Signals end every command, not only ssh to and ssh install (closes #48)
check / check (push) Failing after 2s

SIGINT, SIGTERM and SIGHUP were caught for the whole run, so the
mnemonic prompt waited for Enter and an interrupted `age encrypt -o`
put the encryption of the cut-off input in place. Now they end the
tool at once, except where a command cleans up first: `ssh to` and
`ssh install` while ssh or sftp runs, and `age encrypt -o` and
`age decrypt -o` while they write. A signal those two have received
when their input ends removes the unfinished file and exits 1; a later
one leaves the whole file in place. The tool stays on the main thread,
where Linux delivers the signal first. Signals the tool was started
ignoring stay ignored, so a run under nohup survives a hangup.

Model: opus-5-5
This commit is contained in:
2026-10-04 11:12:13 +00:00
parent 1d1c8182be
commit add39a24c1
8 changed files with 491 additions and 50 deletions
+15 -2
View File
@@ -66,8 +66,9 @@ calls into `internal/`. The packages there are:
- `internal/childmnemonic` derives a child mnemonic from the main one using
BIP-85's own mnemonic application.
- `internal/cli` builds the cobra command tree and runs it. Under it,
`cli/options` holds the flags every command shares, and `cli/ssh`, `cli/age`
and `cli/mnemonic` are the command groups.
`cli/options` holds the flags every command shares, `cli/signals` catches
SIGINT, SIGTERM and SIGHUP for the commands that clean up before they end, and
`cli/ssh`, `cli/age` and `cli/mnemonic` are the command groups.
### Adding a key type
@@ -288,6 +289,18 @@ girl mad pet galaxy egg matter matrix prison refuse sense ordinary nose
Errors go to standard error and the exit status is 1, except for `ssh to`, which
passes through `ssh`'s own exit status.
SIGINT, SIGTERM and SIGHUP end any command at once, at the mnemonic prompt too,
with the status a shell gives a program killed by that signal (130 for SIGINT).
While `age encrypt -o` or `age decrypt -o` is writing the file, the signal makes
it remove the unfinished file, leave a file already at the named path as it was,
and exit with status 1. That holds for a signal that has reached `keyfunc` when
its input ends; a later one leaves the whole file in place. Ctrl-C on a pipeline
ends the input at the same moment, and on Linux `keyfunc` sees the signal first,
though no system promises that. While `ssh to` or `ssh install` has `ssh` or
`sftp` running, the signal ends that program instead, the tool removes its agent
socket or working files, and it exits with status 1, or for `ssh to` with
`ssh`'s own status if `ssh` reported one.
## Entrypoints
The repo adheres to the