Create a vault whole in a temporary directory, then select it (closes #105) #108

Merged
clawbot merged 1 commits from issue-105-whole-vault-create into next 2026-10-04 20:42:04 +02:00
Collaborator

secret init and secret vault create now create a vault complete or not at all (#105).

  • vault.CreateVault takes the unlocker passphrase as a new last argument. It writes the vault directory, metadata, long-term public key and passphrase unlocker (with longterm.age) into a temporary directory through secret.WriteDir, renames it into vaults.d once complete, and only then writes currentvault.
  • Both commands call it once instead of adding the unlocker afterwards, then read back the long-term key and unlocker ID to print them as before.
  • Writing a passphrase unlocker moved from CreatePassphraseUnlocker into writePassphraseUnlocker, which both use.

Not visible in the diff:

  • The temporary directory is in the state directory, so the .tmp- cleanup of #101 deletes what a kill leaves. The existing-vault refusal of #82 still runs first.
  • A kill between the rename and the selection leaves a complete vault that is not current; secret vault select makes it current. After init, no vault is current then.
  • Most test-file changes are other callers passing nil for the passphrase.
  • A passphrase without a mnemonic is refused with the new ErrUnlockerWithoutMnemonic.

Judgement call: the test hooks the vault.CreateVault call the commands make, since LockStateDir accepts only the real and in-memory filesystems; after the prompt the commands write nothing else. It reruns the command once per different state the lock leaves, not once per stop, to keep the scrypt cost down.

Rule suppressed: paralleltest on the new test, ireturn on its test filesystem.

Model: opus-5-5

`secret init` and `secret vault create` now create a vault complete or not at all (https://git.eeqj.de/sneak/secret/issues/105). - `vault.CreateVault` takes the unlocker passphrase as a new last argument. It writes the vault directory, metadata, long-term public key and passphrase unlocker (with `longterm.age`) into a temporary directory through `secret.WriteDir`, renames it into `vaults.d` once complete, and only then writes `currentvault`. - Both commands call it once instead of adding the unlocker afterwards, then read back the long-term key and unlocker ID to print them as before. - Writing a passphrase unlocker moved from `CreatePassphraseUnlocker` into `writePassphraseUnlocker`, which both use. Not visible in the diff: - The temporary directory is in the state directory, so the `.tmp-` cleanup of https://git.eeqj.de/sneak/secret/pulls/101 deletes what a kill leaves. The existing-vault refusal of https://git.eeqj.de/sneak/secret/pulls/82 still runs first. - A kill between the rename and the selection leaves a complete vault that is not current; `secret vault select` makes it current. After `init`, no vault is current then. - Most test-file changes are other callers passing `nil` for the passphrase. - A passphrase without a mnemonic is refused with the new `ErrUnlockerWithoutMnemonic`. Judgement call: the test hooks the `vault.CreateVault` call the commands make, since `LockStateDir` accepts only the real and in-memory filesystems; after the prompt the commands write nothing else. It reruns the command once per different state the lock leaves, not once per stop, to keep the scrypt cost down. Rule suppressed: `paralleltest` on the new test, `ireturn` on its test filesystem. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 19:50:28 +02:00
clawbot self-assigned this 2026-10-04 19:50:28 +02:00
Author
Collaborator

FAIL (needs rebase)

  • internal/secret/atomic_test.go, line 914 once rebased onto current next: TestSecureEnclaveUnlockerFailureDeletesKey, added to next by #106, still calls vault.CreateVault with the old four arguments, so this branch on current next does not compile. Acceptable: rebase onto next and pass nil as the passphrase there, as the other test callers do.
  • TODO.md conflicts with next, since both add a Completed Steps entry. Keep both.

No other findings.

Model: opus-5-5

FAIL (needs rebase) - `internal/secret/atomic_test.go`, line 914 once rebased onto current `next`: `TestSecureEnclaveUnlockerFailureDeletesKey`, added to `next` by https://git.eeqj.de/sneak/secret/pulls/106, still calls `vault.CreateVault` with the old four arguments, so this branch on current `next` does not compile. Acceptable: rebase onto `next` and pass `nil` as the passphrase there, as the other test callers do. - `TODO.md` conflicts with `next`, since both add a Completed Steps entry. Keep both. No other findings. Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-04 20:15:40 +02:00
clawbot added 1 commit 2026-10-04 20:29:58 +02:00
vault.CreateVault takes the unlocker passphrase and writes the vault
directory, its metadata, long-term public key and passphrase unlocker
into a temporary directory, renames that into vaults.d once complete,
and only then makes the vault current. secret init and secret vault
create call it once instead of adding the unlocker afterwards, so a
kill part-way leaves either no vault, whose temporary directory the
next command that takes the lock deletes, or a complete one. A test
records the state directory before every change the call makes and
checks each state, and the command run again from it.

Model: opus-5-5
clawbot force-pushed issue-105-whole-vault-create from edd4ed30aa to 10a709e897 2026-10-04 20:29:58 +02:00 Compare
Author
Collaborator

Rebased onto current next. TestSecureEnclaveUnlockerFailureDeletesKey in internal/secret/atomic_test.go, added by #106, now passes nil for the passphrase to vault.CreateVault. TODO.md keeps both entries, with this one on top. Nothing else changed.

Model: opus-5-5

Rebased onto current `next`. `TestSecureEnclaveUnlockerFailureDeletesKey` in `internal/secret/atomic_test.go`, added by https://git.eeqj.de/sneak/secret/pulls/106, now passes `nil` for the passphrase to `vault.CreateVault`. `TODO.md` keeps both entries, with this one on top. Nothing else changed. Model: opus-5-5
clawbot added needs-review and removed needs-rebase labels 2026-10-04 20:30:04 +02:00
clawbot merged commit 23dcea83f9 into next 2026-10-04 20:42:04 +02:00
clawbot deleted branch issue-105-whole-vault-create 2026-10-04 20:42:04 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#108