Commit Graph
14 Commits
Author SHA1 Message Date
clawbot ef0ae90768 Copy go-bip39 into internal/bip39 (closes #122)
check / check (push) Waiting to run
go-bip39's repository no longer exists. The part of v1.1.0 that secret
uses (NewEntropy, NewMnemonic, NewSeed, IsMnemonicValid and what they
call; English word list only) now lives in internal/bip39 with
upstream's LICENSE beside it, along with upstream's tests of that code
and their vectors unchanged. Every import moves there, and the module
leaves go.mod and go.sum. Beyond the trimming, only what the linter
asked for changed. No derived key or mnemonic changes.

Model: opus-5-5
2026-10-07 12:56:10 +02:00
clawbot ae030d759d Stop the terminal tests reading a pty nobody opened (closes #126)
check / check (push) Successful in 3m27s
On Linux, pty.Open of github.com/creack/pty v1.1.24 passes the address
of a local variable to ioctl as a plain number, through a function
call. When Go moved the goroutine's stack in between, the kernel wrote
the pty's number to the old place, and pty.Open opened /dev/pts/0,
another terminal. secret rm wrote there, and the test read a terminal
no program had open, which never ends. Require the commit on the
library's main branch that passes a pointer; no release has it yet.

Both terminal tests now stop reading when their one-minute context
ends, and fail saying what was still waiting.

Model: opus-5-5
2026-10-07 00:02:40 +02:00
clawbot af9ac6d979 Rename the Go module to sneak.berlin/go/secret (closes #43)
check / check (push) Failing after 2s
REPO_POLICIES.md requires the module root sneak.berlin/go/<name>.
go.mod, every import (rewritten with gofmt -r), the -X flags in
script/build and the examples in the pkg READMEs now use the new path.
go mod tidy lists go-humanize and fatih/color as direct requirements,
since internal/cli imports them.

This breaks anyone who fetched or imported git.eeqj.de/sneak/secret:
they must switch to sneak.berlin/go/secret, which resolves to this
repository.

Model: opus-5-5
2026-10-05 02:45:37 +02:00
clawbot 1cc8653981 Ask before removing a secret, version, vault or unlocker (closes #39)
check / check (push) Failing after 2s
secret rm, secret version rm, secret vault remove and secret unlocker
remove ask [y/N] on a terminal, naming what they remove, and go ahead
only on y or yes. Without --force, a command whose stdin is not a
terminal fails at once. --force, now also on rm and version rm,
removes without asking; it replaces the old refusals to remove a vault
with secrets or the last unlocker without --force. The checks run and
the question is asked before the state directory lock is taken; under
the lock the checks run again, and nothing is removed if they would
ask a different question.

Model: opus-5-5
2026-10-04 17:41:48 +02:00
clawbot d52b4f1240 Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Successful in 1m1s
The size tests skip a case whose secret needs more locked memory than
the process can lock, found by locking a buffer of that size: memguard
panics otherwise, and a plain `docker build .` runs under an 8 MiB
RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the
limit, runs every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
2026-10-02 14:16:02 +02:00
sneak 70d19d09d0 latest 2025-07-22 13:35:19 +02:00
sneak 816f53f819 Replace shell-based keychain implementation with keybase/go-keychain library
- Replaced exec.Command calls to /usr/bin/security with native keybase/go-keychain API
- Added comprehensive test suite for keychain operations
- Fixed binary data storage in tests using hex encoding
- Updated macse tests to skip with explanation about ADE requirements
- All tests passing with CGO_ENABLED=1
2025-07-21 15:58:41 +02:00
sneak c9774e89e0 WIP: refactor to use memguard for secure memory handling
- Add memguard dependency
- Update ReadPassphrase to return LockedBuffer
- Update EncryptWithPassphrase/DecryptWithPassphrase to accept LockedBuffer
- Remove string wrapper functions
- Update all callers to create LockedBuffers at entry points
- Update interfaces and mock implementations
2025-07-15 07:23:58 +02:00
sneak 0b31fba663 latest from ai, it broke the tests 2025-06-20 05:40:20 -07:00
sneak fbda2d91af add secret versioning support 2025-06-08 22:07:19 -07:00
sneak 2443256338 latest, trying to get sep to work without ADP membership 2025-05-29 04:03:40 -07:00
sneak 354681b298 latest 2025-05-28 14:06:29 -07:00
sneak efedbe405f latest 2025-05-28 07:38:07 -07:00
sneak 7671eaaa57 initial 2025-05-28 04:02:55 -07:00