secret init and secret vault create read the mnemonic with secret.ReadPassphrase, so without a terminal they said "failed to read mnemonic: failed to read passphrase: cannot read passphrase from non-terminal stdin ... Please set the SB_UNLOCK_PASSPHRASE environment variable", naming the passphrase and the wrong variable.
They now use the new secret.ReadMnemonic, whose every error wraps the new secret.ErrMnemonicNotRead ("failed to read mnemonic"). ReadPassphrase and ReadMnemonic share one terminal read, which names the environment variable that gives the value instead. Without a terminal, init now says:
failed to read mnemonic: stdin is not a terminal (piped input or script). Please set the SB_SECRET_MNEMONIC environment variable or run interactively
A test pins that output on the built binary, and checks the error with errors.Is.
Judgement call: the passphrase messages change too, because the shared read can no longer say "passphrase" in its own words: "failed to read passphrase: stdin is not a terminal (piped input or script). Please set the SB_UNLOCK_PASSPHRASE environment variable or run interactively" (it no longer repeats "cannot read passphrase"), and empty input gives "nothing was entered" instead of "passphrase cannot be empty". The test that pins the passphrase message is updated.
Model: opus-5-5
Fixes https://git.eeqj.de/sneak/secret/issues/115.
`secret init` and `secret vault create` read the mnemonic with `secret.ReadPassphrase`, so without a terminal they said "failed to read mnemonic: failed to read passphrase: cannot read passphrase from non-terminal stdin ... Please set the SB_UNLOCK_PASSPHRASE environment variable", naming the passphrase and the wrong variable.
They now use the new `secret.ReadMnemonic`, whose every error wraps the new `secret.ErrMnemonicNotRead` ("failed to read mnemonic"). `ReadPassphrase` and `ReadMnemonic` share one terminal read, which names the environment variable that gives the value instead. Without a terminal, `init` now says:
`failed to read mnemonic: stdin is not a terminal (piped input or script). Please set the SB_SECRET_MNEMONIC environment variable or run interactively`
A test pins that output on the built binary, and checks the error with `errors.Is`.
- Judgement call: the passphrase messages change too, because the shared read can no longer say "passphrase" in its own words: "failed to read passphrase: stdin is not a terminal (piped input or script). Please set the SB_UNLOCK_PASSPHRASE environment variable or run interactively" (it no longer repeats "cannot read passphrase"), and empty input gives "nothing was entered" instead of "passphrase cannot be empty". The test that pins the passphrase message is updated.
Model: opus-5-5
secret init and secret vault create read the mnemonic with the new
secret.ReadMnemonic, whose every error wraps the new
secret.ErrMnemonicNotRead. It shares the terminal read with ReadPassphrase,
whose errors still wrap ErrPassphraseNotRead. Without a terminal the error
names the environment variable that gives the value instead:
SB_SECRET_MNEMONIC for the mnemonic, SB_UNLOCK_PASSPHRASE for the
passphrase. A test pins the message of init without a terminal.
Model: opus-5-5
PASS: secret init and secret vault create now report a mnemonic they cannot read as a mnemonic only, identified by secret.ErrMnemonicNotRead alone, passphrase reads still report the passphrase, and the new test pins the init message.
Model: opus-5-5
PASS: `secret init` and `secret vault create` now report a mnemonic they cannot read as a mnemonic only, identified by `secret.ErrMnemonicNotRead` alone, passphrase reads still report the passphrase, and the new test pins the `init` message.
Model: opus-5-5
clawbot
merged commit 2503f2db96 into next2026-10-05 01:43:00 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes #115.
secret initandsecret vault createread the mnemonic withsecret.ReadPassphrase, so without a terminal they said "failed to read mnemonic: failed to read passphrase: cannot read passphrase from non-terminal stdin ... Please set the SB_UNLOCK_PASSPHRASE environment variable", naming the passphrase and the wrong variable.They now use the new
secret.ReadMnemonic, whose every error wraps the newsecret.ErrMnemonicNotRead("failed to read mnemonic").ReadPassphraseandReadMnemonicshare one terminal read, which names the environment variable that gives the value instead. Without a terminal,initnow says:failed to read mnemonic: stdin is not a terminal (piped input or script). Please set the SB_SECRET_MNEMONIC environment variable or run interactivelyA test pins that output on the built binary, and checks the error with
errors.Is.Model: opus-5-5
PASS:
secret initandsecret vault createnow report a mnemonic they cannot read as a mnemonic only, identified bysecret.ErrMnemonicNotReadalone, passphrase reads still report the passphrase, and the new test pins theinitmessage.Model: opus-5-5