Give each failure one error value (closes #113)
check / check (push) Failing after 3s

internal/cli's copies of vault.ErrSecretNotFound, ErrVaultNotFound,
ErrVersionNotFound and ErrSecretExists are removed; the commands wrap the
vault errors. Every error of secret.ReadPassphrase wraps
ErrPassphraseNotRead, so its callers no longer add those words.
ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a key the keyring
lacks, recognised by gpg's status line. storeInKeychain returns
errNilDataBuffer. bip85's ErrPasswordTooShort and ErrEncodedTooShort go
with their unreachable checks. Tests that matched these errors' text use
errors.Is.

Model: opus-5-5
This commit is contained in:
2026-10-04 21:39:24 +00:00
parent 176095e3d1
commit a83743383e
19 changed files with 159 additions and 97 deletions
+21
View File
@@ -18,6 +18,27 @@ https://git.eeqj.de/sneak/secret/milestone/12
# Completed Steps
- 2026-10-04: A failure returns the same error value whichever command hits
it (https://git.eeqj.de/sneak/secret/issues/113). `internal/cli` no longer
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
the `vault` errors. Messages are unchanged, except that `secret decrypt`
of a missing secret says "not found", as `secret get` does, not "does not
exist". Every error of `secret.ReadPassphrase` wraps
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
passphrase" that its callers used to add themselves; so two passphrases
that differ now give only "passphrases do not match", the words now follow
"failed to read mnemonic:" and "failed to read passphrase confirmation:",
and a terminal read error no longer repeats them. A GPG key the keyring
does not hold gives `secret.ErrGPGKeyNotFound`, found by gpg's status line
for "No public key"; before, the message repeated "failed to resolve GPG
key fingerprint" and ended in gpg's exit status. The keychain unlocker
returns `errNilDataBuffer` for nil data; this and its test build only on
macOS with cgo and were only read. `bip85.ErrPasswordTooShort` and
`ErrEncodedTooShort` are removed with their checks: 64 bytes of entropy
always give 86 Base64 or 80 Base85 characters, the most a password length
may ask for. Tests that matched these errors' text use `errors.Is`.
- 2026-10-04: Tests check which error a failure returns with `errors.Is`,
not by matching words of its message
(https://git.eeqj.de/sneak/secret/issues/49). Every exported error that