Every command ends on SIGINT, SIGTERM or SIGHUP; an interrupted age -o leaves no file (closes #48)
check / check (push) Failing after 1s

SIGINT, SIGTERM and SIGHUP are no longer caught for the whole run, so they end any command at once, the mnemonic prompt included. One package, internal/cli/signals, catches them only where cleanup is needed, and only those not ignored at start, so nohup still works: ssh to and ssh install while their child runs, and age encrypt -o and age decrypt -o while they write. A signal received by the time the input ends leaves no new file and exits 1; otherwise the whole file is put in place, never an unfinished one.

Judgement call: the guarantee is stated for a signal keyfunc has received, as Go cannot promise more; the main goroutine stays on the main thread so a Ctrl-C on a pipeline is seen first on Linux. Unverified on macOS.

Model: opus-5-5 (implementation); fable-5-1 (design)
This commit was merged in pull request #54.
This commit is contained in:
2026-10-04 13:42:49 +02:00
parent 1d1c8182be
commit c96b77dd67
8 changed files with 491 additions and 50 deletions
+15 -2
View File
@@ -66,8 +66,9 @@ calls into `internal/`. The packages there are:
- `internal/childmnemonic` derives a child mnemonic from the main one using
BIP-85's own mnemonic application.
- `internal/cli` builds the cobra command tree and runs it. Under it,
`cli/options` holds the flags every command shares, and `cli/ssh`, `cli/age`
and `cli/mnemonic` are the command groups.
`cli/options` holds the flags every command shares, `cli/signals` catches
SIGINT, SIGTERM and SIGHUP for the commands that clean up before they end, and
`cli/ssh`, `cli/age` and `cli/mnemonic` are the command groups.
### Adding a key type
@@ -288,6 +289,18 @@ girl mad pet galaxy egg matter matrix prison refuse sense ordinary nose
Errors go to standard error and the exit status is 1, except for `ssh to`, which
passes through `ssh`'s own exit status.
SIGINT, SIGTERM and SIGHUP end any command at once, at the mnemonic prompt too,
with the status a shell gives a program killed by that signal (130 for SIGINT).
While `age encrypt -o` or `age decrypt -o` is writing the file, the signal makes
it remove the unfinished file, leave a file already at the named path as it was,
and exit with status 1. That holds for a signal that has reached `keyfunc` when
its input ends; a later one leaves the whole file in place. Ctrl-C on a pipeline
ends the input at the same moment, and on Linux `keyfunc` sees the signal first,
though no system promises that. While `ssh to` or `ssh install` has `ssh` or
`sftp` running, the signal ends that program instead, the tool removes its agent
socket or working files, and it exits with status 1, or for `ssh to` with
`ssh`'s own status if `ssh` reported one.
## Entrypoints
The repo adheres to the