internal/cli drops its copies of vault.ErrSecretNotFound, ErrVaultNotFound, ErrVersionNotFound and ErrSecretExists and of the secret package's keychain and Secure Enclave errors, and its second error for an unknown unlocker type, an invalid mnemonic, a length below 1, an unsupported secret type and an oversized secret. vault.ErrNilValueBuffer becomes secret.ErrNilValueBuffer. Every error of secret.ReadPassphrase wraps ErrPassphraseNotRead. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a key the keyring lacks. storeInKeychain returns errNilDataBuffer. bip85's ErrPasswordTooShort and ErrEncodedTooShort go with their unreachable checks, as does the macOS check in macOS-only code. Tests that matched these errors' text use errors.Is. Model: opus-5-5
This commit was merged in pull request #114.
This commit is contained in:
@@ -18,6 +18,10 @@ import (
|
||||
"github.com/spf13/afero"
|
||||
)
|
||||
|
||||
// gpgNoPublicKeyStatus is the status line gpg writes when it has no key for
|
||||
// the ID it was asked to list: 9 is gpg's error code for "No public key".
|
||||
const gpgNoPublicKeyStatus = "[GNUPG:] ERROR keylist.getkey 9\n"
|
||||
|
||||
var (
|
||||
errGPGKeyIDEmpty = errors.New("GPG key ID cannot be empty")
|
||||
errInvalidGPGKeyID = errors.New("invalid GPG key ID format")
|
||||
@@ -25,6 +29,10 @@ var (
|
||||
errNilDataBuffer = errors.New("data buffer is nil")
|
||||
)
|
||||
|
||||
// ErrGPGKeyNotFound is returned by ResolveGPGKeyFingerprint for a key ID
|
||||
// that matches no key in the GPG keyring.
|
||||
var ErrGPGKeyNotFound = errors.New("GPG key not found")
|
||||
|
||||
// Variables to allow overriding in tests
|
||||
var (
|
||||
// GPGEncryptFunc is the function used for GPG encryption
|
||||
@@ -367,14 +375,20 @@ func ResolveGPGKeyFingerprint(keyID string) (string, error) {
|
||||
return "", fmt.Errorf("invalid GPG key ID: %w", err)
|
||||
}
|
||||
|
||||
// Use GPG to get the full fingerprint for the key
|
||||
// Use GPG to get the full fingerprint for the key. --status-fd 1 adds
|
||||
// gpg's status lines to the output.
|
||||
cmd := exec.CommandContext( //nolint:gosec // G204: keyID validated above
|
||||
context.Background(),
|
||||
"gpg", "--list-keys", "--with-colons", "--fingerprint", keyID,
|
||||
"gpg", "--status-fd", "1",
|
||||
"--list-keys", "--with-colons", "--fingerprint", keyID,
|
||||
)
|
||||
|
||||
output, err := cmd.Output()
|
||||
if err != nil {
|
||||
if strings.Contains(string(output), gpgNoPublicKeyStatus) {
|
||||
return "", fmt.Errorf("%w: %s", ErrGPGKeyNotFound, keyID)
|
||||
}
|
||||
|
||||
return "", fmt.Errorf("failed to resolve GPG key fingerprint: %w", err)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user