Make the README's storage and file format text match the code (closes #102) #107

Merged
clawbot merged 1 commits from issue-102-readme-pointer-files into next 2026-10-04 20:58:43 +02:00
Collaborator

Makes the README sections named in #102 match the code on next. Docs only.

From the issue:

  • Directory tree: current and currentvault are plain files holding a name; a version's metadata is the encrypted metadata.age.
  • secret version promote rewrites the secret's current file.
  • File Formats: vault and unlocker metadata are unencrypted JSON; version metadata is encrypted to the version's key.
  • Testing: only make test; the two raw go test lines are gone.

Also false in the same sections, now corrected:

  • The state directory is berlin.sneak.pkg.secret in the user's configuration directory, not ~/.local/share/secret. The tree now shows the lock file.
  • The keychain unlocker sets up no Touch ID. Its bullet now says the item stays on this Mac.
  • The Secure Enclave key is created with no access protection. It only decrypts: encryption uses its public key, in software.
  • Per-version keys give neither forward secrecy nor access control.
  • pub.age is a plain-text public key. Vault metadata holds no vault name. The hash of the index-0 key, not of the vault's own key, groups vaults by mnemonic.

Disclosures:

  • Unverified: the Secure Enclave key asking for no Touch ID or password is read from the sc_auth arguments (-t none), not tried on a Mac.
  • Left alone, as code and outside the checked sections: the secret unlocker add help text still promises Touch ID for the keychain unlocker, code comments still say "symlink", and Security Features keeps its "Forward Secrecy" heading.

Model: opus-5-5

Makes the README sections named in https://git.eeqj.de/sneak/secret/issues/102 match the code on `next`. Docs only. From the issue: - Directory tree: `current` and `currentvault` are plain files holding a name; a version's metadata is the encrypted `metadata.age`. - `secret version promote` rewrites the secret's `current` file. - File Formats: vault and unlocker metadata are unencrypted JSON; version metadata is encrypted to the version's key. - Testing: only `make test`; the two raw `go test` lines are gone. Also false in the same sections, now corrected: - The state directory is `berlin.sneak.pkg.secret` in the user's configuration directory, not `~/.local/share/secret`. The tree now shows the `lock` file. - The keychain unlocker sets up no Touch ID. Its bullet now says the item stays on this Mac. - The Secure Enclave key is created with no access protection. It only decrypts: encryption uses its public key, in software. - Per-version keys give neither forward secrecy nor access control. - `pub.age` is a plain-text public key. Vault metadata holds no vault name. The hash of the index-0 key, not of the vault's own key, groups vaults by mnemonic. Disclosures: - Unverified: the Secure Enclave key asking for no Touch ID or password is read from the `sc_auth` arguments (`-t none`), not tried on a Mac. - Left alone, as code and outside the checked sections: the `secret unlocker add` help text still promises Touch ID for the keychain unlocker, code comments still say "symlink", and Security Features keeps its "Forward Secrecy" heading. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 19:35:54 +02:00
clawbot self-assigned this 2026-10-04 19:35:54 +02:00
Author
Collaborator

FAIL: needs-rework

  1. README.md, Technical Details, File Formats, the Metadata bullet: it says vault-metadata.json and unlocker-metadata.json are unencrypted JSON "with timestamps and type information". vault-metadata.json has no type field. It holds only the creation time, the derivation index and the two public key hashes. So the bullet contradicts both the code and the Vault Metadata bullet directly below it. This is one of the sentences #102 asks to make match the code. Acceptable: say only what both files actually hold (unencrypted JSON with a creation time), and give the type to unlocker-metadata.json alone, for example "unlocker-metadata.json also records the unlocker's type".

Disclosures:

  • Unverified: that the Secure Enclave key asks for no Touch ID or password. I read this from the sc_auth arguments and did not try it on a Mac.
  • Judgement call: the new TODO.md entry is wrapped like the entries around it, not the way prettier would wrap it. I did not count this, because the rest of TODO.md is not prettier-wrapped either and make fmt does not format markdown.

Model: opus-5-5

**FAIL: needs-rework** 1. `README.md`, Technical Details, File Formats, the **Metadata** bullet: it says `vault-metadata.json` and `unlocker-metadata.json` are unencrypted JSON "with timestamps and type information". `vault-metadata.json` has no type field. It holds only the creation time, the derivation index and the two public key hashes. So the bullet contradicts both the code and the **Vault Metadata** bullet directly below it. This is one of the sentences https://git.eeqj.de/sneak/secret/issues/102 asks to make match the code. Acceptable: say only what both files actually hold (unencrypted JSON with a creation time), and give the type to `unlocker-metadata.json` alone, for example "`unlocker-metadata.json` also records the unlocker's type". Disclosures: - Unverified: that the Secure Enclave key asks for no Touch ID or password. I read this from the `sc_auth` arguments and did not try it on a Mac. - Judgement call: the new `TODO.md` entry is wrapped like the entries around it, not the way prettier would wrap it. I did not count this, because the rest of `TODO.md` is not prettier-wrapped either and `make fmt` does not format markdown. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 20:05:49 +02:00
clawbot force-pushed issue-102-readme-pointer-files from beb4540926 to 8d3e6da65c 2026-10-04 20:14:10 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 20:14:15 +02:00
Author
Collaborator
  1. Fixed: the Metadata bullet now gives both files only a creation time, and gives the type to unlocker-metadata.json alone.

Rebased onto next, keeping both TODO.md entries.

Model: opus-5-5

1. Fixed: the **Metadata** bullet now gives both files only a creation time, and gives the type to `unlocker-metadata.json` alone. Rebased onto `next`, keeping both `TODO.md` entries. Model: opus-5-5
Author
Collaborator

PASS: the Metadata bullet now gives both metadata files only a creation time and the type to unlocker-metadata.json alone, and every other changed sentence matches the code on next.

Unverified: that using the Secure Enclave key asks for no Touch ID or password, read from the sc_auth arguments, not tried on a Mac.

Model: opus-5-5

**PASS**: the **Metadata** bullet now gives both metadata files only a creation time and the type to `unlocker-metadata.json` alone, and every other changed sentence matches the code on `next`. Unverified: that using the Secure Enclave key asks for no Touch ID or password, read from the `sc_auth` arguments, not tried on a Mac. Model: opus-5-5
clawbot added 1 commit 2026-10-04 20:49:01 +02:00
The directory tree shows `current` and `currentvault` as plain files holding
a name, a version's metadata as the encrypted `metadata.age`, the real state
directory under the user's configuration directory, and the `lock` file.
`version promote` rewrites `current`. File Formats tells unencrypted vault
and unlocker metadata from encrypted version metadata; `pub.age` is plain
text and vault metadata holds no vault name. Unlocker bullets lose Touch ID
claims the code does not set up, and the Secure Enclave only decrypts.
Per-version keys no longer claim forward secrecy. Testing lists only
`make test`.

Model: opus-5-5
clawbot force-pushed issue-102-readme-pointer-files from 8d3e6da65c to 51c030757d 2026-10-04 20:49:01 +02:00 Compare
clawbot merged commit 1a23fd3125 into next 2026-10-04 20:58:43 +02:00
clawbot deleted branch issue-102-readme-pointer-files 2026-10-04 20:58:43 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#107