Left open by #75 (its review, #101); TODO.md lists it as the remaining crash-safety exception.
Problem
secret init and secret vault create write the vault directory, its metadata and its unlocker one after another. A command killed after the passphrase prompt but before the unlocker is written leaves a vault with no unlocker, which vault create has already made the current vault. Running the command again refuses with "vault NAME already exists" (#82), and vault rm refuses the last vault, so the user is left with a vault that opens only through secret unlocker add passphrase with SB_SECRET_MNEMONIC set.
Definition of done
A vault is created complete or not at all: build the vault directory with its metadata, unlocker and longterm.age in a temporary directory (secret.WriteDir or the temp-directory helpers) and rename it into vaults.d only when complete; make it current only after that.
A test simulates a stop at each step of init and vault create and shows either no vault or a complete, openable one, and that the command can then be run again.
The exception is removed from TODO.md.
Model: opus-5-5
Left open by https://git.eeqj.de/sneak/secret/issues/75 (its review, https://git.eeqj.de/sneak/secret/pulls/101); `TODO.md` lists it as the remaining crash-safety exception.
## Problem
`secret init` and `secret vault create` write the vault directory, its metadata and its unlocker one after another. A command killed after the passphrase prompt but before the unlocker is written leaves a vault with no unlocker, which `vault create` has already made the current vault. Running the command again refuses with "vault NAME already exists" (https://git.eeqj.de/sneak/secret/pulls/82), and `vault rm` refuses the last vault, so the user is left with a vault that opens only through `secret unlocker add passphrase` with `SB_SECRET_MNEMONIC` set.
## Definition of done
- A vault is created complete or not at all: build the vault directory with its metadata, unlocker and `longterm.age` in a temporary directory (`secret.WriteDir` or the temp-directory helpers) and rename it into `vaults.d` only when complete; make it current only after that.
- A test simulates a stop at each step of `init` and `vault create` and shows either no vault or a complete, openable one, and that the command can then be run again.
- The exception is removed from `TODO.md`.
Model: opus-5-5
Built in #108: vault.CreateVault now writes the whole vault, its passphrase unlocker and longterm.age included, into a temporary directory, renames it into vaults.d when complete, and only then makes it current; init and vault create call it once. A kill between the rename and the selection leaves a complete vault that is not current, which secret vault select fixes.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/secret/pulls/108: `vault.CreateVault` now writes the whole vault, its passphrase unlocker and `longterm.age` included, into a temporary directory, renames it into `vaults.d` when complete, and only then makes it current; `init` and `vault create` call it once. A kill between the rename and the selection leaves a complete vault that is not current, which `secret vault select` fixes.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Left open by #75 (its review, #101);
TODO.mdlists it as the remaining crash-safety exception.Problem
secret initandsecret vault createwrite the vault directory, its metadata and its unlocker one after another. A command killed after the passphrase prompt but before the unlocker is written leaves a vault with no unlocker, whichvault createhas already made the current vault. Running the command again refuses with "vault NAME already exists" (#82), andvault rmrefuses the last vault, so the user is left with a vault that opens only throughsecret unlocker add passphrasewithSB_SECRET_MNEMONICset.Definition of done
longterm.agein a temporary directory (secret.WriteDiror the temp-directory helpers) and rename it intovaults.donly when complete; make it current only after that.initandvault createand shows either no vault or a complete, openable one, and that the command can then be run again.TODO.md.Model: opus-5-5
clawbot referenced this issue2026-10-04 19:27:19 +02:00
Built in #108:
vault.CreateVaultnow writes the whole vault, its passphrase unlocker andlongterm.ageincluded, into a temporary directory, renames it intovaults.dwhen complete, and only then makes it current;initandvault createcall it once. A kill between the rename and the selection leaves a complete vault that is not current, whichsecret vault selectfixes.Model: opus-5-5