session_file
session_file
¶
Tmpfs-file backing for the volatile unlock cache.
session_cache engages this
backing when the kernel key facility is unusable on a host. The cache
file lives under $XDG_RUNTIME_DIR: a per-login tmpfs that systemd
wipes at the last logout and that never survives a reboot. The file
has 0600 permissions in a 0700 directory. This construction
reproduces the kernel-keyring guarantees: memory-backed, user-only,
gone with the session. Nothing here touches durable storage.
The file name embeds the same (hostname, DB path) digest as
kernel_keyring.key_description,
so the cache for one vault never resolves another's.
__all__ = ['forget', 'is_cached', 'load', 'store', 'unavailable_reason']
module-attribute
¶
store(passphrase, db_path)
¶
Cache passphrase for db_path in the session runtime directory.
Returns:
| Type | Description |
|---|---|
bool
|
True when the cache file was written, False when the session |
bool
|
runtime directory is unusable or the write failed. |
Source code in src/terok_sandbox/vault/store/session_file.py
load(db_path)
¶
Return the passphrase cached for db_path, or None on any miss.
Silent on every miss, mirroring
kernel_keyring.load.
An absent file and an unusable runtime directory are both the
ordinary "locked" outcome, and the next tier handles it.
Source code in src/terok_sandbox/vault/store/session_file.py
forget(db_path)
¶
Remove the cache file for db_path.
Returns:
| Type | Description |
|---|---|
bool
|
True when the file is gone (removed or never present), False |
bool
|
when it may still exist. |
Source code in src/terok_sandbox/vault/store/session_file.py
is_cached(db_path)
¶
Return True when a non-empty cache file exists for db_path.
Source code in src/terok_sandbox/vault/store/session_file.py
unavailable_reason()
¶
Explain why this session cannot hold the cache file, or None if it can.