Give each failure one error value (closes #113)
check / check (push) Failing after 3s

internal/cli drops its copies of vault.ErrSecretNotFound, ErrVaultNotFound,
ErrVersionNotFound and ErrSecretExists and of the secret package's keychain
and Secure Enclave errors, and its second error for an unknown unlocker
type, an invalid mnemonic, a length below 1, an unsupported secret type and
an oversized secret. vault.ErrNilValueBuffer becomes
secret.ErrNilValueBuffer. Every error of secret.ReadPassphrase wraps
ErrPassphraseNotRead. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for
a key the keyring lacks. storeInKeychain returns errNilDataBuffer. bip85's
ErrPasswordTooShort and ErrEncodedTooShort go with their unreachable checks,
as does the macOS check in macOS-only code. Tests that matched these
errors' text use errors.Is.

Model: opus-5-5
This commit was merged in pull request #114.
This commit is contained in:
2026-10-05 01:08:01 +02:00
parent 176095e3d1
commit 43f66bf369
28 changed files with 271 additions and 162 deletions
+7 -16
View File
@@ -32,13 +32,7 @@ const (
// Sentinel errors for secret operations
var (
errSecretTooLarge = errors.New("secret too large: exceeds 100MB limit")
errSecretFileTooLarge = errors.New(
"secret file too large: exceeds 100MB limit")
errSecretNotFound = errors.New("not found")
errSecretExistsNoForce = errors.New(
"already exists (use --force to overwrite)")
errVaultDoesNotExist = errors.New("does not exist")
errSecretTooLarge = errors.New("secret too large: exceeds 100MB limit")
errCrossVaultSourceUnqualified = errors.New(
"source must specify vault (e.g., vault:secret) for cross-vault move")
errMoveOntoItself = errors.New("cannot be moved onto itself")
@@ -673,10 +667,6 @@ func (cli *Instance) ImportSecret(
buffers, totalSize, err := readSecretFromReader(file)
if err != nil {
if errors.Is(err, errSecretTooLarge) {
return errSecretFileTooLarge
}
return fmt.Errorf("failed to read secret from file %s: %w", sourceFile, err)
}
defer destroyBuffers(buffers)
@@ -776,7 +766,7 @@ func (cli *Instance) findSecretToRemove(
if !exists {
return secretToRemove{},
fmt.Errorf("secret '%s' %w", secretName, errSecretNotFound)
fmt.Errorf("secret '%s' %w", secretName, vault.ErrSecretNotFound)
}
// A secret without a versions directory has no versions, and can
@@ -907,7 +897,7 @@ func (cli *Instance) existingVault(name string) (*vault.Vault, error) {
}
if !slices.Contains(vaults, name) {
return nil, fmt.Errorf("vault '%s' %w", name, errVaultDoesNotExist)
return nil, fmt.Errorf("vault '%s' %w", name, vault.ErrVaultNotFound)
}
return vault.NewVault(cli.fs, cli.stateDir, name), nil
@@ -938,7 +928,7 @@ func (cli *Instance) moveSecretWithinVault(
}
if !exists {
return fmt.Errorf("secret '%s' %w", source, errSecretNotFound)
return fmt.Errorf("secret '%s' %w", source, vault.ErrSecretNotFound)
}
destEncoded := strings.ReplaceAll(dest, "/", "%")
@@ -963,7 +953,8 @@ func (cli *Instance) moveSecretWithinVault(
if exists {
if !force {
return fmt.Errorf("secret '%s' %w", dest, errSecretExistsNoForce)
return fmt.Errorf("secret '%s' %w (use --force to overwrite)",
dest, vault.ErrSecretExists)
}
err = secret.RemoveDirAtomic(cli.fs, destDir)
@@ -1028,7 +1019,7 @@ func (cli *Instance) moveSecretCrossVault(
exists, err := afero.DirExists(cli.fs, srcSecretDir)
if err != nil || !exists {
return fmt.Errorf("secret '%s' %w in vault '%s'",
srcSecretName, errSecretNotFound, srcVault.Name)
srcSecretName, vault.ErrSecretNotFound, srcVault.Name)
}
// The source is removed after the copy, so a destination that is the