Commit Graph
9 Commits
Author SHA1 Message Date
sneak e9fafa14ad update dependencies to current releases (closes #19)
check / check (push) Successful in 3m4s
Direct deps bumped to their latest release: age v1.2.1 to v1.3.2,
cobra v1.9.1 to v1.10.2, testify v1.8.4 to v1.12.1, x/crypto v0.38.0
to v0.57.0, x/term v0.32.0 to v0.46.0, btcutil v1.1.6 to v1.2.0,
btcd v0.24.2 to v0.25.0. go-bip39 is already at v1.1.0 and the secret
module at its latest commit.

btcd is held at v0.25.0: v0.26.x moved the chaincfg and wire packages
into separate /v2 modules, a breaking migration our chaincfg import and
the pinned secret dependency's v1 btcutil cannot take without upstream
work. go mod tidy normalized the go directive to 1.26.0. No test vector
changed.

Model: opus-4-8
2026-09-21 07:25:57 +00:00
clawbot 63575ce827 Move the entrypoint to cmd/keyfunc (closes #20)
check / check (push) Successful in 16s
main.go moves unchanged to cmd/keyfunc/main.go, where REPO_POLICIES.md puts Go entrypoints, and the Makefile build target builds ./cmd/keyfunc. The binary is still written to ./keyfunc and still carries the stamped version.

Model: opus-4-8 (implementation); fable-5-1 (summary)
2026-09-21 09:25:38 +02:00
clawbot 8aeed7b901 ssh install works over sftp and runs nothing on the host (closes #10)
check / check (push) Successful in 4s
ssh install no longer runs a command on the host. It reads .ssh/authorized_keys over sftp, takes the empty reading only from sftp's own message about that path, appends the derived key locally when it is not already present, uploads the result beside the file with mode 0600 and renames it over the original. Any other failure prints what sftp said, writes nothing and exits 1. sftp batch mode disables password prompts, so a key or agent is required; a directory the owner cannot enter reads as a host with no file, which README.md states.

Model: opus-5 (implementation); fable-5-1 (landing)
2026-09-08 08:20:17 +02:00
sneak a2a0890ded Merge pull request '0.1.0: deterministic SSH keys, age identities with encryption, and child mnemonics from one mnemonic' (#9) from next into main
check / check (push) Successful in 22s
Reviewed-on: #9
2026-09-08 04:49:04 +02:00
clawbot b9c8631788 The ssh install and ssh to commands (closes #2)
check / check (push) Successful in 2m30s
keyfunc ssh install appends the public line on a host through the system ssh, only when absent, feeding the line on standard input; keyfunc ssh to serves the derived key from an in-process agent on a private socket and runs the system ssh with it, the private key never on disk. Two review rounds; the second passed with no findings.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 18:49:42 +02:00
clawbot 5bbeec86d6 The age commands: pub, priv, encrypt and decrypt (closes #3)
check / check (push) Successful in 28s
keyfunc age derives an age identity at the generic path the way secret's agehd does, prints the recipient or the identity, and encrypts to or decrypts with it, the derived recipient always among encrypt's recipients. Two review rounds; the second passed with no findings, the clamping step now pinned by a fixed identity test.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 18:35:11 +02:00
clawbot d69bed722a The mnemonic command: child mnemonics (closes #4)
check / check (push) Successful in 4s
keyfunc mnemonic derives a 12, 18 or 24 word child mnemonic through BIP-85's own mnemonic application, with the specification's test vectors as tests. One review round, passed with no findings; the reviewer reproduced the vectors from an implementation written from the specification alone.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 18:05:08 +02:00
clawbot 279cba6bcf Skeleton, mnemonic input, derivation, and the ssh pub and priv commands (closes #1)
check / check (push) Successful in 5s
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.

Model: opus-5 (implementation and review); fable-5-1 (landing)
2026-09-07 17:34:54 +02:00
clawbot c3fd26a1de keyfunc: the specification
The README is the specification sneak approved on 2026-09-07, moved
here from the hacks repository: deterministic SSH keys, age identities
with encrypt and decrypt, and child mnemonics, all derived from one
BIP-39 mnemonic and stored nowhere.

Model: fable-5-1
2026-09-07 14:27:57 +00:00