Give each failure one error value (closes #113)
check / check (push) Failing after 3s

internal/cli's copies of vault.ErrSecretNotFound, ErrVaultNotFound,
ErrVersionNotFound and ErrSecretExists are removed; the commands wrap the
vault errors. Every error of secret.ReadPassphrase wraps
ErrPassphraseNotRead, so its callers no longer add those words.
ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a key the keyring
lacks, recognised by gpg's status line. storeInKeychain returns
errNilDataBuffer. bip85's ErrPasswordTooShort and ErrEncodedTooShort go
with their unreachable checks. Tests that matched these errors' text use
errors.Is.

Model: opus-5-5
This commit is contained in:
2026-10-04 21:39:24 +00:00
parent 176095e3d1
commit a83743383e
19 changed files with 159 additions and 97 deletions
+4 -26
View File
@@ -59,16 +59,6 @@ var (
// ErrInvalidBase85PwdLen is returned when the Base85 password length
// is out of range.
ErrInvalidBase85PwdLen = errors.New("pwdLen must be between 10 and 80")
// ErrPasswordTooShort is returned when the derived material is
// shorter than the requested password length. It carries only the
// middle of the message, which the caller composes as
// "derived password length <n> is shorter than requested length <m>",
// so the emitted text is unchanged.
ErrPasswordTooShort = errors.New("is shorter than requested length")
// ErrEncodedTooShort is returned when the encoded material is shorter
// than the requested password length. Composed as
// "encoded length <n> is less than requested length <m>".
ErrEncodedTooShort = errors.New("is less than requested length")
)
// Version bytes for extended keys
@@ -381,14 +371,8 @@ func DeriveBase64Password(
// Remove any padding
encodedStr = strings.TrimRight(encodedStr, "=")
// Slice to the desired password length
if len(encodedStr) < int(pwdLen) {
return "", fmt.Errorf(
"derived password length %d %w %d",
len(encodedStr), ErrPasswordTooShort, pwdLen,
)
}
// Slice to the desired password length: 64 bytes of entropy leave 86
// characters, the most pwdLen allows
return encodedStr[:pwdLen], nil
}
@@ -411,14 +395,8 @@ func DeriveBase85Password(
// Base85 encode all 64 bytes of entropy using the RFC1924 character set
encoded := encodeBase85WithRFC1924Charset(entropy)
// Slice to the desired password length
if len(encoded) < int(pwdLen) {
return "", fmt.Errorf(
"encoded length %d %w %d",
len(encoded), ErrEncodedTooShort, pwdLen,
)
}
// Slice to the desired password length: 64 bytes of entropy give 80
// characters, the most pwdLen allows
return encoded[:pwdLen], nil
}