A failed keychain or Secure Enclave unlocker add leaves its keychain item or Secure Enclave key behind #89

Open
opened 2026-10-04 10:32:12 +02:00 by clawbot · 0 comments
Collaborator

A failed keychain or Secure Enclave unlocker add can leave something behind outside the unlocker directory:

  • Secure Enclave: CreateSecureEnclaveUnlocker (internal/secret/seunlocker_darwin.go) creates the Secure Enclave key first. If getting the long-term key fails after that (for example a wrong passphrase for the current unlocker), or anything later does, the key stays in the Secure Enclave with nothing referring to it. macse.DeleteKey exists.
  • Keychain: CreateKeychainUnlocker (internal/secret/keychainunlocker.go) stores the keychain item before writing the metadata file. If that write, or moving the finished unlocker into place, fails, the item stays in the keychain. deleteFromKeychain exists.

Found while working on #48, which makes such a failure leave no unlocker directory.

Definition of done

  • A failed add deletes the Secure Enclave key or keychain item it created, with a failure to delete it reported along with the original error.
  • TODO.md updated in the same commit.

Model: opus-5-5

A failed keychain or Secure Enclave unlocker add can leave something behind outside the unlocker directory: - Secure Enclave: `CreateSecureEnclaveUnlocker` (`internal/secret/seunlocker_darwin.go`) creates the Secure Enclave key first. If getting the long-term key fails after that (for example a wrong passphrase for the current unlocker), or anything later does, the key stays in the Secure Enclave with nothing referring to it. `macse.DeleteKey` exists. - Keychain: `CreateKeychainUnlocker` (`internal/secret/keychainunlocker.go`) stores the keychain item before writing the metadata file. If that write, or moving the finished unlocker into place, fails, the item stays in the keychain. `deleteFromKeychain` exists. Found while working on https://git.eeqj.de/sneak/secret/issues/48, which makes such a failure leave no unlocker directory. ## Definition of done - A failed add deletes the Secure Enclave key or keychain item it created, with a failure to delete it reported along with the original error. - `TODO.md` updated in the same commit. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#89