A failed keychain or Secure Enclave unlocker add can leave something behind outside the unlocker directory:
Secure Enclave: CreateSecureEnclaveUnlocker (internal/secret/seunlocker_darwin.go) creates the Secure Enclave key first. If getting the long-term key fails after that (for example a wrong passphrase for the current unlocker), or anything later does, the key stays in the Secure Enclave with nothing referring to it. macse.DeleteKey exists.
Keychain: CreateKeychainUnlocker (internal/secret/keychainunlocker.go) stores the keychain item before writing the metadata file. If that write, or moving the finished unlocker into place, fails, the item stays in the keychain. deleteFromKeychain exists.
Found while working on #48, which makes such a failure leave no unlocker directory.
Definition of done
A failed add deletes the Secure Enclave key or keychain item it created, with a failure to delete it reported along with the original error.
TODO.md updated in the same commit.
Model: opus-5-5
A failed keychain or Secure Enclave unlocker add can leave something behind outside the unlocker directory:
- Secure Enclave: `CreateSecureEnclaveUnlocker` (`internal/secret/seunlocker_darwin.go`) creates the Secure Enclave key first. If getting the long-term key fails after that (for example a wrong passphrase for the current unlocker), or anything later does, the key stays in the Secure Enclave with nothing referring to it. `macse.DeleteKey` exists.
- Keychain: `CreateKeychainUnlocker` (`internal/secret/keychainunlocker.go`) stores the keychain item before writing the metadata file. If that write, or moving the finished unlocker into place, fails, the item stays in the keychain. `deleteFromKeychain` exists.
Found while working on https://git.eeqj.de/sneak/secret/issues/48, which makes such a failure leave no unlocker directory.
## Definition of done
- A failed add deletes the Secure Enclave key or keychain item it created, with a failure to delete it reported along with the original error.
- `TODO.md` updated in the same commit.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
A failed keychain or Secure Enclave unlocker add can leave something behind outside the unlocker directory:
CreateSecureEnclaveUnlocker(internal/secret/seunlocker_darwin.go) creates the Secure Enclave key first. If getting the long-term key fails after that (for example a wrong passphrase for the current unlocker), or anything later does, the key stays in the Secure Enclave with nothing referring to it.macse.DeleteKeyexists.CreateKeychainUnlocker(internal/secret/keychainunlocker.go) stores the keychain item before writing the metadata file. If that write, or moving the finished unlocker into place, fails, the item stays in the keychain.deleteFromKeychainexists.Found while working on #48, which makes such a failure leave no unlocker directory.
Definition of done
TODO.mdupdated in the same commit.Model: opus-5-5