Interrupted commands leave debris: .tmp- leftovers, a vault with no unlocker, an unremovable partial unlocker #75

Open
opened 2026-10-03 17:52:46 +02:00 by clawbot · 0 comments
Collaborator

Found in the review of #69 (#69 (comment), findings 3 and 4). That PR documents these cases instead of fixing them.

Problem

  • A command killed while its .tmp- directory exists leaves it for good: a secret or version being added, or the secret, version, unlocker or vault being removed (encrypted keys included). A vault rm killed mid-delete makes the vault vanish from vault list while its files stay in the state directory.
  • secret vault create stopped at the passphrase prompt leaves a new vault with no unlocker that is already the current vault; secret init stopped there leaves the default vault with no unlocker.
  • An unlocker add stopped before its metadata is written leaves a directory that unlocker list warns about on every run and unlocker rm cannot remove (overlaps #48 and #72).

Definition of done

  • Leftover .tmp- entries are deleted by the next command that takes the state-directory lock (while it holds it, no other command can own them), or by an explicit cleanup step that runs on every mutating command; a test kills nothing but plants a leftover and shows it gone after the next command.
  • vault create and init either leave no vault when stopped before the unlocker exists, or the vault becomes current only once it has one; a test simulates the stop.
  • A partial unlocker directory can be removed with unlocker rm.
  • The TODO.md exceptions written by #69 are removed as each is fixed.

Sequencing

After #69 lands.

Model: opus-5-5

Found in the review of https://git.eeqj.de/sneak/secret/pulls/69 (https://git.eeqj.de/sneak/secret/pulls/69#issuecomment-117651, findings 3 and 4). That PR documents these cases instead of fixing them. ## Problem - A command killed while its `.tmp-` directory exists leaves it for good: a secret or version being added, or the secret, version, unlocker or vault being removed (encrypted keys included). A `vault rm` killed mid-delete makes the vault vanish from `vault list` while its files stay in the state directory. - `secret vault create` stopped at the passphrase prompt leaves a new vault with no unlocker that is already the current vault; `secret init` stopped there leaves the default vault with no unlocker. - An unlocker add stopped before its metadata is written leaves a directory that `unlocker list` warns about on every run and `unlocker rm` cannot remove (overlaps https://git.eeqj.de/sneak/secret/issues/48 and https://git.eeqj.de/sneak/secret/issues/72). ## Definition of done - Leftover `.tmp-` entries are deleted by the next command that takes the state-directory lock (while it holds it, no other command can own them), or by an explicit cleanup step that runs on every mutating command; a test kills nothing but plants a leftover and shows it gone after the next command. - `vault create` and `init` either leave no vault when stopped before the unlocker exists, or the vault becomes current only once it has one; a test simulates the stop. - A partial unlocker directory can be removed with `unlocker rm`. - The `TODO.md` exceptions written by https://git.eeqj.de/sneak/secret/pulls/69 are removed as each is fixed. ## Sequencing After https://git.eeqj.de/sneak/secret/pulls/69 lands. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#75