The age commands: pub, priv, encrypt and decrypt (closes #3)
All checks were successful
check / check (push) Successful in 2m38s

The application number is 657169, so the path is
m/83696968'/657169'/<n>'. The 32 derived bytes are clamped the way
X25519 requires and go through bech32 into an age identity, the only
route age offers from raw bytes to a key; these are the steps
sneak/secret takes in its agehd package. A test fixes the secret key
the example mnemonic gives at index 0, so a change to any of those
steps is caught.

The derived recipient is always first, so the mnemonic that encrypted
a file can read it back. Decrypting recognises the text form by its
first line, so it needs no flag. A file named with -o is written
beside the target, readable only by its owner, and renamed into place
once the work succeeds, so a refused decryption leaves what was
already there untouched.

Model: opus-5
This commit is contained in:
2026-09-07 15:44:08 +00:00
parent d69bed722a
commit a44164a6f5
7 changed files with 744 additions and 1 deletions

View File

@@ -5,6 +5,7 @@ import (
"fmt"
"os"
"git.eeqj.de/sneak/keyfunc/internal/cli/age"
"git.eeqj.de/sneak/keyfunc/internal/cli/mnemonic"
"git.eeqj.de/sneak/keyfunc/internal/cli/options"
"git.eeqj.de/sneak/keyfunc/internal/cli/ssh"
@@ -30,7 +31,7 @@ func Root() *cobra.Command {
}
options.Add(root)
root.AddCommand(ssh.Command(), mnemonic.Command())
root.AddCommand(ssh.Command(), age.Command(), mnemonic.Command())
return root
}