secret unlocker add pgp always fails on Linux: it gets the long-term key from the keychain stub #88

Closed
opened 2026-10-04 10:32:12 +02:00 by clawbot · 1 comment
Collaborator

On every platform but macOS, CreatePGPUnlocker (internal/secret/pgpunlocker.go) gets the vault's long-term key from getLongTermPrivateKey, which there is the keychain stub in internal/secret/keychainunlocker_stub.go. It always returns "keychain unlockers are only supported on macOS", so secret unlocker add pgp cannot add a PGP unlocker on Linux, with or without the mnemonic. The only test that adds one, internal/secret/pgpunlock_test.go, is darwin-only.

Found while working on #48.

Definition of done

  • secret unlocker add pgp adds a PGP unlocker on Linux, both with the mnemonic set and with a current unlocker to get the long-term key from.
  • A test that runs on Linux adds a PGP unlocker.
  • TODO.md updated in the same commit.

Model: opus-5-5

On every platform but macOS, `CreatePGPUnlocker` (`internal/secret/pgpunlocker.go`) gets the vault's long-term key from `getLongTermPrivateKey`, which there is the keychain stub in `internal/secret/keychainunlocker_stub.go`. It always returns "keychain unlockers are only supported on macOS", so `secret unlocker add pgp` cannot add a PGP unlocker on Linux, with or without the mnemonic. The only test that adds one, `internal/secret/pgpunlock_test.go`, is darwin-only. Found while working on https://git.eeqj.de/sneak/secret/issues/48. ## Definition of done - `secret unlocker add pgp` adds a PGP unlocker on Linux, both with the mnemonic set and with a current unlocker to get the long-term key from. - A test that runs on Linux adds a PGP unlocker. - `TODO.md` updated in the same commit. Model: opus-5-5
clawbot reopened this issue 2026-10-04 13:26:48 +02:00
Author
Collaborator

#95: secret unlocker add pgp now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, instead of through the keychain stub. A new test, which runs on Linux, adds a PGP unlocker for a throwaway GPG key both ways and reads a secret through it.

Reopened: this issue was closed when #90 merged, because the words "Filed, not fixed" just before this issue's link in that PR's body were taken as a closing keyword.

Model: opus-5-5

https://git.eeqj.de/sneak/secret/pulls/95: `secret unlocker add pgp` now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, instead of through the keychain stub. A new test, which runs on Linux, adds a PGP unlocker for a throwaway GPG key both ways and reads a secret through it. Reopened: this issue was closed when https://git.eeqj.de/sneak/secret/pulls/90 merged, because the words "Filed, not fixed" just before this issue's link in that PR's body were taken as a closing keyword. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#88