[keyman] phase 2: guard the directories nothing creates

encrypt read ~/.ssh and the tmp directory, and decrypt read <vault>/keys,
with no existsSync between them. main.ts created vaultRoot and tmpDir but
never keysDir, so decrypt on a fresh vault threw ENOENT instead of
printing the "no encrypted keys" message it already had — the message was
unreachable until something else created the directory.

Both functions now fall through to their warning. main.ts creates all
three directories, 0700: the vault holds the age identity and tmp holds
plaintext private keys.

age spawns go through runTool, which separates "not installed" (ENOENT,
whose message is `spawn age ENOENT`) from "age refused" (whose reason is
on stderr and nowhere in the thrown message). Tested against real
processes, not a mocked execa — the shape of the failure is the point.

list.ts kept statSync rather than switching to withFileTypes as planned:
withFileTypes reports a symlinked key directory as a link and would have
silently dropped it. `throwIfNoEntry: false` fixes the dangling-symlink
throw and keeps following the good ones. Both cases now have a test.

Also deletes the three debug logs (encrypt.ts printed both key arrays,
decrypt.ts printed every candidate path from inside a filter).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Benjamin Diedrichsen
2026-07-30 14:33:26 +02:00
parent 8fa0cfa271
commit 11c323b715
10 changed files with 183 additions and 22 deletions
+7 -6
View File
@@ -2,14 +2,15 @@ import fs from 'node:fs';
import path from 'node:path';
import { execa } from 'execa';
import inquirer from 'inquirer';
import { runTool } from './keyman.utils.js';
export async function decryptKeys(sshDir: string, vaultDir: string, ageKey: string) {
const keyDir = path.join(vaultDir, 'keys');
const vaultKeys = fs.readdirSync(keyDir).filter((key) => {
const keyfile = path.join(keyDir, key, `id_${key}.age`);
console.log(keyfile);
return fs.existsSync(keyfile);
});
// Guarded: nothing creates the keys directory until the first encrypt, so on a
// fresh vault this readdir threw instead of reporting an empty vault.
const vaultKeys = fs.existsSync(keyDir)
? fs.readdirSync(keyDir).filter((key) => fs.existsSync(path.join(keyDir, key, `id_${key}.age`)))
: [];
if (vaultKeys.length === 0) {
console.log('⚠️ No encrypted keys found.');
@@ -44,7 +45,7 @@ export async function decryptKeys(sshDir: string, vaultDir: string, ageKey: stri
: path.join(sshDir, `id_${key}.pub`);
// Decrypt key
await execa('age', ['-d', '-i', ageKey, '-o', privateKeyOut, encryptedKey]);
await runTool('age', ['-d', '-i', ageKey, '-o', privateKeyOut, encryptedKey]);
await execa('cp', [publicKey, publicKeyOut]);
await execa('chmod', ['600', privateKeyOut]);
+18 -11
View File
@@ -1,7 +1,20 @@
import fs from 'node:fs';
import path from 'node:path';
import { execa } from 'execa';
import inquirer from 'inquirer';
import { runTool } from './keyman.utils.js';
/**
* Private keys in a directory that may not exist.
*
* A first run has neither `~/.ssh` nor the tmp directory, and an unguarded
* readdir there threw before the "nothing to encrypt" message could be reached.
*/
function privateKeysIn(dir: string): string[] {
if (!fs.existsSync(dir)) {
return [];
}
return fs.readdirSync(dir).filter((key) => key.startsWith('id_') && !key.endsWith('.pub'));
}
export async function encryptKeys(
sshDir: string,
@@ -9,14 +22,8 @@ export async function encryptKeys(
tmpDir: string,
pubkey: string
) {
const sshKeys = fs
.readdirSync(sshDir)
.filter((key) => key.startsWith('id_') && !key.endsWith('.pub'));
const tmpKeys = fs
.readdirSync(tmpDir)
.filter((key) => key.startsWith('id_') && !key.endsWith('.pub'));
console.log(tmpKeys);
console.log(sshKeys);
const sshKeys = privateKeysIn(sshDir);
const tmpKeys = privateKeysIn(tmpDir);
const keys = [...new Set([...sshKeys, ...tmpKeys])];
if (keys.length === 0) {
@@ -36,10 +43,10 @@ export async function encryptKeys(
for (const key of selectedKeys) {
const keyPath = path.join(tmpKeys.includes(key) ? tmpDir : sshDir, key);
const vaultPath = path.join(vaultDir, 'keys', key.replace('id_', ''));
fs.mkdirSync(vaultPath, { recursive: true });
fs.mkdirSync(vaultPath, { recursive: true, mode: 0o700 });
// Encrypt key using `age`
await execa('age', ['-r', pubkey, '-o', path.join(vaultPath, `${key}.age`), keyPath]);
await runTool('age', ['-r', pubkey, '-o', path.join(vaultPath, `${key}.age`), keyPath]);
// Copy public key and create README
fs.copyFileSync(`${keyPath}.pub`, path.join(vaultPath, `${key}.pub`));
+5 -2
View File
@@ -76,9 +76,12 @@ export async function listKeys(sshDir: string, vaultDir: string, tmpDir: string)
// Scan vault directory
if (fs.existsSync(vaultDir)) {
// throwIfNoEntry keeps a dangling symlink from aborting the whole listing;
// the stat still follows a symlink to a real directory, which withFileTypes
// would have reported as a link and skipped.
const vaultDirs = fs.readdirSync(vaultDir).filter((dir) => {
const stat = fs.statSync(path.join(vaultDir, dir));
return stat.isDirectory();
const stat = fs.statSync(path.join(vaultDir, dir), { throwIfNoEntry: false });
return stat?.isDirectory() ?? false;
});
for (const dir of vaultDirs) {
+6 -2
View File
@@ -37,8 +37,12 @@ export async function keyman() {
}
const sshDir = path.join(homeDir, '.ssh');
fs.mkdirSync(paths.vaultRoot, { recursive: true });
fs.mkdirSync(paths.tmpDir, { recursive: true });
// 0700 because the vault holds the age identity and, in tmp, plaintext private
// keys. keysDir is created here too: decrypt used to read it before anything
// created it.
for (const dir of [paths.vaultRoot, paths.keysDir, paths.tmpDir]) {
fs.mkdirSync(dir, { recursive: true, mode: 0o700 });
}
// Main loop - keep showing menu until user quits
let running = true;
+33
View File
@@ -1,4 +1,37 @@
import fs from 'node:fs';
import { execa, type Options } from 'execa';
/**
* Runs one of the external binaries keyman depends on.
*
* Two failures are worth telling apart, and an execa error tells a reader
* neither: the binary not being installed (`ENOENT`, whose message is
* `spawn <name> ENOENT`) and the binary refusing (whose reason is on stderr and
* nowhere in the thrown message). `age` is a hard requirement, so its absence
* has to read as an instruction.
*
* Returns only `stdout` — annotated rather than inferred because execa's result
* type cannot be named from here (TS2883), and it is all any caller wants. Empty
* when the output went somewhere else, as with `stdio: 'inherit'`.
*/
export async function runTool(
binary: string,
args: string[],
options?: Options
): Promise<{ stdout: string }> {
try {
// Called without the third argument when there are no options, so a test
// asserting on the spawn sees the call it wrote.
const result = options ? await execa(binary, args, options) : await execa(binary, args);
return { stdout: typeof result.stdout === 'string' ? result.stdout : '' };
} catch (error) {
const failure = error as { code?: string; stderr?: string; shortMessage?: string };
if (failure.code === 'ENOENT') {
throw new Error(`\`${binary}\` was not found on PATH. Install it and try again.`);
}
throw new Error(`\`${binary}\` failed: ${failure.stderr?.trim() || failure.shortMessage}`);
}
}
/**
* Extracts the public key from an age key file.