Skip to content

Two simultaneous first-time vault setups can still create two active encryption suites #751

Description

@rubenvdlinde

What happens

Two first-time vault setups for the same user, submitted at the same moment, can both succeed. The user then has two active encryption suites. That is the state #173 described: new secrets get sealed to a key the user is not unlocking with, and nothing says so at the time.

A double click on "Set up vault", or two open tabs, is enough to try it.

Why

lib/Service/EncryptionSuiteProvisioningService.php:118 counts the owner's active suites, and persistSuite() inserts afterwards. There is no lock and no unique constraint between the two. The certificate is signed before the count (:107), which widens the window.

The plain double-submit case from #173 is fixed: a second create now gets 409 (d475d00, 2026-08-21). Only the concurrent case is left.

Fix direction

  • Add a partial unique index on active suites per owner where the database supports it, or a dedicated per-owner lock row.
  • Or take an ILockingProvider lock on keepiq/suite/<ownerType>/<ownerId> around count and insert.
  • Keep the compromise-recovery successor path (createSuccessorSuite) outside the lock rule on purpose.

Live check

  1. With a fresh user, send two POST /apps/keepiq/api/v1/suites requests in parallel (for example two curl calls started with &).
  2. Call GET /apps/keepiq/api/v1/suites. If it lists two active suites, the defect holds.

Related: #173 (the sequential case, fixed), #395. Matrix row: crypto-15 in openspec/parity/capabilities.json (development, 06f25bf).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingencryption-suitesEncryptionSuite lifecycletriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions