Make secret unlocker add pgp work on Linux (closes #88) #95

Merged
clawbot merged 1 commits from issue-88-pgp-unlocker-linux into next 2026-10-04 14:42:03 +02:00
Collaborator

CreatePGPUnlocker got the vault's long-term key from a helper written for the keychain unlocker. On every platform but macOS that helper is a stub that always fails, so secret unlocker add pgp could never work on Linux. It now calls the vault's GetOrDeriveLongTermKey, which adding a passphrase unlocker already uses: the key comes from the mnemonic when it is set, else from the current unlocker. That method is added to VaultInterface, so the three test stand-ins for a vault gain it too. The stub helper, now unused, is removed.

The new TestAddPGPUnlocker runs secret unlocker add pgp for a throwaway GPG key in a short GNUPGHOME, once with the mnemonic set and once taking the key from a passphrase unlocker. It then reads a secret with neither the mnemonic nor the passphrase set, so only the new unlocker can open the vault. The shared test key now has an encryption subkey; before, it could only sign.

Not shown by the diff:

  • Behaviour change on macOS: the mnemonic is now checked against the vault, so a wrong one is refused instead of producing an unlocker that holds the wrong key, and a Secure Enclave current unlocker now works as the source. Adding a keychain unlocker still uses the old helper.
  • Unverified: nothing here compiles darwin-only files. The darwin test stand-in in internal/secret/derivation_index_test.go gained the method and an import; checked only by make fmt-check parsing it, and by reading. The darwin PGP test creates its vault with the mnemonic set, so the new check passes there.

Model: opus-5-5

`CreatePGPUnlocker` got the vault's long-term key from a helper written for the keychain unlocker. On every platform but macOS that helper is a stub that always fails, so `secret unlocker add pgp` could never work on Linux. It now calls the vault's `GetOrDeriveLongTermKey`, which adding a passphrase unlocker already uses: the key comes from the mnemonic when it is set, else from the current unlocker. That method is added to `VaultInterface`, so the three test stand-ins for a vault gain it too. The stub helper, now unused, is removed. The new `TestAddPGPUnlocker` runs `secret unlocker add pgp` for a throwaway GPG key in a short `GNUPGHOME`, once with the mnemonic set and once taking the key from a passphrase unlocker. It then reads a secret with neither the mnemonic nor the passphrase set, so only the new unlocker can open the vault. The shared test key now has an encryption subkey; before, it could only sign. Not shown by the diff: - Behaviour change on macOS: the mnemonic is now checked against the vault, so a wrong one is refused instead of producing an unlocker that holds the wrong key, and a Secure Enclave current unlocker now works as the source. Adding a keychain unlocker still uses the old helper. - Unverified: nothing here compiles darwin-only files. The darwin test stand-in in `internal/secret/derivation_index_test.go` gained the method and an import; checked only by `make fmt-check` parsing it, and by reading. The darwin PGP test creates its vault with the mnemonic set, so the new check passes there. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 13:41:46 +02:00
clawbot self-assigned this 2026-10-04 13:41:46 +02:00
Author
Collaborator

PASS: secret unlocker add pgp now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, and the new test adds a PGP unlocker on Linux both ways and reads a secret through it.

  • Unverified item: the darwin-only change in internal/secret/derivation_index_test.go was read line by line, not compiled.
  • TODO.md conflicts with current next (both add an entry at the top of Completed Steps). I kept both entries locally for this review. The branch still needs a rebase before merge.

Model: opus-5-5

PASS: `secret unlocker add pgp` now gets the vault's long-term key the way adding a passphrase unlocker does, from the mnemonic or else from the current unlocker, and the new test adds a PGP unlocker on Linux both ways and reads a secret through it. - Unverified item: the darwin-only change in `internal/secret/derivation_index_test.go` was read line by line, not compiled. - `TODO.md` conflicts with current `next` (both add an entry at the top of Completed Steps). I kept both entries locally for this review. The branch still needs a rebase before merge. Model: opus-5-5
clawbot added 1 commit 2026-10-04 14:27:42 +02:00
CreatePGPUnlocker got the vault's long-term key from the keychain
unlocker's helper, which on every platform but macOS is a stub that
always fails. It now calls the vault's GetOrDeriveLongTermKey, as adding
a passphrase unlocker does: from the mnemonic, checked against the
vault, or else from the current unlocker. That method joins
VaultInterface. The test GPG key gains an encryption subkey, and a new
test adds a PGP unlocker with the long-term key from the mnemonic and
from a passphrase unlocker, then reads a secret through it.

Model: opus-5-5
clawbot force-pushed issue-88-pgp-unlocker-linux from f9ef4b64ca to a8282ccd8b 2026-10-04 14:27:42 +02:00 Compare
clawbot merged commit 62967f28d0 into next 2026-10-04 14:42:03 +02:00
clawbot deleted branch issue-88-pgp-unlocker-linux 2026-10-04 14:42:04 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#95