `.tmp-` name
(https://git.eeqj.de/sneak/secret/issues/75): the temporary directories
of `secret.TempDirFor` and the temporary files of
`secret.WriteFileAtomic`, in the state directory, each vault, each secret
and each version, the only directories those make them in. Before, they
stayed, encrypted keys included, until deleted by hand. A command that
only reads takes no lock and deletes nothing. A failure to delete is
warned about and the command goes on. An unlocker directory with no
metadata file was already removed by `secret unlocker remove` given its
directory name; a test now shows it.
- 2026-10-04: A crash while an unlocker is being replaced no longer leaves a
current unlocker that cannot open the vault
(https://git.eeqj.de/sneak/secret/issues/71). Every new unlocker gets a
@@ -188,15 +199,10 @@ Bring the repo into policy compliance in one commit:
cross-vault copies are built in a temporary directory and renamed
into place, and removals rename out of the way first, so a version
or secret is never half-added and never half-removed. An
interrupted command can still leave:
- from `init` or `vault create` killed after the passphrase prompt
but before the unlocker is written, a vault with no unlocker,
which `vault create` has already made the current vault;
- data under a `.tmp-` name in the state directory: a secret,
version or unlocker being added, or the secret, version, unlocker
or vault being removed, encrypted keys included. Nothing deletes
it; it must be deleted by hand
(https://git.eeqj.de/sneak/secret/issues/75).
interrupted command can still leave, from `init` or `vault create`
killed after the passphrase prompt but before the unlocker is
written, a vault with no unlocker, which `vault create` has already
made the current vault.
- 2026-10-03: The checks run before changing a vault now stop with an
error naming the path and cause when they cannot read what they
inspect, instead of reading the failure as "nothing there": the