Skip to content

gl: quickstart and init silently regenerate an unreadable identity, orphaning the agent DID #491

Description

@euxaristia

Summary

gl quickstart and gl init treat any load_keypair_from_dir failure as "no identity" and regenerate: crates/gl/src/quickstart.rs:62-65 ("Identity file exists but is unreadable. Regenerating...") and crates/gl/src/init.rs:69-74, with generate_identity unconditionally fs::write-ing the new PEM over the old file (init.rs:240, :245). gl identity new itself demands confirmation or --force before overwriting (crates/gl/src/identity.rs:114); these two paths bypass that guard.

Impact

A corrupted PEM (non-atomic write, disk fault) or a transient read failure (Windows file lock from AV/backup) silently replaces the agent's keypair with a fresh one. init then registers the NEW DID and creates a new public repo, silently orphaning the old identity: repos, escrow, and trust links become unreachable. Local data loss with real-world triggers.

Remediation

  1. On an unreadable existing identity, require explicit confirmation (or --force) before regenerating, and write the old file to a backup path first.
  2. Make identity writes atomic (temp file + rename).

Proposed labels: kind:bug, crate:gl, subsystem:identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:glgl — the contributor CLIkind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions