Skip to content

fix(gcp): protect minted key cleanup across interrupts - #2120

Merged
cristim merged 1 commit into
mainfrom
fix/2112-key-interrupt-lifecycle
Sep 29, 2026
Merged

cristim merged 1 commit into
mainfrom
fix/2112-key-interrupt-lifecycle

Conversation

@cristim

@cristim cristim commented Sep 29, 2026

Copy link
Copy Markdown
Member

Summary

GCP setup now protects wizard-minted keys from SIGINT and SIGTERM from the final create choice through upload and cleanup. Prompts retain default interrupt behavior. Output occurs after cleanup, so stdout backpressure cannot strand the plaintext key.

This fixes the remaining interruption gap from #1947 and #2112. The other hardening items in #2117 remain separate.

Closes #2119.

Root cause and fix

The coordinator registered signal handling after Step 5 returned. Step 5 had already minted and written the key and could block while printing its temporary path. Another message could block after remote deletion but before local removal.

The coordinator now starts one signal context after the final input choice, before minting, and retains it through the existing uploader cleanup. A nil-safe deferred closure stops signal handling on failure. Successful cleanup restores default signal behavior before final output. Both blocking pre-cleanup messages are removed. Operator-supplied files retain their existing behavior.

Regression proof

Subprocess tests invoke the actual runConfigureGCP coordinator and real SDK clients against local fixture endpoints. They cover SIGINT and SIGTERM with stdout full, cancellation during the IAM request, and default SIGINT termination at the final prompt. Assertions check local file and directory removal and the remote delete request.

The tests fail against the original coordinator because plaintext survives both signals. Separate probes also fail when restoring only late signal activation, Step 5 output, or remote-cleanup output. The latter two leave the plaintext file present after the bounded subprocess timeout.

Verification

With Go 1.26.6 and GOWORK=off:

  • Focused coordinator, upload, and key-writing tests with -race: pass.
  • Full go test -race -short ./cmd/... -count=1: pass, 443.190s.
  • Build, vet, and go mod tidy -diff: pass; tidy output empty.
  • golangci-lint v2.10.1: zero issues.
  • Normal commit hooks: pass.

These author checks cover tree f7b2822efae9f06add8ecae99229cb1fc075a5fe, identical at fully tested commit 2dc4d8e and follow-up candidate 42dcc9e5. Independent gpt-6-astra review approved final SHA 42dcc9e5e2cb6fc737ab7a1ec3791040825ddd09 with no actionable findings and independently passed the focused race tests in 8.234s. Tests use fixture credentials and local APIs; no live cloud operation was performed.

Start signal handling after the final wizard choice and retain it through
minting, upload, and cleanup. Remove stdout writes that can block cleanup.

Exercise the real coordinator in subprocesses with fixture APIs, saturated
stdout, SIGINT, SIGTERM, and interruption during minting or at the prompt.
@cristim cristim added triaged Item has been triaged priority/p2 Backlog-worthy severity/medium Moderate harm urgency/this-sprint Within the current sprint impact/few Limited audience effort/s Hours type/security Security finding labels Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: LeanerCloud/cloud-commitments-cli/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: f9a62791-1649-4279-b309-bcd02c0ac18f

📥 Commits

Reviewing files that changed from the base of the PR and between c9d01f5 and 42dcc9e.

📒 Files selected for processing (2)
  • cmd/configure_gcp.go
  • cmd/configure_gcp_signal_test.go
 _______________________________________
< CI/CD: Carrots In / Defects Canceled. >
 ---------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@cristim
cristim marked this pull request as ready for review September 29, 2026 08:20
@cristim
cristim merged commit 0229b93 into main Sep 29, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/few Limited audience priority/p2 Backlog-worthy severity/medium Moderate harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sec(gcp): close the mint-to-upload interrupt cleanup gap

1 participant