REPO_POLICIES.md sets the Go module root to sneak.berlin/go/<name>.
go.mod, every import of the old path and the -X path in the Makefile
LDFLAGS now use sneak.berlin/go/keyfunc; make fmt moved those imports
to their new place in the sort order. The old path keeps no alias. The
README gives the go install line next to the build from a clone and
drops this issue from its TODO list, which now names the open 1.0
issues.
Model: opus-5-5
`cli.Main` ran the command tree on a background context, so SIGINT, SIGTERM or SIGHUP killed the process before deferred cleanup ran: `ssh to` left its agent socket and directory behind, and `ssh install` left a copy of the host's `authorized_keys` in its working directory. `Main` now runs the tree on a `signal.NotifyContext` for those signals; the cancelled context ends the child `ssh` or `sftp` and the cleanup runs. `ssh to` stops its child with SIGTERM, not a kill, so `ssh` restores the terminal. Exit status after a signal is 1 unless `ssh` reported its own.
The test re-runs the test binary as the tool, waits for the agent socket, sends each signal and checks the directory is gone.
Disclosure: the repeated `"uptime"` test literal became a `remoteCommand` constant because `goconst` required it.
Model: opus-4-8 (implementation, review); fable-5-1 (merge message)
keyfunc --version printed dev for any binary not built with make build. When no version was stamped at build time, the tool now reports the module version recorded in the binary's build info, which go install fills in. A stamped version still wins, and a local build with neither still prints dev.
Model: opus-4-8 (implementation); fable-5-1 (summary)
keyfunc ssh install appends the public line on a host through the system ssh, only when absent, feeding the line on standard input; keyfunc ssh to serves the derived key from an in-process agent on a private socket and runs the system ssh with it, the private key never on disk. Two review rounds; the second passed with no findings.
Model: opus-5 (implementation and review); fable-5-1 (landing)
keyfunc age derives an age identity at the generic path the way secret's agehd does, prints the recipient or the identity, and encrypts to or decrypts with it, the derived recipient always among encrypt's recipients. Two review rounds; the second passed with no findings, the clamping step now pinned by a fixed identity test.
Model: opus-5 (implementation and review); fable-5-1 (landing)
keyfunc mnemonic derives a 12, 18 or 24 word child mnemonic through BIP-85's own mnemonic application, with the specification's test vectors as tests. One review round, passed with no findings; the reviewer reproduced the vectors from an implementation written from the specification alone.
Model: opus-5 (implementation and review); fable-5-1 (landing)
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.
Model: opus-5 (implementation and review); fable-5-1 (landing)