age -o follows a symlink and writes a pipe or device directly (closes #59)
check / check (push) Failing after 2s

age encrypt -o and age decrypt -o always renamed a new file over the
named path, replacing a symlink, a named pipe or a device such as
/dev/null with a regular file. A path that is the same file as the
tool's standard output or standard error, under any name, is now
written to that stream, so the file it is redirected to keeps its
contents. Any other path is looked at without following a final
symlink: nothing there or a regular file is replaced by rename as
before, a symlink gets the same treatment for what it points at and is
refused if it points at nothing, and anything else is written to
directly, without catching signals. The README says so, and that a
replaced file has mode 0600.

Model: opus-5-5
This commit is contained in:
2026-10-04 14:33:34 +00:00
parent dad29597bd
commit 02942b591d
4 changed files with 236 additions and 17 deletions
+24 -11
View File
@@ -250,11 +250,21 @@ identity's own recipient, plus any given with `--to`, so the same mnemonic can
always decrypt what it encrypted. Output goes to `-o` or standard output;
`--armor` writes the text form. Nothing is written except the output.
A `-o` path that is the same file as the tool's own standard output or standard
error, under any name such as `/dev/stdout` or `/dev/fd/2`, is written to that
stream, as leaving out `-o` writes to standard output; the file the stream is
redirected to is written as the redirect says and never replaced, so with `>>`
the output follows what the file already held. Otherwise, a regular file already
at the `-o` path is replaced, and the new file has mode `0600`. A symlink there
is followed, and what it points at is treated the same way, so the link keeps
pointing where it did; a symlink that points at nothing is refused. A named pipe
or a device, such as `/dev/null`, is written to directly.
### `keyfunc age decrypt [-n N] [-o <file>] [<file>]`
Decrypts the file (or standard input) with the derived identity. Output goes to
`-o` or standard output. If the identity is not one of the recipients, the tool
says so and exits with status 1.
`-o`, which is treated as for `encrypt`, or standard output. If the identity is
not one of the recipients, the tool says so and exits with status 1.
## Derived mnemonics: `keyfunc mnemonic`
@@ -291,15 +301,18 @@ passes through `ssh`'s own exit status.
SIGINT, SIGTERM and SIGHUP end any command at once, at the mnemonic prompt too,
with the status a shell gives a program killed by that signal (130 for SIGINT).
While `age encrypt -o` or `age decrypt -o` is writing the file, the signal makes
it remove the unfinished file, leave a file already at the named path as it was,
and exit with status 1. That holds for a signal that has reached `keyfunc` when
its input ends; a later one leaves the whole file in place. Ctrl-C on a pipeline
ends the input at the same moment, and on Linux `keyfunc` sees the signal first,
though no system promises that. While `ssh to` or `ssh install` has `ssh` or
`sftp` running, the signal ends that program instead, the tool removes its agent
socket or working files, and it exits with status 1, or for `ssh to` with
`ssh`'s own status if `ssh` reported one.
While `age encrypt -o` or `age decrypt -o` is writing a new file or replacing a
regular one, the signal makes it remove the unfinished file, leave a file
already at the named path as it was, and exit with status 1. That holds for a
signal that has reached `keyfunc` when its input ends; a later one leaves the
whole file in place. Ctrl-C on a pipeline ends the input at the same moment, and
on Linux `keyfunc` sees the signal first, though no system promises that. A
named pipe or a device at the `-o` path, or a path that is the same file as
standard output or standard error, is written to directly, and the signal ends
the tool there as it ends any other command. While `ssh to` or `ssh install` has
`ssh` or `sftp` running, the signal ends that program instead, the tool removes
its agent socket or working files, and it exits with status 1, or for `ssh to`
with `ssh`'s own status if `ssh` reported one.
## Entrypoints