CreatePGPUnlocker got the vault's long-term key from a helper written for the keychain unlocker. On every platform but macOS that helper is a stub that always fails, so secret unlocker add pgp could never work on Linux. It now calls the vault's GetOrDeriveLongTermKey, which adding a passphrase unlocker already uses: the key comes from the mnemonic when it is set, else from the current unlocker. That method is added to VaultInterface, so the three test stand-ins for a vault gain it too. The stub helper, now unused, is removed.
The new TestAddPGPUnlocker runs secret unlocker add pgp for a throwaway GPG key in a short GNUPGHOME, once with the mnemonic set and once taking the key from a passphrase unlocker. It then reads a secret with neither the mnemonic nor the passphrase set, so only the new unlocker can open the vault. The shared test key now has an encryption subkey; before, it could only sign.
Not shown by the diff:
Behaviour change on macOS: the mnemonic is now checked against the vault, so a wrong one is refused instead of producing an unlocker that holds the wrong key, and a Secure Enclave current unlocker now works as the source. Adding a keychain unlocker still uses the old helper.
Unverified: nothing here compiles darwin-only files. The darwin test stand-in in internal/secret/derivation_index_test.go gained the method and an import; checked only by make fmt-check parsing it, and by reading. The darwin PGP test creates its vault with the mnemonic set, so the new check passes there.
Model: opus-5-5
`CreatePGPUnlocker` got the vault's long-term key from a helper written for the keychain unlocker. On every platform but macOS that helper is a stub that always fails, so `secret unlocker add pgp` could never work on Linux. It now calls the vault's `GetOrDeriveLongTermKey`, which adding a passphrase unlocker already uses: the key comes from the mnemonic when it is set, else from the current unlocker. That method is added to `VaultInterface`, so the three test stand-ins for a vault gain it too. The stub helper, now unused, is removed.
The new `TestAddPGPUnlocker` runs `secret unlocker add pgp` for a throwaway GPG key in a short `GNUPGHOME`, once with the mnemonic set and once taking the key from a passphrase unlocker. It then reads a secret with neither the mnemonic nor the passphrase set, so only the new unlocker can open the vault. The shared test key now has an encryption subkey; before, it could only sign.
Not shown by the diff:
- Behaviour change on macOS: the mnemonic is now checked against the vault, so a wrong one is refused instead of producing an unlocker that holds the wrong key, and a Secure Enclave current unlocker now works as the source. Adding a keychain unlocker still uses the old helper.
- Unverified: nothing here compiles darwin-only files. The darwin test stand-in in `internal/secret/derivation_index_test.go` gained the method and an import; checked only by `make fmt-check` parsing it, and by reading. The darwin PGP test creates its vault with the mnemonic set, so the new check passes there.
Model: opus-5-5
PASS: secret unlocker add pgp now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, and the new test adds a PGP unlocker on Linux both ways and reads a secret through it.
Unverified item: the darwin-only change in internal/secret/derivation_index_test.go was read line by line, not compiled.
TODO.md conflicts with current next (both add an entry at the top of Completed Steps). I kept both entries locally for this review. The branch still needs a rebase before merge.
Model: opus-5-5
PASS: `secret unlocker add pgp` now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, and the new test adds a PGP unlocker on Linux both ways and reads a secret through it.
- Unverified item: the darwin-only change in `internal/secret/derivation_index_test.go` was read line by line, not compiled.
- `TODO.md` conflicts with current `next` (both add an entry at the top of Completed Steps). I kept both entries locally for this review. The branch still needs a rebase before merge.
Model: opus-5-5
CreatePGPUnlocker got the vault's long-term key from the keychain
unlocker's helper, which on every platform but macOS is a stub that
always fails. It now calls the vault's GetOrDeriveLongTermKey, as adding
a passphrase unlocker does: from the mnemonic, checked against the
vault, or else from the current unlocker. That method joins
VaultInterface. The test GPG key gains an encryption subkey, and a new
test adds a PGP unlocker with the long-term key from the mnemonic and
from a passphrase unlocker, then reads a secret through it.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
CreatePGPUnlockergot the vault's long-term key from a helper written for the keychain unlocker. On every platform but macOS that helper is a stub that always fails, sosecret unlocker add pgpcould never work on Linux. It now calls the vault'sGetOrDeriveLongTermKey, which adding a passphrase unlocker already uses: the key comes from the mnemonic when it is set, else from the current unlocker. That method is added toVaultInterface, so the three test stand-ins for a vault gain it too. The stub helper, now unused, is removed.The new
TestAddPGPUnlockerrunssecret unlocker add pgpfor a throwaway GPG key in a shortGNUPGHOME, once with the mnemonic set and once taking the key from a passphrase unlocker. It then reads a secret with neither the mnemonic nor the passphrase set, so only the new unlocker can open the vault. The shared test key now has an encryption subkey; before, it could only sign.Not shown by the diff:
internal/secret/derivation_index_test.gogained the method and an import; checked only bymake fmt-checkparsing it, and by reading. The darwin PGP test creates its vault with the mnemonic set, so the new check passes there.Model: opus-5-5
PASS:
secret unlocker add pgpnow gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, and the new test adds a PGP unlocker on Linux both ways and reads a secret through it.internal/secret/derivation_index_test.gowas read line by line, not compiled.TODO.mdconflicts with currentnext(both add an entry at the top of Completed Steps). I kept both entries locally for this review. The branch still needs a rebase before merge.Model: opus-5-5
secret unlocker add pgpwork on Linux (closes #88)f9ef4b64catoa8282ccd8b