check / check (push) Failing after 1s
script/lint-darwin (make lint-darwin; run by script/check, and its commands by the Dockerfile lint stage) runs go vet and golangci-lint with GOOS=darwin and cgo off. Compiling cgo for macOS needs Apple's SDK, and keychainunlocker.go uses go-keychain, which is cgo there, so it and its tests are now built only with cgo on macOS, like internal/macse; their stubs serve a macOS build without cgo. checkMacOSAvailable moves to seunlocker_darwin.go. The findings in the newly checked files are fixed, and lines over 88 columns in the unchecked ones are wrapped. Model: opus-5-5
89 lines
2.2 KiB
Go
89 lines
2.2 KiB
Go
//go:build !darwin || !cgo
|
|
|
|
package secret
|
|
|
|
import (
|
|
"errors"
|
|
|
|
"filippo.io/age"
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/afero"
|
|
)
|
|
|
|
// KeychainUnlockerMetadata is a stub for non-Darwin platforms
|
|
type KeychainUnlockerMetadata struct {
|
|
UnlockerMetadata
|
|
|
|
KeychainItemName string `json:"keychainItemName"`
|
|
}
|
|
|
|
// KeychainUnlocker is a stub for non-Darwin platforms
|
|
type KeychainUnlocker struct {
|
|
Directory string
|
|
Metadata UnlockerMetadata
|
|
fs afero.Fs
|
|
}
|
|
|
|
var errKeychainNotSupported = errors.New(
|
|
"keychain unlockers are only supported on macOS")
|
|
|
|
// NewKeychainUnlocker creates a stub KeychainUnlocker on non-Darwin
|
|
// platforms. The returned instance's methods that require macOS
|
|
// functionality will return errors.
|
|
func NewKeychainUnlocker(
|
|
fs afero.Fs, directory string, metadata UnlockerMetadata,
|
|
) *KeychainUnlocker {
|
|
return &KeychainUnlocker{
|
|
Directory: directory,
|
|
Metadata: metadata,
|
|
fs: fs,
|
|
}
|
|
}
|
|
|
|
// GetIdentity returns an error on non-Darwin platforms
|
|
func (k *KeychainUnlocker) GetIdentity() (*age.X25519Identity, error) {
|
|
return nil, errKeychainNotSupported
|
|
}
|
|
|
|
// GetType returns the unlocker type
|
|
func (k *KeychainUnlocker) GetType() string {
|
|
return "keychain"
|
|
}
|
|
|
|
// GetMetadata returns the unlocker metadata
|
|
func (k *KeychainUnlocker) GetMetadata() UnlockerMetadata {
|
|
return k.Metadata
|
|
}
|
|
|
|
// GetDirectory returns the unlocker directory
|
|
func (k *KeychainUnlocker) GetDirectory() string {
|
|
return k.Directory
|
|
}
|
|
|
|
// GetID returns the unlocker ID
|
|
func (k *KeychainUnlocker) GetID() string {
|
|
return k.Metadata.CreatedAt.Format("2006-01-02.15.04") + "-keychain"
|
|
}
|
|
|
|
// GetKeychainItemName returns an error on non-Darwin platforms
|
|
func (k *KeychainUnlocker) GetKeychainItemName() (string, error) {
|
|
return "", errKeychainNotSupported
|
|
}
|
|
|
|
// Remove returns an error on non-Darwin platforms
|
|
func (k *KeychainUnlocker) Remove() error {
|
|
return errKeychainNotSupported
|
|
}
|
|
|
|
// CreateKeychainUnlocker returns an error on non-Darwin platforms
|
|
func CreateKeychainUnlocker(_ afero.Fs, _ string) (*KeychainUnlocker, error) {
|
|
return nil, errKeychainNotSupported
|
|
}
|
|
|
|
// getLongTermPrivateKey returns an error on non-Darwin platforms
|
|
func getLongTermPrivateKey(
|
|
_ afero.Fs, _ VaultInterface,
|
|
) (*memguard.LockedBuffer, error) {
|
|
return nil, errKeychainNotSupported
|
|
}
|