Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
407490f824 |
@@ -250,15 +250,14 @@ identity's own recipient, plus any given with `--to`, so the same mnemonic can
|
||||
always decrypt what it encrypted. Output goes to `-o` or standard output;
|
||||
`--armor` writes the text form. Nothing is written except the output.
|
||||
|
||||
A `-o` path that is the same file as the tool's own standard output or standard
|
||||
error, under any name such as `/dev/stdout` or `/dev/fd/2`, is written to that
|
||||
stream, as leaving out `-o` writes to standard output; the file the stream is
|
||||
redirected to is written as the redirect says and never replaced, so with `>>`
|
||||
the output follows what the file already held. Otherwise, a regular file already
|
||||
at the `-o` path is replaced, and the new file has mode `0600`. A symlink there
|
||||
is followed, and what it points at is treated the same way, so the link keeps
|
||||
pointing where it did; a symlink that points at nothing is refused. A named pipe
|
||||
or a device, such as `/dev/null`, is written to directly.
|
||||
A regular file already at the `-o` path is replaced, and the new file has mode
|
||||
`0600`. A symlink there is followed, and what it points at is treated the same
|
||||
way, so the link keeps pointing where it did; a symlink that points at nothing
|
||||
is refused. A named pipe or a device, such as `/dev/null`, is written to
|
||||
directly. `-o /dev/stdout` writes to the tool's own standard output, as leaving
|
||||
out `-o` does, and `-o /dev/stderr` to its standard error; a file either stream
|
||||
is redirected to is written as the redirect says and never replaced, so with
|
||||
`>>` the output follows what the file already held.
|
||||
|
||||
### `keyfunc age decrypt [-n N] [-o <file>] [<file>]`
|
||||
|
||||
@@ -307,12 +306,12 @@ already at the named path as it was, and exit with status 1. That holds for a
|
||||
signal that has reached `keyfunc` when its input ends; a later one leaves the
|
||||
whole file in place. Ctrl-C on a pipeline ends the input at the same moment, and
|
||||
on Linux `keyfunc` sees the signal first, though no system promises that. A
|
||||
named pipe or a device at the `-o` path, or a path that is the same file as
|
||||
standard output or standard error, is written to directly, and the signal ends
|
||||
the tool there as it ends any other command. While `ssh to` or `ssh install` has
|
||||
`ssh` or `sftp` running, the signal ends that program instead, the tool removes
|
||||
its agent socket or working files, and it exits with status 1, or for `ssh to`
|
||||
with `ssh`'s own status if `ssh` reported one.
|
||||
named pipe or a device at the `-o` path, `/dev/stdout` or `/dev/stderr`, is
|
||||
written to directly, and the signal ends the tool there as it ends any other
|
||||
command. While `ssh to` or `ssh install` has `ssh` or `sftp` running, the signal
|
||||
ends that program instead, the tool removes its agent socket or working files,
|
||||
and it exits with status 1, or for `ssh to` with `ssh`'s own status if `ssh`
|
||||
reported one.
|
||||
|
||||
## Entrypoints
|
||||
|
||||
|
||||
+8
-30
@@ -141,10 +141,10 @@ func runDecrypt(cmd *cobra.Command, args []string) error {
|
||||
|
||||
// through opens the input the arguments ask for and hands it to the
|
||||
// work, with the file --output names to write to, or the command's own
|
||||
// output when it names none or names the same file as that output, and
|
||||
// the command's own error output when it names the same file as that.
|
||||
// Those two are the streams the tool already has, so whatever they are
|
||||
// redirected to is written as the redirect says, never replaced.
|
||||
// output when it names none or names /dev/stdout, and the command's own
|
||||
// error output when it names /dev/stderr. Those two are the streams the
|
||||
// tool already has, so whatever they are redirected to is written as
|
||||
// the redirect says, never replaced.
|
||||
func through(
|
||||
cmd *cobra.Command, args []string,
|
||||
work func(io.Writer, io.Reader) error,
|
||||
@@ -161,38 +161,16 @@ func through(
|
||||
return fmt.Errorf("reading the output file: %w", err)
|
||||
}
|
||||
|
||||
switch {
|
||||
case name == "", same(name, cmd.OutOrStdout()):
|
||||
switch name {
|
||||
case "", "/dev/stdout":
|
||||
return work(cmd.OutOrStdout(), src)
|
||||
case same(name, cmd.ErrOrStderr()):
|
||||
case "/dev/stderr":
|
||||
return work(cmd.ErrOrStderr(), src)
|
||||
default:
|
||||
return output(name, src, work)
|
||||
}
|
||||
}
|
||||
|
||||
// same reports whether the named path, followed to the end, is the
|
||||
// file the stream writes to, whatever name it is reached by, such as
|
||||
// /dev/stdout or /dev/fd/1 for standard output.
|
||||
func same(name string, stream io.Writer) bool {
|
||||
file, ok := stream.(*os.File)
|
||||
if !ok {
|
||||
return false
|
||||
}
|
||||
|
||||
streamInfo, err := file.Stat()
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
info, err := os.Stat(name)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
return os.SameFile(info, streamInfo)
|
||||
}
|
||||
|
||||
// input returns what to read from: the named file, or the command's
|
||||
// own input when no file is named. The second result closes a file
|
||||
// that was opened and does nothing otherwise.
|
||||
@@ -232,7 +210,7 @@ func output(
|
||||
case info.Mode().IsRegular():
|
||||
return replace(name, src, work)
|
||||
case info.Mode().Type() == fs.ModeSymlink:
|
||||
// os.Stat follows the link as opening it would. /dev/fd/3
|
||||
// os.Stat follows the link as opening it would. /dev/fd/1
|
||||
// needs that: it reaches a pipe or a terminal through a link
|
||||
// that names no path.
|
||||
info, err = os.Stat(name)
|
||||
|
||||
@@ -151,32 +151,14 @@ func TestANamedPipeAtTheOutputPathIsWrittenToAndStaysAPipe(t *testing.T) {
|
||||
require.Equal(t, "the secret\n", run(t, "age", "decrypt", sealedFile))
|
||||
}
|
||||
|
||||
func TestANameForStandardOutputAddsToTheFileItIsAppendedTo(t *testing.T) {
|
||||
func TestDevStdoutAddsToTheFileStandardOutputIsAppendedTo(t *testing.T) {
|
||||
t.Setenv(mnemonic.Variable, example())
|
||||
|
||||
sealed := filepath.Join(t.TempDir(), "notes.age")
|
||||
run(t, "age", "encrypt", "-o", sealed, written(t, "notes.txt", "the secret\n"))
|
||||
|
||||
for _, name := range []string{"/dev/stdout", "/dev/fd/1"} {
|
||||
appendedThrough(t, name, sealed)
|
||||
}
|
||||
}
|
||||
|
||||
// appendedThrough decrypts sealed with -o name while the tool's standard
|
||||
// output is appended to a file that already has contents, as the shell's
|
||||
// ">> notes.out" does, and checks that the file is the same one, with
|
||||
// the same mode, and holds its earlier contents and then the output.
|
||||
func appendedThrough(t *testing.T, name, sealed string) {
|
||||
t.Helper()
|
||||
|
||||
// A mode of its own, so that a replaced file would show.
|
||||
const ownMode = 0o644
|
||||
|
||||
// What the shell's ">> notes.out" gives the tool as standard output.
|
||||
existing := written(t, "notes.out", "what was already there\n")
|
||||
require.NoError(t, os.Chmod(existing, ownMode))
|
||||
|
||||
before, err := os.Stat(existing)
|
||||
require.NoError(t, err)
|
||||
|
||||
//nolint:gosec // the test made this path itself
|
||||
appended, err := os.OpenFile(existing, os.O_WRONLY|os.O_APPEND, 0)
|
||||
@@ -186,21 +168,16 @@ func appendedThrough(t *testing.T, name, sealed string) {
|
||||
|
||||
//nolint:gosec // this test's own binary as the tool
|
||||
command := exec.CommandContext(
|
||||
t.Context(), os.Args[0], "age", "decrypt", "-o", name, sealed,
|
||||
t.Context(), os.Args[0], "age", "decrypt", "-o", "/dev/stdout", sealed,
|
||||
)
|
||||
|
||||
command.Env = append(os.Environ(), runAsTool+"=1")
|
||||
command.Stdout = appended
|
||||
|
||||
require.NoError(t, command.Run(), name)
|
||||
require.NoError(t, command.Run())
|
||||
require.Equal(t,
|
||||
"what was already there\nthe secret\n", read(t, existing), name,
|
||||
"what was already there\nthe secret\n", read(t, existing),
|
||||
)
|
||||
|
||||
after, err := os.Stat(existing)
|
||||
require.NoError(t, err)
|
||||
require.True(t, os.SameFile(before, after), name)
|
||||
require.Equal(t, os.FileMode(ownMode), after.Mode().Perm(), name)
|
||||
}
|
||||
|
||||
func TestASignalStopsAnEncryptionAndLeavesNoFile(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user