Give each failure one error value (closes #113)
check / check (push) Failing after 3s

internal/cli's copies of vault.ErrSecretNotFound, ErrVaultNotFound,
ErrVersionNotFound and ErrSecretExists are removed; the commands wrap the
vault errors. errUnsupportedUnlockerType is removed for
errInvalidUnlockerType, which names the same failure. Every error of
secret.ReadPassphrase wraps ErrPassphraseNotRead, so its callers no longer
add those words. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for a
key the keyring lacks, recognised by gpg's status line. storeInKeychain
returns errNilDataBuffer. bip85's ErrPasswordTooShort and
ErrEncodedTooShort go with their unreachable checks. Tests that matched
these errors' text use errors.Is.

Model: opus-5-5
This commit is contained in:
2026-10-04 22:09:27 +00:00
parent 176095e3d1
commit c0b02b3dcb
19 changed files with 175 additions and 99 deletions
+23
View File
@@ -18,6 +18,29 @@ https://git.eeqj.de/sneak/secret/milestone/12
# Completed Steps
- 2026-10-04: A failure returns the same error value whichever command hits
it (https://git.eeqj.de/sneak/secret/issues/113). `internal/cli` no longer
keeps its own copies of `vault.ErrSecretNotFound`, `ErrVaultNotFound`,
`ErrVersionNotFound` and `ErrSecretExists`: `secret mv`, `rm`, `decrypt`,
`vault import`, `vault remove` and `version list`, `promote` and `rm` wrap
the `vault` errors. `errUnsupportedUnlockerType` is removed: `secret
unlocker add` gives `errInvalidUnlockerType` for an unknown type, whichever
check rejects it. Messages are unchanged, except that `secret decrypt`
of a missing secret says "not found", as `secret get` does, not "does not
exist". Every error of `secret.ReadPassphrase` wraps
`secret.ErrPassphraseNotRead`, which supplies the words "failed to read
passphrase" that its callers used to add themselves; so two passphrases
that differ now give only "passphrases do not match", the words now follow
"failed to read mnemonic:" and "failed to read passphrase confirmation:",
and a terminal read error no longer repeats them. A GPG key the keyring
does not hold gives `secret.ErrGPGKeyNotFound`, found by gpg's status line
for "No public key"; before, the message repeated "failed to resolve GPG
key fingerprint" and ended in gpg's exit status. The keychain unlocker
returns `errNilDataBuffer` for nil data; this and its test build only on
macOS with cgo and were only read. `bip85.ErrPasswordTooShort` and
`ErrEncodedTooShort` are removed with their checks: 64 bytes of entropy
always give 86 Base64 or 80 Base85 characters, the most a password length
may ask for. Tests that matched these errors' text use `errors.Is`.
- 2026-10-04: Tests check which error a failure returns with `errors.Is`,
not by matching words of its message
(https://git.eeqj.de/sneak/secret/issues/49). Every exported error that