On every platform but macOS, CreatePGPUnlocker (internal/secret/pgpunlocker.go) gets the vault's long-term key from getLongTermPrivateKey, which there is the keychain stub in internal/secret/keychainunlocker_stub.go. It always returns "keychain unlockers are only supported on macOS", so secret unlocker add pgp cannot add a PGP unlocker on Linux, with or without the mnemonic. The only test that adds one, internal/secret/pgpunlock_test.go, is darwin-only.
secret unlocker add pgp adds a PGP unlocker on Linux, both with the mnemonic set and with a current unlocker to get the long-term key from.
A test that runs on Linux adds a PGP unlocker.
TODO.md updated in the same commit.
Model: opus-5-5
On every platform but macOS, `CreatePGPUnlocker` (`internal/secret/pgpunlocker.go`) gets the vault's long-term key from `getLongTermPrivateKey`, which there is the keychain stub in `internal/secret/keychainunlocker_stub.go`. It always returns "keychain unlockers are only supported on macOS", so `secret unlocker add pgp` cannot add a PGP unlocker on Linux, with or without the mnemonic. The only test that adds one, `internal/secret/pgpunlock_test.go`, is darwin-only.
Found while working on https://git.eeqj.de/sneak/secret/issues/48.
## Definition of done
- `secret unlocker add pgp` adds a PGP unlocker on Linux, both with the mnemonic set and with a current unlocker to get the long-term key from.
- A test that runs on Linux adds a PGP unlocker.
- `TODO.md` updated in the same commit.
Model: opus-5-5
#95: secret unlocker add pgp now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, instead of through the keychain stub. A new test, which runs on Linux, adds a PGP unlocker for a throwaway GPG key both ways and reads a secret through it.
Reopened: this issue was closed when #90 merged, because the words "Filed, not fixed" just before this issue's link in that PR's body were taken as a closing keyword.
Model: opus-5-5
https://git.eeqj.de/sneak/secret/pulls/95: `secret unlocker add pgp` now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, instead of through the keychain stub. A new test, which runs on Linux, adds a PGP unlocker for a throwaway GPG key both ways and reads a secret through it.
Reopened: this issue was closed when https://git.eeqj.de/sneak/secret/pulls/90 merged, because the words "Filed, not fixed" just before this issue's link in that PR's body were taken as a closing keyword.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
On every platform but macOS,
CreatePGPUnlocker(internal/secret/pgpunlocker.go) gets the vault's long-term key fromgetLongTermPrivateKey, which there is the keychain stub ininternal/secret/keychainunlocker_stub.go. It always returns "keychain unlockers are only supported on macOS", sosecret unlocker add pgpcannot add a PGP unlocker on Linux, with or without the mnemonic. The only test that adds one,internal/secret/pgpunlock_test.go, is darwin-only.Found while working on #48.
Definition of done
secret unlocker add pgpadds a PGP unlocker on Linux, both with the mnemonic set and with a current unlocker to get the long-term key from.TODO.mdupdated in the same commit.Model: opus-5-5
clawbot referenced this issue2026-10-04 11:23:15 +02:00
#95:
secret unlocker add pgpnow gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, instead of through the keychain stub. A new test, which runs on Linux, adds a PGP unlocker for a throwaway GPG key both ways and reads a secret through it.Reopened: this issue was closed when #90 merged, because the words "Filed, not fixed" just before this issue's link in that PR's body were taken as a closing keyword.
Model: opus-5-5