Stop vault safety checks from reading unreadable state as empty (closes #51) #64

Merged
clawbot merged 1 commits from issue-51-fail-closed-unlocker-check into next 2026-10-04 10:15:21 +02:00
1 Commits
Author SHA1 Message Date
sneak 773a5ff69d Stop vault safety checks from reading unreadable state as empty (closes #51)
check / check (push) Waiting to run
Adding a PGP unlocker checked unlockers.d for a duplicate and, when the
directory or an unlocker's metadata file could not be read, reported no
duplicate and went on. The check now reads unlockers.d itself and stops
with an error naming the path and cause; `unlocker list` keeps skipping
unlockers it cannot read.

The same flaw guarded removing the last unlocker and removing a vault
(an unreadable secrets directory counted as no secrets) and vault
import (an unreadable pub.age counted as no long-term key). Those now
stop with an error too.

`vault rm` and `unlocker rm` now take the state directory lock and call
an unexported function that does the work, as `vault import` does.

Model: opus-5-5
2026-10-04 07:23:03 +00:00