Say the mnemonic still opens a vault its unlocker cannot (closes #47)
check / check (push) Failing after 2s

When the vault cannot be opened through its current unlocker, the error
now ends by saying that the vault still opens with its mnemonic, and
that 'secret unlocker add passphrase' run with SB_SECRET_MNEMONIC set
gives it a new unlocker; only when the vault metadata records the key
the mnemonic derives. 'secret encrypt' and 'secret decrypt' read the key
secret through vault.GetSecret, as 'secret get' does, so they say it
too. An unreadable 'current' file's error names 'secret version list'
and 'secret version promote'. Causes stay wrapped.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:04:32 +00:00
parent 1a23fd3125
commit af7246c608
5 changed files with 328 additions and 25 deletions
+2 -19
View File
@@ -130,7 +130,7 @@ func (cli *Instance) resolveEncryptionKey(
}
// Secret exists, get the age secret key from it
secretBuffer, err := cli.getSecretValue(vlt, secretObj)
secretBuffer, err := vlt.GetSecret(secretName)
if err != nil {
return nil, fmt.Errorf("failed to get secret value: %w", err)
}
@@ -249,7 +249,7 @@ func (cli *Instance) Decrypt(secretName, inputFile, outputFile string) error {
}
// Get the age secret key from the secret
secretBuffer, err := cli.getSecretValue(vlt, secretObj)
secretBuffer, err := vlt.GetSecret(secretName)
if err != nil {
return fmt.Errorf("failed to get secret value: %w", err)
}
@@ -313,20 +313,3 @@ func isValidAgeSecretKey(key string) bool {
return err == nil
}
// getSecretValue retrieves the value of a secret with the vault's mnemonic
// when it has one, else with the current unlocker
func (cli *Instance) getSecretValue(
vlt *vault.Vault, secretObj *secret.Secret,
) (*memguard.LockedBuffer, error) {
if vlt.Mnemonic != nil {
return secretObj.GetValue(nil, vlt.Mnemonic)
}
unlocker, err := vlt.GetCurrentUnlocker()
if err != nil {
return nil, fmt.Errorf("failed to get current unlocker: %w", err)
}
return secretObj.GetValue(unlocker, nil)
}