check / check (push) Failing after 2s
REPO_POLICIES.md requires the module root sneak.berlin/go/<name>. go.mod, every import (rewritten with gofmt -r), the -X flags in script/build and the examples in the pkg READMEs now use the new path. go mod tidy lists go-humanize and fatih/color as direct requirements, since internal/cli imports them. This breaks anyone who fetched or imported git.eeqj.de/sneak/secret: they must switch to sneak.berlin/go/secret, which resolves to this repository. Model: opus-5-5
97 lines
2.7 KiB
Go
97 lines
2.7 KiB
Go
package cli
|
|
|
|
import (
|
|
"os"
|
|
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/cobra"
|
|
"golang.org/x/sys/unix"
|
|
"golang.org/x/term"
|
|
"sneak.berlin/go/secret/internal/secret"
|
|
)
|
|
|
|
// Entry runs the secret CLI and returns the process exit code. It wipes
|
|
// every memguard buffer before it returns, so the caller must do nothing
|
|
// but exit with the code.
|
|
func Entry() int {
|
|
// On SIGINT or SIGTERM memguard runs this function, wipes every buffer
|
|
// and exits with status 1. The passphrase prompt turns terminal echo
|
|
// off until the read finishes, so a signal there would leave echo off.
|
|
// Only a process in the terminal's foreground process group may reset
|
|
// it: one in the background that tries is stopped instead of exiting.
|
|
terminalState, terminalErr := term.GetState(unix.Stdin)
|
|
|
|
memguard.CatchSignal(func(os.Signal) {
|
|
foreground, err := unix.IoctlGetInt(unix.Stdin, unix.TIOCGPGRP)
|
|
if terminalErr == nil && err == nil && foreground == unix.Getpgrp() {
|
|
_ = term.Restore(unix.Stdin, terminalState)
|
|
}
|
|
}, os.Interrupt, unix.SIGTERM)
|
|
|
|
defer memguard.Purge()
|
|
|
|
err := newRootCmd().Execute()
|
|
if err != nil {
|
|
return 1
|
|
}
|
|
|
|
return 0
|
|
}
|
|
|
|
func newRootCmd() *cobra.Command {
|
|
secret.Debug("newRootCmd starting")
|
|
|
|
cmd := &cobra.Command{
|
|
Use: "secret",
|
|
Short: "A simple secrets manager",
|
|
Long: `A simple secrets manager to store and retrieve sensitive ` +
|
|
`information securely.`,
|
|
// Cobra prints the error a command returns; Entry does not.
|
|
SilenceErrors: false,
|
|
// Usage belongs only to a command called wrongly. Cobra has
|
|
// checked its arguments and flag values before this runs, but
|
|
// checks required flags (ValidateRequiredFlags) and flag groups
|
|
// (ValidateFlagGroups) only after it, so both are checked here
|
|
// to keep usage for them. An error after that comes from running
|
|
// the command, and usage would only bury it. A subcommand that
|
|
// sets its own PersistentPreRun replaces this one.
|
|
PersistentPreRunE: func(cmd *cobra.Command, _ []string) error {
|
|
err := cmd.ValidateRequiredFlags()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
err = cmd.ValidateFlagGroups()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
cmd.SilenceUsage = true
|
|
|
|
return nil
|
|
},
|
|
}
|
|
|
|
secret.Debug("Adding subcommands to root command")
|
|
// Add subcommands
|
|
cmd.AddCommand(NewInitCmd())
|
|
cmd.AddCommand(newGenerateCmd())
|
|
cmd.AddCommand(newVaultCmd())
|
|
cmd.AddCommand(newAddCmd())
|
|
cmd.AddCommand(newGetCmd())
|
|
cmd.AddCommand(newListCmd())
|
|
cmd.AddCommand(newRemoveCmd())
|
|
cmd.AddCommand(newMoveCmd())
|
|
cmd.AddCommand(newUnlockerCmd())
|
|
cmd.AddCommand(newImportCmd())
|
|
cmd.AddCommand(newEncryptCmd())
|
|
cmd.AddCommand(newDecryptCmd())
|
|
cmd.AddCommand(newVersionCmd())
|
|
cmd.AddCommand(newInfoCmd())
|
|
cmd.AddCommand(newCompletionCmd())
|
|
|
|
secret.Debug("newRootCmd completed")
|
|
|
|
return cmd
|
|
}
|