Read secret environment variables once per command, then unset them (closes #60)
check / check (push) Failing after 1s
check / check (push) Failing after 1s
init and vault create put the mnemonic into the process environment for vault.CreateVault to read back, so every program they ran, gpg included, inherited it, and SB_SECRET_MNEMONIC and SB_UNLOCK_PASSPHRASE were read at 13 places and never unset. Each command that may need them now reads both once, in its RunE, into locked buffers on the CLI Instance, and unsets them at once. The buffers are passed down: vault.CreateVault takes the mnemonic, a Vault carries Mnemonic and UnlockPassphrase, and the PGP, keychain and Secure Enclave unlocker constructors take both; CreatePGPUnlocker sets them on the vault it loads through SetMnemonic and SetUnlockPassphrase, new in VaultInterface. README warns against both variables. Model: opus-5-5
This commit was merged in pull request #94.
This commit is contained in:
@@ -25,6 +25,20 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `SB_SECRET_MNEMONIC` and `SB_UNLOCK_PASSPHRASE` are read once
|
||||
per command, in its `RunE`, into locked buffers on the CLI `Instance`, and
|
||||
unset at once, so that no program the command runs, `gpg` included,
|
||||
inherits them (https://git.eeqj.de/sneak/secret/issues/60). Nothing below
|
||||
the command reads the environment; the buffers are passed down:
|
||||
`vault.CreateVault` takes the mnemonic (nil for none), a `Vault` derives its
|
||||
long-term key from its `Mnemonic` and gives its `UnlockPassphrase` to a
|
||||
passphrase unlocker, and the PGP, keychain and Secure Enclave unlocker
|
||||
constructors take both. `CreatePGPUnlocker` sets both on the vault it
|
||||
loads, through `SetMnemonic` and `SetUnlockPassphrase`, now part of
|
||||
`VaultInterface`, before calling its `GetOrDeriveLongTermKey`. `init` and
|
||||
`vault create` no longer put the mnemonic into the environment. Unsetting
|
||||
erases nothing: the starting environment (`/proc/<pid>/environ`) and
|
||||
memory still hold the value. The README warns against both variables.
|
||||
- 2026-10-04: `.golangci.yml` is again the canonical file from
|
||||
`sneak/prompts`, byte for byte
|
||||
(https://git.eeqj.de/sneak/secret/issues/66). It runs `gomodguard_v2`
|
||||
@@ -293,8 +307,6 @@ Bring the repo into policy compliance in one commit:
|
||||
suggestions.
|
||||
- Validate GPG key existence before creating PGP unlock keys.
|
||||
- Split oversized CLI functions.
|
||||
- Document env var security (SB_UNLOCK_PASSPHRASE,
|
||||
SB_SECRET_MNEMONIC); clear after use.
|
||||
- mlock/munlock for sensitive allocations.
|
||||
- Cleanups: read statedir from environment or default instead of
|
||||
passing it around.
|
||||
|
||||
Reference in New Issue
Block a user