init or vault create killed mid-way leaves a vault with no unlocker that cannot be created again #105

Closed
opened 2026-10-04 19:08:08 +02:00 by clawbot · 1 comment
Collaborator

Left open by #75 (its review, #101); TODO.md lists it as the remaining crash-safety exception.

Problem

secret init and secret vault create write the vault directory, its metadata and its unlocker one after another. A command killed after the passphrase prompt but before the unlocker is written leaves a vault with no unlocker, which vault create has already made the current vault. Running the command again refuses with "vault NAME already exists" (#82), and vault rm refuses the last vault, so the user is left with a vault that opens only through secret unlocker add passphrase with SB_SECRET_MNEMONIC set.

Definition of done

  • A vault is created complete or not at all: build the vault directory with its metadata, unlocker and longterm.age in a temporary directory (secret.WriteDir or the temp-directory helpers) and rename it into vaults.d only when complete; make it current only after that.
  • A test simulates a stop at each step of init and vault create and shows either no vault or a complete, openable one, and that the command can then be run again.
  • The exception is removed from TODO.md.

Model: opus-5-5

Left open by https://git.eeqj.de/sneak/secret/issues/75 (its review, https://git.eeqj.de/sneak/secret/pulls/101); `TODO.md` lists it as the remaining crash-safety exception. ## Problem `secret init` and `secret vault create` write the vault directory, its metadata and its unlocker one after another. A command killed after the passphrase prompt but before the unlocker is written leaves a vault with no unlocker, which `vault create` has already made the current vault. Running the command again refuses with "vault NAME already exists" (https://git.eeqj.de/sneak/secret/pulls/82), and `vault rm` refuses the last vault, so the user is left with a vault that opens only through `secret unlocker add passphrase` with `SB_SECRET_MNEMONIC` set. ## Definition of done - A vault is created complete or not at all: build the vault directory with its metadata, unlocker and `longterm.age` in a temporary directory (`secret.WriteDir` or the temp-directory helpers) and rename it into `vaults.d` only when complete; make it current only after that. - A test simulates a stop at each step of `init` and `vault create` and shows either no vault or a complete, openable one, and that the command can then be run again. - The exception is removed from `TODO.md`. Model: opus-5-5
Author
Collaborator

Built in #108: vault.CreateVault now writes the whole vault, its passphrase unlocker and longterm.age included, into a temporary directory, renames it into vaults.d when complete, and only then makes it current; init and vault create call it once. A kill between the rename and the selection leaves a complete vault that is not current, which secret vault select fixes.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/secret/pulls/108: `vault.CreateVault` now writes the whole vault, its passphrase unlocker and `longterm.age` included, into a temporary directory, renames it into `vaults.d` when complete, and only then makes it current; `init` and `vault create` call it once. A kill between the rename and the selection leaves a complete vault that is not current, which `secret vault select` fixes. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#105