README calls the current-version and current-vault files symlinks and version metadata unencrypted #102

Closed
opened 2026-10-04 17:51:54 +02:00 by clawbot · 1 comment
Collaborator

Found while restructuring the README for #46, in sections that issue does not cover. The same two facts were corrected in the README's Design section there.

  • Storage Architecture's directory tree shows current -> versions/... and currentvault -> vaults.d/default as symbolic links. Both are plain files holding a name, written with secret.WriteFileAtomic by secret.SetCurrentVersion and vault.SelectVault.
  • The same tree lists a version's metadata.json as unencrypted metadata. The file is metadata.age, encrypted to the version's public key (writeEncryptedMetadata in internal/secret/version.go).
  • secret version promote is said to work "by updating the symlink"; it rewrites the current file.
  • Technical Details, File Formats: "Metadata: Unencrypted JSON" holds for vault-metadata.json and unlocker-metadata.json, not for version metadata.
  • Development, Testing: go test -tags=integration -v ./internal/cli is labelled integration tests, but no file has an integration build tag, so it runs the ordinary tests. Both raw go test lines bypass make test.

Definition of done: each of these README sentences matches the code. Docs only.

Model: opus-5-5

Found while restructuring the README for https://git.eeqj.de/sneak/secret/issues/46, in sections that issue does not cover. The same two facts were corrected in the README's Design section there. - Storage Architecture's directory tree shows `current -> versions/...` and `currentvault -> vaults.d/default` as symbolic links. Both are plain files holding a name, written with `secret.WriteFileAtomic` by `secret.SetCurrentVersion` and `vault.SelectVault`. - The same tree lists a version's `metadata.json` as unencrypted metadata. The file is `metadata.age`, encrypted to the version's public key (`writeEncryptedMetadata` in `internal/secret/version.go`). - `secret version promote` is said to work "by updating the symlink"; it rewrites the `current` file. - Technical Details, File Formats: "Metadata: Unencrypted JSON" holds for `vault-metadata.json` and `unlocker-metadata.json`, not for version metadata. - Development, Testing: `go test -tags=integration -v ./internal/cli` is labelled integration tests, but no file has an `integration` build tag, so it runs the ordinary tests. Both raw `go test` lines bypass `make test`. Definition of done: each of these README sentences matches the code. Docs only. Model: opus-5-5
Author
Collaborator

#107 corrects the five points above, and the other false sentences in the same sections: the state directory's location, Touch ID claims for the keychain and Secure Enclave unlockers, the forward secrecy claim for per-version keys, pub.age and the vault metadata fields.

Model: opus-5-5

https://git.eeqj.de/sneak/secret/pulls/107 corrects the five points above, and the other false sentences in the same sections: the state directory's location, Touch ID claims for the keychain and Secure Enclave unlockers, the forward secrecy claim for per-version keys, `pub.age` and the vault metadata fields. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#102