Reject secret mv onto the same secret under another name (closes #78) #81

Merged
clawbot merged 1 commits from issue-78-case-alias-move into next 2026-10-04 07:42:12 +02:00
Collaborator

On a case-insensitive filesystem (the macOS default) Foo and foo name one secret, so secret mv --force Foo foo removed the destination, which was the source, and the secret was lost with all its versions. A move between vaults lost it one step later: the copy replaced the source, and removing the source then removed the copy.

Chosen: reject. Before changing anything, a move within a vault and a move between vaults compare the two secret directories with os.SameFile and refuse with secret 'Foo' cannot be moved onto itself: 'foo' is the same secret on this filesystem. A plain rename to the new spelling was not chosen: it cannot be tested without a case-insensitive filesystem (a rename onto a symbolic link to the source fails), and between vaults it would not be a plain rename. On macOS, changing only the case of a name now takes two moves through a third name; README.md says so.

Not visible in the diff:

  • The check runs before the --force check, so without --force the same move now gets this error instead of "already exists".
  • os.SameFile is always false on the in-memory test filesystem, so the exact-name check from #76 still covers mv x x there; the new tests use symbolic links in a temporary directory on the real filesystem.
  • A case-only rename on a case-sensitive filesystem is unchanged; its test skips itself if the temporary directory is case-insensitive.

Model: opus-5-5

On a case-insensitive filesystem (the macOS default) `Foo` and `foo` name one secret, so `secret mv --force Foo foo` removed the destination, which was the source, and the secret was lost with all its versions. A move between vaults lost it one step later: the copy replaced the source, and removing the source then removed the copy. **Chosen: reject.** Before changing anything, a move within a vault and a move between vaults compare the two secret directories with `os.SameFile` and refuse with `secret 'Foo' cannot be moved onto itself: 'foo' is the same secret on this filesystem`. A plain rename to the new spelling was not chosen: it cannot be tested without a case-insensitive filesystem (a rename onto a symbolic link to the source fails), and between vaults it would not be a plain rename. On macOS, changing only the case of a name now takes two moves through a third name; `README.md` says so. Not visible in the diff: - The check runs before the `--force` check, so without `--force` the same move now gets this error instead of "already exists". - `os.SameFile` is always false on the in-memory test filesystem, so the exact-name check from https://git.eeqj.de/sneak/secret/pulls/76 still covers `mv x x` there; the new tests use symbolic links in a temporary directory on the real filesystem. - A case-only rename on a case-sensitive filesystem is unchanged; its test skips itself if the temporary directory is case-insensitive. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 06:18:06 +02:00
clawbot self-assigned this 2026-10-04 06:18:06 +02:00
Author
Collaborator

PASS: a move within a vault or between vaults is now refused before anything is removed when the destination is the source under another name, and a case-only rename on a case-sensitive filesystem works as before.

  • TODO.md conflicts with current next; I kept both entries locally to review the code, so the branch needs a rebase before merging.
  • Not run on a case-insensitive filesystem; the same-directory case was exercised through symbolic links only.

Model: opus-5-5

PASS: a move within a vault or between vaults is now refused before anything is removed when the destination is the source under another name, and a case-only rename on a case-sensitive filesystem works as before. - `TODO.md` conflicts with current `next`; I kept both entries locally to review the code, so the branch needs a rebase before merging. - Not run on a case-insensitive filesystem; the same-directory case was exercised through symbolic links only. Model: opus-5-5
clawbot added 1 commit 2026-10-04 07:24:39 +02:00
On a case-insensitive filesystem (the macOS default) "Foo" and "foo" name
one secret, so `secret mv --force Foo foo` removed the destination, which
was the source, and lost the secret with every version. Between vaults the
copy replaced the source, and removing the source then removed the copy.

Both kinds of move now compare the two secret directories with
os.SameFile before changing anything and reject the move if they are one,
with or without --force. The tests give one secret two names with
symbolic links on the real filesystem.

Model: opus-5-5
clawbot force-pushed issue-78-case-alias-move from 5cfb9c5f46 to 97d039f1a4 2026-10-04 07:24:39 +02:00 Compare
clawbot merged commit e640d10964 into next 2026-10-04 07:42:12 +02:00
clawbot deleted branch issue-78-case-alias-move 2026-10-04 07:42:12 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#81