check / check (push) Failing after 1s
A vault name may use only lowercase ASCII letters, digits, `.`, `-` and `_`, and must not be empty, `.` or `..`; the error now states that rule. `vault create`, `vault import`, `vault select`, `vault remove`, both vault names of `mv` and shell completion of a `vault:secret` argument check the name as typed before building any path from it. Before, `vault import ..` wrote a long-term key and an unlocker into the state directory itself, and `vault select ..` made that the current vault. Model: opus-5-5
78 lines
3.2 KiB
Go
78 lines
3.2 KiB
Go
package vault
|
|
|
|
import "errors"
|
|
|
|
// Sentinel errors returned by vault operations.
|
|
//
|
|
// Several of these carry deliberately partial text: the message a caller
|
|
// composes with fmt.Errorf places the interpolated value where it has
|
|
// always appeared, and the sentinel supplies only the surrounding fixed
|
|
// words. This keeps every composed message byte-identical to the dynamic
|
|
// errors these sentinels replaced. Each such sentinel notes the message it
|
|
// participates in.
|
|
var (
|
|
// ErrMnemonicMismatch indicates the mnemonic-derived public key does
|
|
// not match the vault's stored public key hash.
|
|
ErrMnemonicMismatch = errors.New(
|
|
"derived public key does not match vault: mnemonic may be incorrect",
|
|
)
|
|
|
|
// ErrInvalidVaultName indicates a vault name that breaks the naming
|
|
// rule: only lowercase ASCII letters, digits, '.', '-' and '_'; not
|
|
// empty, "." or "..". Composed by ValidateVaultName as
|
|
// "invalid vault name '<name>': <the rule>".
|
|
ErrInvalidVaultName = errors.New("invalid vault name")
|
|
|
|
// ErrVaultNotFound indicates the named vault does not exist. Composed
|
|
// as "vault <name> does not exist".
|
|
ErrVaultNotFound = errors.New("does not exist")
|
|
|
|
// ErrVaultExists indicates that a vault to be created already exists.
|
|
// Composed as "vault <name> already exists".
|
|
ErrVaultExists = errors.New("already exists")
|
|
|
|
// ErrNilValueBuffer indicates a nil value buffer was supplied.
|
|
ErrNilValueBuffer = errors.New("value buffer is nil")
|
|
|
|
// ErrInvalidSecretName indicates a secret name that breaks the naming
|
|
// rule: only ASCII letters, digits, '.', '-', '_' and '/'; not empty;
|
|
// no leading '.' or '/', no trailing '/', no '//', no '..' path segment.
|
|
// Composed by ValidateSecretName as
|
|
// "invalid secret name '<name>': <the rule>".
|
|
ErrInvalidSecretName = errors.New("invalid secret name")
|
|
|
|
// ErrSecretExists indicates the secret already exists and --force
|
|
// was not supplied. Composed as
|
|
// "secret <name> already exists (use --force to overwrite)", or as
|
|
// "secret '<name>' already exists in vault '<vault>' (use --force to
|
|
// overwrite)" when copying between vaults.
|
|
ErrSecretExists = errors.New("already exists")
|
|
|
|
// ErrSecretNotFound indicates the named secret does not exist.
|
|
// Composed as "secret <name> not found".
|
|
ErrSecretNotFound = errors.New("not found")
|
|
|
|
// ErrVersionNotFound indicates the requested secret version does not
|
|
// exist. Composed as
|
|
// "version '<version>' not found for secret '<name>'".
|
|
ErrVersionNotFound = errors.New("not found for secret")
|
|
|
|
// ErrNoVersions indicates the source secret has no versions. Composed
|
|
// as "source secret '<name>' has no versions".
|
|
ErrNoVersions = errors.New("has no versions")
|
|
|
|
// ErrUnsupportedUnlockerType indicates an unlocker metadata type
|
|
// that this build does not support.
|
|
ErrUnsupportedUnlockerType = errors.New("unsupported unlocker type")
|
|
|
|
// ErrUnlockerNotFound indicates no unlocker with the given ID exists.
|
|
// Composed as "unlocker with ID <id> not found".
|
|
ErrUnlockerNotFound = errors.New("not found")
|
|
|
|
// ErrNoLockForFilesystem indicates LockStateDir was given a filesystem
|
|
// it cannot lock. Composed as "cannot lock the state directory on
|
|
// filesystem <type>".
|
|
ErrNoLockForFilesystem = errors.New(
|
|
"cannot lock the state directory on filesystem")
|
|
)
|