internal/cli's copies of vault.ErrSecretNotFound, ErrVaultNotFound, ErrVersionNotFound and ErrSecretExists are removed; the commands wrap the vault errors. Every error of secret.ReadPassphrase wraps ErrPassphraseNotRead, so its callers no longer add those words. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a key the keyring lacks, recognised by gpg's status line. storeInKeychain returns errNilDataBuffer. bip85's ErrPasswordTooShort and ErrEncodedTooShort go with their unreachable checks. Tests that matched these errors' text use errors.Is. Model: opus-5-5
This commit is contained in:
@@ -18,6 +18,27 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: A failure returns the same error value whichever command hits
|
||||
it (https://git.eeqj.de/sneak/secret/issues/113). `internal/cli` no longer
|
||||
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
|
||||
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
|
||||
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
|
||||
the `vault` errors. Messages are unchanged, except that `secret decrypt`
|
||||
of a missing secret says "not found", as `secret get` does, not "does not
|
||||
exist". Every error of `secret.ReadPassphrase` wraps
|
||||
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
|
||||
passphrase" that its callers used to add themselves; so two passphrases
|
||||
that differ now give only "passphrases do not match", the words now follow
|
||||
"failed to read mnemonic:" and "failed to read passphrase confirmation:",
|
||||
and a terminal read error no longer repeats them. A GPG key the keyring
|
||||
does not hold gives `secret.ErrGPGKeyNotFound`, found by gpg's status line
|
||||
for "No public key"; before, the message repeated "failed to resolve GPG
|
||||
key fingerprint" and ended in gpg's exit status. The keychain unlocker
|
||||
returns `errNilDataBuffer` for nil data; this and its test build only on
|
||||
macOS with cgo and were only read. `bip85.ErrPasswordTooShort` and
|
||||
`ErrEncodedTooShort` are removed with their checks: 64 bytes of entropy
|
||||
always give 86 Base64 or 80 Base85 characters, the most a password length
|
||||
may ask for. Tests that matched these errors' text use `errors.Is`.
|
||||
- 2026-10-04: Tests check which error a failure returns with `errors.Is`,
|
||||
not by matching words of its message
|
||||
(https://git.eeqj.de/sneak/secret/issues/49). Every exported error that
|
||||
|
||||
Reference in New Issue
Block a user