2 Commits
Author SHA1 Message Date
sneak 6300a48451 Signals end every command, not only ssh to and ssh install (closes #48)
check / check (push) Failing after 3s
SIGINT, SIGTERM and SIGHUP were caught for the whole run, but only the
ssh and sftp children acted on them: the mnemonic prompt waited for
Enter, and an interrupted `age encrypt -o` put the encryption of the
cut-off input in place. Now they end the tool at once, except where a
command cleans up first: `ssh to` and `ssh install` while ssh or sftp
runs, and `age encrypt -o` and `age decrypt -o` while they write, where
a signal up to a tenth of a second after the input ends still removes
the unfinished file and exits 1. Those commands catch only the signals
the tool was not started ignoring, so a run under nohup survives a
hangup.

Model: opus-5-5
2026-10-04 07:52:57 +00:00
clawbot 1d1c8182be Current templates: safe.directory, golangci-lint v2.14.0, fetch-depth 0, the policy's last stage (closes #50)
check / check (push) Failing after 2s
Brings keyfunc to the current sneak/prompts templates: REPO_POLICIES.md and .golangci.yml are the template copies, the lint phase runs golangci-lint v2.14.0 on the template digest (its one new finding fixed), and .dockerignore gains the template line for submodule configs. The stage that compiles keyfunc marks /src safe for git, so a context sent as a tar stream still stamps the tag or short commit. The last stage is now a development environment, as the policy asks of a non-server repo: run the tool as docker run IMAGE keyfunc .... The CI checkout fetches tags.

Deviation: .gitea/workflows/check.yml differs from the template copy by fetch-depth: 0, which REPO_POLICIES.md requires.

Model: opus-5-5
2026-10-04 08:59:08 +02:00
13 changed files with 427 additions and 119 deletions
+3
View File
@@ -17,7 +17,10 @@
# stage that compiles runs `git describe --tags --always` on .git, which
# does not need .git/config; that file can hold a credential, such as a
# password in a remote URL or the token the CI checkout step stores there.
# Each submodule keeps a config with the same exposure in its git directory
# under .git/modules/, nested again for a submodule's own submodules.
.git/config
.git/modules/**/config
# Agent scratch: one full checkout of the repo per in-flight agent.
# Anchored because it occurs once where agents run at the repo root.
+3
View File
@@ -6,4 +6,7 @@ jobs:
steps:
# actions/checkout v4.2.2, 2026-02-22
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
# All history and tags, which `git describe --tags` needs.
fetch-depth: 0
- run: script/cibuild
+1
View File
@@ -17,6 +17,7 @@ linters:
disable:
# Genuinely incompatible with project patterns
- exhaustruct # Requires all struct fields
- exhaustruct_v5 # Requires all struct fields (successor to exhaustruct)
- godot # Requires comments to end with periods
- wrapcheck # Too verbose for internal packages
- varnamelen # Short names like db, id are idiomatic Go
+27 -29
View File
@@ -1,11 +1,11 @@
# The lint phase, the test phase and the build. script/lint and
# script/test each build one phase alone; a plain `docker build .` builds
# both, because the build stage copies a file from each. Formatting is
# checked on the host by script/fmt-check, not here.
# The lint phase, the test phase and a development environment.
# script/lint and script/test each build one phase alone; a plain
# `docker build .` builds both, because the last stage copies a file from
# each. Formatting is checked on the host by script/fmt-check, not here.
# Lint phase
# golangci/golangci-lint:v2.12.2, 2026-09-07
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
# golangci/golangci-lint:v2.14.0, 2026-10-04
FROM golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f AS lint
WORKDIR /src
@@ -16,13 +16,12 @@ COPY . .
RUN golangci-lint run --config .golangci.yml ./...
# Test phase
# golang:1.26-alpine, 2026-09-07. It carries Go 1.26.8, the version
# script/bootstrap installs on the host; change both together.
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS test
# -race needs cgo, and cgo needs a C toolchain.
RUN apk add --no-cache gcc musl-dev
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
# image ships.
# golang:1.26.8-trixie, 2026-10-04. It carries Go 1.26.8, the version
# script/bootstrap installs on the host; change both together, and the
# same image in the last stage.
FROM golang@sha256:eae2aaa6add2936cbf350dd0d2628b363461542f0c4b3c0b558957e0f2997379 AS test
WORKDIR /src
@@ -35,21 +34,27 @@ RUN go test -timeout 90s -race -cover ./... || \
{ echo "--- Rerunning with -v for details ---"; \
go test -timeout 90s -race -v ./...; exit 1; }
# Build stage. Nothing is wanted from either phase above; the copies
# are what make BuildKit build them first, so this stage cannot run
# unless lint and test passed.
# golang:1.26-alpine, 2026-09-07
FROM golang@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS builder
# Development environment, and the last stage: a plain `docker build .`
# builds this one. It holds the source tree in /src, what
# script/bootstrap installs, and keyfunc built from that tree on the
# PATH. Nothing is wanted from either phase above; the copies are what
# make BuildKit build them first, so this stage cannot run unless lint
# and test passed.
# golang:1.26.8-trixie, 2026-10-04
FROM golang@sha256:eae2aaa6add2936cbf350dd0d2628b363461542f0c4b3c0b558957e0f2997379
COPY --from=lint /src/go.sum /dev/null
COPY --from=test /src/go.sum /dev/null
RUN apk add --no-cache make git
# A tar-stream context keeps the sender's file owners, which git refuses.
RUN git config --system --add safe.directory /src
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
# script/bootstrap needs only script/ and the dependency manifests.
COPY script/ script/
COPY go.mod go.sum package.json yarn.lock ./
RUN script/bootstrap
COPY . .
@@ -64,11 +69,4 @@ RUN version="${VERSION:-$(git describe --tags --always || echo dev)}"; \
echo "no version could be derived although the build context carries .git" >&2; \
exit 1; \
fi; \
make build VERSION="$version"
# alpine:3.23, 2026-09-07
FROM alpine@sha256:fd791d74b68913cbb027c6546007b3f0d3bc45125f797758156952bc2d6daf40
COPY --from=builder /src/keyfunc /usr/local/bin/keyfunc
ENTRYPOINT ["keyfunc"]
make build VERSION="$version" && mv keyfunc /usr/local/bin/keyfunc
+16 -1
View File
@@ -288,6 +288,18 @@ girl mad pet galaxy egg matter matrix prison refuse sense ordinary nose
Errors go to standard error and the exit status is 1, except for `ssh to`, which
passes through `ssh`'s own exit status.
SIGINT, SIGTERM and SIGHUP end any command at once, at the mnemonic prompt too,
with the status a shell gives a program killed by that signal (130 for SIGINT).
An interrupted `age encrypt -o` or `age decrypt -o` leaves no file. While it is
writing the file, the signal makes it remove the unfinished file, leave a file
already at the named path as it was, and exit with status 1. It puts the file in
place a tenth of a second after its input ends, and a signal in that time still
counts: Ctrl-C on a pipeline also ends the program feeding it, so the input can
end just before the signal arrives. While `ssh to` or `ssh install` has `ssh` or
`sftp` running, the signal ends that program instead, the tool removes its agent
socket or working files, and it exits with status 1, or for `ssh to` with
`ssh`'s own status if `ssh` reported one.
## Entrypoints
The repo adheres to the
@@ -331,7 +343,10 @@ standard: most Makefile targets are thin shims over an executable in `script/`
- `script/docker` builds the Docker image, uncached, tagged with the project
name and stamped with the version `git describe` gives on the host. The image
cannot be built unless the `lint` and `test` phases pass, so a plain
`docker build .` runs them too.
`docker build .` runs them too. The image is a development environment, not a
runtime image: the Debian Go image with what `script/bootstrap` installs, the
source tree in `/src`, and `keyfunc` built from it on the `PATH`.
`docker run --rm -it keyfunc` opens a shell in it.
- `script/cibuild` is the CI build the Gitea workflow calls: it runs
`bootstrap`, then `check`, then builds the image as `script/docker` does.
- `script/precommit` is what the git pre-commit hook runs: `go mod tidy` and
+55 -36
View File
@@ -1,6 +1,6 @@
---
title: Repository Policies
last_modified: 2026-10-02
last_modified: 2026-10-04
---
This document covers repository structure, tooling, and workflow standards. Code
@@ -160,7 +160,7 @@ style conventions are in separate documents:
- **The gate phases are separate stages, and the build stage depends on both.**
The lint phase is based on the `golangci/golangci-lint` image (pinned by
hash), so lint failures surface in seconds rather than after a full compile,
and the test phase is based on the Go image. The canonical Go repo
and the test phase is based on the Debian Go image. The canonical Go repo
`Dockerfile`:
```dockerfile
@@ -173,8 +173,9 @@ style conventions are in separate documents:
COPY . .
RUN golangci-lint run --config .golangci.yml ./...
# Test phase
# golang:1.x-alpine, YYYY-MM-DD
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
# image ships and the alpine one does not.
# golang:1.x, YYYY-MM-DD
FROM golang@sha256:... AS test
WORKDIR /src
COPY go.mod go.sum ./
@@ -192,6 +193,8 @@ style conventions are in separate documents:
COPY --from=lint /src/go.sum /dev/null
COPY --from=test /src/go.sum /dev/null
RUN apk add --no-cache git
# A tar-stream context keeps the sender's file owners, which git refuses.
RUN git config --system --add safe.directory /src
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
@@ -236,19 +239,23 @@ style conventions are in separate documents:
- If the project requires CGO or system libraries for linting (e.g.
`vips-dev`), install them in the lint phase with `apk add`.
- `.dockerignore` lets `.git` into the build context. It keeps out
`.git/config`, which `git describe` does not need and which can hold a
credential: a password in a remote URL, or the token the CI checkout step
stores there. The stage that compiles has `git` (the Debian Go image has
it; an alpine one needs `apk add --no-cache git`) and takes the version
from the `VERSION` build argument when one is given, otherwise from
`git describe --tags --always`. That gives the tag on a tagged commit; on
a later commit, the tag, the number of commits since it and the short
commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is
reachable. `ARG VERSION` has no default, and the build fails if the
context carries `.git` and the version still comes out empty, `dev` or
`unknown`. A plain `docker build .` with no build arguments must succeed;
a Dockerfile that refuses an empty build argument drops that refusal and
keeps the argument.
`.git/config` and each submodule's `config` under `.git/modules/` at any
depth (`.git/modules/**/config`), which `git describe` does not need and
which can hold a credential: a password in a remote URL, or the token the
CI checkout step stores there. The stage that compiles has `git` (the
Debian Go image has it; an alpine one needs `apk add --no-cache git`) and
takes the version from the `VERSION` build argument when one is given,
otherwise from `git describe --tags --always`. That gives the tag on a
tagged commit; on a later commit, the tag, the number of commits since it
and the short commit (`v1.2.3-4-gabc1234`); and the short commit when no
tag is reachable. The stage that compiles also marks its working directory
safe for git (`git config --system --add safe.directory /src`): a context
sent as a tar stream keeps the sender's file owners, and git refuses a
checkout owned by another user, so the version would come out empty.
`ARG VERSION` has no default, and the build fails if the context carries
`.git` and the version still comes out empty, `dev` or `unknown`. A plain
`docker build .` with no build arguments must succeed; a Dockerfile that
refuses an empty build argument drops that refusal and keeps the argument.
- Every repo should have a Gitea Actions workflow (`.gitea/workflows/`) that
runs `script/cibuild` on push, and checks out the repo as its only other step.
@@ -310,17 +317,19 @@ style conventions are in separate documents:
```
`-count=1` is required on both invocations: it defeats Go's test _result_
cache, so the target cannot report a pass it did not earn, and the rerun
reproduces a failure instead of replaying it. It leaves the build cache
alone, so it costs the runtime of the suite and no recompilation.
cache, so neither run can report a stored pass in place of running the
tests. It leaves the build cache alone, so it costs the runtime of the suite
and no recompilation.
Note that this is a second, independent cache, stacked below the Docker
layer cache that [issue #26](https://git.eeqj.de/sneak/prompts/issues/26)
addresses. `CHECK_EPOCH` guarantees the `RUN make test` _step_ re-executes;
it does not guarantee `go test` inside that step does any work, because the
`GOCACHE` baked into earlier image layers survives into the re-executed
step. They are two separate defects requiring two separate fixes, and a fix
for one must not be recorded as covering the other.
That cache is Go's own, separate from Docker's layer cache. Go stores a
passing result in its cache directory (`GOCACHE`), and when the same tests
run again on unchanged code it prints that result, marked `(cached)`,
without running them. That matters on a developer's machine, where this
target runs and the directory lasts from one run to the next. The `test`
phase of the `Dockerfile` needs no `-count=1`: its base image holds no
result for this repo's tests and nothing before its `go test` step runs a
test, so there is nothing to replay. `--no-cache` (above) is what makes that
step run on an unchanged tree.
Python example:
@@ -451,12 +460,18 @@ style conventions are in separate documents:
`test-support` depguard rule, where a repo names its own test-support packages
by full import path. A repo adds entries there and changes nothing else, and a
re-vendor carries its entries forward. The canonical golangci-lint version is
v2.12.2 (released 2026-05-06), pinned as the digest of the lint phase's base
v2.14.0 (released 2026-09-24), pinned as the digest of the lint phase's base
image
(`golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240`,
which reports `2.12.2 built with go1.26.2 from c0d3ddc9`). That digest is the
only pin, since no repo installs golangci-lint on the host: bumping the
version means changing it and nothing else.
(`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`,
which reports `2.14.0 built with go1.27.0 from 114493f9`). A module's `go`
directive must not name a newer Go minor version than the one golangci-lint
was built with, or golangci-lint refuses to lint it: this release lints
`go 1.27.1` but not `go 1.28`. That digest is the only pin, since no repo
installs golangci-lint on the host. A repo sets the lint phase digest to the
one named here and re-vendors `.golangci.yml` in the same commit, whichever of
the two prompted the change: the canonical copy can name linters that an older
golangci-lint rejects, and a newer golangci-lint can add linters that
`default: all` switches on until the canonical copy disables them.
- **`script/bootstrap` installs a pinned tool by comparing versions, never by
testing presence.** An `if ! command -v <tool>; then install; fi` guard tests
@@ -592,10 +607,10 @@ style conventions are in separate documents:
settings.
- Avoid putting files in the repo root unless necessary. Root should contain
only project-level config files (`README.md`, `Makefile`, `Dockerfile`,
`LICENSE`, `.gitignore`, `.editorconfig`, `REPO_POLICIES.md`, and
language-specific config). Everything else goes in a subdirectory. Canonical
subdirectory names:
only project-level config files (`README.md`, `AGENTS.md`, `Makefile`,
`Dockerfile`, `LICENSE`, `.gitignore`, `.editorconfig`, `REPO_POLICIES.md`,
and language-specific config). Everything else goes in a subdirectory.
Canonical subdirectory names:
- `bin/` — executable scripts and tools
- `cmd/` — Go command entrypoints; thin only: one `main.go` per binary whose
body is a single call into `internal/` or `pkg/`, no project logic in
@@ -626,3 +641,7 @@ style conventions are in separate documents:
- Go: `go.mod`, `go.sum`, `.golangci.yml`
- JS: `package.json`, `yarn.lock`, `.prettierrc`, `.prettierignore`
- Python: `pyproject.toml`
- Guidance for coding agents lives in one `AGENTS.md` at the repository root. It
is never committed under a file or directory named after one agent tool, such
as `CLAUDE.md` or `.claude/`, and never split into separate memory files.
+55 -27
View File
@@ -3,17 +3,33 @@
package age
import (
"context"
"errors"
"fmt"
"io"
"os"
"path/filepath"
"time"
"github.com/spf13/cobra"
"sneak.berlin/go/keyfunc/internal/agekey"
"sneak.berlin/go/keyfunc/internal/cli/options"
"sneak.berlin/go/keyfunc/internal/cli/signals"
"sneak.berlin/go/keyfunc/internal/derive"
)
// ErrInterrupted is returned when SIGINT, SIGTERM or SIGHUP came before
// the file --output names was put in place.
var ErrInterrupted = errors.New(
"interrupted by a signal; the output file was left as it was",
)
// signalWait is how long after the work has ended a signal still keeps
// the new file from being put in place. Ctrl-C on "producer | keyfunc
// age encrypt -o file" ends the producer as well, and the end of the
// input can reach the work a moment before the signal reaches the tool.
const signalWait = 100 * time.Millisecond
// Command returns the age command and everything under it.
func Command() *cobra.Command {
group := &cobra.Command{
@@ -128,8 +144,9 @@ func runDecrypt(cmd *cobra.Command, args []string) error {
return through(cmd, args, key.Decrypt)
}
// through opens the input and the output the arguments ask for, hands
// them to the work, and finishes the output afterwards either way.
// through opens the input the arguments ask for and hands it to the
// work, with the file --output names to write to, or the command's own
// output when it names none.
func through(
cmd *cobra.Command, args []string,
work func(io.Writer, io.Reader) error,
@@ -141,14 +158,16 @@ func through(
defer closeSrc()
dst, done, err := output(cmd)
name, err := cmd.Flags().GetString("output")
if err != nil {
return err
return fmt.Errorf("reading the output file: %w", err)
}
err = work(dst, src)
if name == "" {
return work(cmd.OutOrStdout(), src)
}
return done(err)
return output(name, src, work)
}
// input returns what to read from: the named file, or the command's
@@ -167,35 +186,44 @@ func input(cmd *cobra.Command, args []string) (io.Reader, func(), error) {
return file, func() { _ = file.Close() }, nil
}
// output returns what to write to: a new file beside the one --output
// names, or the command's own output when it names none. The second
// result finishes the write, and is given whatever the work returned:
// the new file takes the named file's place only when the work
// succeeded, so a file that is already there survives a run that
// failed.
func output(cmd *cobra.Command) (io.Writer, func(error) error, error) {
name, err := cmd.Flags().GetString("output")
if err != nil {
return nil, nil, fmt.Errorf("reading the output file: %w", err)
}
if name == "" {
return cmd.OutOrStdout(), func(failed error) error {
return failed
}, nil
}
// output has the work write a new file beside the named one, and puts
// the new file in the named file's place only when the work succeeded,
// so a file that is already there survives a run that failed.
//
// Meanwhile SIGINT, SIGTERM and SIGHUP are caught, as signals.Context
// does. One that comes while the work runs, or within signalWait after
// it has ended, wins: the new file is removed and ErrInterrupted
// returned at once, without waiting for the work, which may be blocked
// reading its input.
func output(
name string, src io.Reader, work func(io.Writer, io.Reader) error,
) error {
interrupted, stop := signals.Context(context.Background())
defer stop()
// The file is made in the same directory so that putting it in
// place is a rename and never a copy, and it is readable only by
// its owner, which is the mode it keeps once renamed.
file, err := os.CreateTemp(filepath.Dir(name), filepath.Base(name)+".")
if err != nil {
return nil, nil, fmt.Errorf("creating a file beside %s: %w", name, err)
return fmt.Errorf("creating a file beside %s: %w", name, err)
}
return file, func(failed error) error {
return finish(file, name, failed)
}, nil
worked := make(chan error, 1)
go func() { worked <- work(file, src) }()
select {
case failed := <-worked:
select {
case <-interrupted.Done():
case <-time.After(signalWait):
return finish(file, name, failed)
}
case <-interrupted.Done():
}
return finish(file, name, ErrInterrupted)
}
// finish closes the new file and puts it in the named file's place, or
+138
View File
@@ -1,10 +1,14 @@
package cli_test
import (
"io"
"os"
"os/exec"
"path/filepath"
"strings"
"syscall"
"testing"
"time"
"github.com/stretchr/testify/require"
"sneak.berlin/go/keyfunc/internal/agekey"
@@ -90,6 +94,140 @@ func TestARefusedDecryptionLeavesTheOutputFileAlone(t *testing.T) {
require.Equal(t, "what was already there\n", string(kept))
}
func TestASignalStopsAnEncryptionAndLeavesNoFile(t *testing.T) {
t.Setenv(mnemonic.Variable, example())
for _, ending := range []os.Signal{
syscall.SIGTERM, syscall.SIGINT, syscall.SIGHUP,
} {
interrupted(t, ending, "encrypt", "the start of the secret\n", false)
}
}
func TestASignalStopsADecryptionAndLeavesNoFile(t *testing.T) {
t.Setenv(mnemonic.Variable, example())
// All of an encryption but its last byte, so the tool reads the
// header and then waits for the rest.
sealed := run(t, "age", "encrypt", written(t, "notes.txt", "the secret\n"))
cut := sealed[:len(sealed)-1]
for _, ending := range []os.Signal{
syscall.SIGTERM, syscall.SIGINT, syscall.SIGHUP,
} {
interrupted(t, ending, "decrypt", cut, false)
}
}
func TestASignalAsTheInputEndsLeavesNoFile(t *testing.T) {
t.Setenv(mnemonic.Variable, example())
sealed := run(t, "age", "encrypt", written(t, "notes.txt", "the secret\n"))
// Ctrl-C on "producer | keyfunc age encrypt -o file" ends the
// producer too, so the input ends just as the signal comes, with
// enough of it in hand for a whole encryption or decryption. Which
// of the two reaches the tool first varies, so it is tried often.
for range 25 {
interrupted(t, syscall.SIGINT, "encrypt", "the start of the secret\n", true)
interrupted(t, syscall.SIGINT, "decrypt", sealed, true)
}
}
func TestAnEncryptionStartedUnderNohupSurvivesAHangup(t *testing.T) {
t.Setenv(mnemonic.Variable, example())
directory := t.TempDir()
named := filepath.Join(directory, "notes")
// nohup starts the tool with SIGHUP ignored. A tool that caught it
// anyway would turn it back on and be ended by it.
command, producer := writing(
t, directory, "the secret\n",
"nohup", os.Args[0], "age", "encrypt", "-o", named,
)
require.NoError(t, command.Process.Signal(syscall.SIGHUP))
require.NoError(t, producer.Close())
waitForTool(t, "SIGHUP under nohup", command)
require.Equal(t, 0, command.ProcessState.ExitCode())
left, err := os.ReadDir(directory)
require.NoError(t, err)
require.Len(t, left, 1)
require.Equal(t, "the secret\n", run(t, "age", "decrypt", named))
}
// interrupted runs "age encrypt -o" or "age decrypt -o", as the
// operation says, writing into a directory of its own, and once it has
// begun writing sends it the signal, then ends the input if endInput
// says so and otherwise leaves it open. The tool has to end with status
// 1 and leave the directory empty. A tool that went on reading would
// not end until the input did; one that did not remove the file it was
// writing would leave it there, with what it had written so far; one
// that put that file in place because the input ended would leave the
// named file.
func interrupted(
t *testing.T, signal os.Signal, operation, input string, endInput bool,
) {
t.Helper()
name := operation + " " + signal.String()
directory := t.TempDir()
command, producer := writing(
t, directory, input,
os.Args[0], "age", operation, "-o", filepath.Join(directory, "notes"),
)
require.NoError(t, command.Process.Signal(signal))
if endInput {
require.NoError(t, producer.Close())
}
waitForTool(t, name, command)
require.Equal(t, 1, command.ProcessState.ExitCode(), name)
left, err := os.ReadDir(directory)
require.NoError(t, err)
require.Empty(t, left, name)
}
// writing starts argv, the tool told to write into directory, as a
// subprocess reading the input from a pipe, and returns once the tool
// has begun writing the file beside the one it was named. The pipe is
// left open for the caller to end.
func writing(
t *testing.T, directory, input string, argv ...string,
) (*exec.Cmd, io.WriteCloser) {
t.Helper()
//nolint:gosec // this test's own binary as the tool, or nohup running it
command := exec.CommandContext(t.Context(), argv[0], argv[1:]...)
command.Env = append(os.Environ(), runAsTool+"=1")
producer, err := command.StdinPipe()
require.NoError(t, err)
require.NoError(t, command.Start())
_, err = io.WriteString(producer, input)
require.NoError(t, err)
// The file beside the named one is made once the mnemonic has been
// read, before any input is.
require.Eventually(t, func() bool {
entries, err := os.ReadDir(directory)
return err == nil && len(entries) > 0
}, 5*time.Second, 5*time.Millisecond)
return command, producer
}
// written puts the contents in a file of that name in a directory of
// this test's own and returns the path to it.
func written(t *testing.T, name, contents string) string {
+9 -16
View File
@@ -2,13 +2,10 @@
package cli
import (
"context"
"errors"
"fmt"
"os"
"os/signal"
"runtime/debug"
"syscall"
"github.com/spf13/cobra"
"sneak.berlin/go/keyfunc/internal/cli/age"
@@ -70,24 +67,20 @@ func Root() *cobra.Command {
// ended with. ssh has already said whatever it had to say in that
// case, so nothing more is printed.
//
// SIGINT, SIGTERM and SIGHUP cancel the command's context instead of
// killing the process outright, so the child ssh or sftp ends and the
// deferred cleanup that removes the agent socket and the install
// working directory still runs.
// SIGINT, SIGTERM and SIGHUP end the tool at once, as they end any Go
// program, so a command waiting at the mnemonic prompt or reading what
// it encrypts or decrypts goes no further. The exceptions catch the
// signals to clean up first: "ssh to" and "ssh install" while they
// have ssh or sftp running, so the child ends and their own cleanup
// still runs, and "age encrypt -o" and "age decrypt -o" while they
// write, so the unfinished file is removed.
func Main() int {
ctx, stop := signal.NotifyContext(
context.Background(),
syscall.SIGINT, syscall.SIGTERM, syscall.SIGHUP,
)
defer stop()
err := Root().ExecuteContext(ctx)
err := Root().Execute()
if err == nil {
return 0
}
var passed ssh.StatusError
if errors.As(err, &passed) {
if passed, ok := errors.AsType[ssh.StatusError](err); ok {
return passed.Status
}
+34
View File
@@ -0,0 +1,34 @@
// Package signals catches the signals that end the tool, for the
// commands that clean up before they end.
package signals
import (
"context"
"os"
"os/signal"
"syscall"
)
// Context is signal.NotifyContext for SIGINT, SIGTERM and SIGHUP: the
// context it returns is cancelled when one of them arrives, and stop
// stops catching them. It leaves out any of the three the tool was
// started with set to be ignored, as nohup does with SIGHUP, because
// catching a signal turns an ignored one back on and would end a run
// that was meant to survive it.
func Context(parent context.Context) (context.Context, context.CancelFunc) {
endings := []os.Signal{syscall.SIGINT, syscall.SIGTERM, syscall.SIGHUP}
caught := make([]os.Signal, 0, len(endings))
for _, ending := range endings {
if !signal.Ignored(ending) {
caught = append(caught, ending)
}
}
// Given no signals at all, NotifyContext would catch every one.
if len(caught) == 0 {
return context.WithCancel(parent)
}
return signal.NotifyContext(parent, caught...)
}
+9
View File
@@ -13,6 +13,7 @@ import (
"strings"
"github.com/spf13/cobra"
"sneak.berlin/go/keyfunc/internal/cli/signals"
)
// Where the key goes on the host and what the file it arrives in is
@@ -62,6 +63,14 @@ func install() *cobra.Command {
return err
}
// From here on a signal cancels the context, which
// sftp runs under, instead of ending the tool, so sftp
// ends and the working directory is still removed.
ctx, stop := signals.Context(cmd.Context())
defer stop()
cmd.SetContext(ctx)
return add(cmd, args[0], args[1:], line)
},
}
+12 -5
View File
@@ -10,6 +10,7 @@ import (
"syscall"
"github.com/spf13/cobra"
"sneak.berlin/go/keyfunc/internal/cli/signals"
)
// StatusError says the tool should end with the status ssh ended with.
@@ -42,7 +43,14 @@ func to() *cobra.Command {
return err
}
served, err := key.Serve(cmd.Context(), comment)
// From here until the agent is taken down, a signal
// cancels the context instead of ending the tool, so
// ssh ends and the socket and its directory are still
// removed.
ctx, stop := signals.Context(cmd.Context())
defer stop()
served, err := key.Serve(ctx, comment)
if err != nil {
return err
}
@@ -53,7 +61,7 @@ func to() *cobra.Command {
"-o", "IdentityAgent=" + served.Socket(),
}, args)
return connect(cmd.Context(), argv)
return connect(ctx, argv)
},
}
@@ -76,7 +84,7 @@ func connect(ctx context.Context, argv []string) error {
command.Stdout = os.Stdout
command.Stderr = os.Stderr
// A cancelled context means a signal ended the tool. Send ssh a
// A cancelled context means a signal arrived. Send ssh a
// SIGTERM rather than the default kill, so it puts the terminal
// back the way it found it before it goes.
command.Cancel = func() error {
@@ -88,8 +96,7 @@ func connect(ctx context.Context, argv []string) error {
return nil
}
var ended *exec.ExitError
if errors.As(err, &ended) {
if ended, ok := errors.AsType[*exec.ExitError](err); ok {
status := ended.ExitCode()
if status < 0 {
// A signal ended ssh, and a signal has no status of its
+65 -5
View File
@@ -20,13 +20,13 @@ import (
// runAsTool, set in the environment of a re-executed test binary, tells
// TestMain to run the tool through Main rather than the suite, so the
// signal test can drive the real signal path in a process it can send a
// signal to.
// signal tests can drive the real signal path in a process they can
// send a signal to.
const runAsTool = "KEYFUNC_TEST_RUN_AS_TOOL"
// TestMain re-executes the test binary as the tool when runAsTool is
// set, and otherwise runs the suite. The signal test starts the tool
// this way, as a subprocess it can signal and watch clean up.
// set, and otherwise runs the suite. The signal tests start the tool
// this way, as a subprocess they can signal and watch end.
func TestMain(m *testing.M) {
if os.Getenv(runAsTool) == "1" {
os.Exit(cli.Main())
@@ -209,6 +209,16 @@ fi
sleep 5
`
// stalled is a stand-in for the system sftp that notes it has started
// and then blocks, so a test can signal the tool while sftp is running
// and watch it remove its working directory. The exec keeps the shell
// from leaving a sleep behind that holds the output the tool reads sftp
// through.
const stalled = `
touch "$KEYFUNC_TEST_STARTED"
exec sleep 5
`
// pretended is where a stand-in writes down what it was asked to do.
type pretended struct {
// home stands in for the home directory on the host.
@@ -544,7 +554,7 @@ func TestASignalTakesTheAgentDirectoryDown(t *testing.T) {
// ssh that blocks, waits until the agent is up and ssh is running
// against it, sends the tool the signal, and requires the agent socket
// and its directory to be gone once the tool has ended. The subprocess
// goes through Main and its signal handling, so with that handling
// goes through Main and the command's signal handling, so with that handling
// removed the signal kills the tool outright, no deferred cleanup runs,
// the directory is left behind, and the check fails.
func signalEndsTheTool(t *testing.T, name string, signal os.Signal) {
@@ -611,6 +621,56 @@ func waitForSocket(t *testing.T, noted string) string {
return socket
}
func TestASignalTakesTheInstallWorkingDirectoryDown(t *testing.T) {
t.Setenv(mnemonic.Variable, example())
for _, ending := range []os.Signal{
syscall.SIGTERM, syscall.SIGINT, syscall.SIGHUP,
} {
signalEndsTheInstall(t, ending.String(), ending)
}
}
// signalEndsTheInstall runs "ssh install" as a subprocess against a
// stand-in sftp that blocks, with a temporary directory of the test's
// own, waits until sftp is running, sends the tool the signal, and
// requires the working directory the tool made there to be gone once
// the tool has ended.
func signalEndsTheInstall(t *testing.T, name string, signal os.Signal) {
t.Helper()
temporary := t.TempDir()
started := filepath.Join(t.TempDir(), "started")
t.Setenv("KEYFUNC_TEST_STARTED", started)
standIn(t, "sftp", stalled)
//nolint:gosec // the binary is this test's own, re-run as the tool
command := exec.CommandContext(
t.Context(), os.Args[0], subcommand, installing, host,
)
command.Env = append(os.Environ(), runAsTool+"=1", "TMPDIR="+temporary)
require.NoError(t, command.Start())
// sftp is started only once the working directory has been made.
require.Eventually(t, func() bool {
_, err := os.Stat(started)
return err == nil
}, 5*time.Second, 5*time.Millisecond)
working, err := os.ReadDir(temporary)
require.NoError(t, err)
require.Len(t, working, 1, name)
require.NoError(t, command.Process.Signal(signal))
waitForTool(t, name, command)
left, err := os.ReadDir(temporary)
require.NoError(t, err)
require.Empty(t, left, name)
}
func TestTheMnemonicIsNotHandedToSFTP(t *testing.T) {
t.Setenv(mnemonic.CommandVariable, "echo "+example())
t.Setenv(mnemonic.Variable, example())