[keyman] phase 2: guard the directories nothing creates
encrypt read ~/.ssh and the tmp directory, and decrypt read <vault>/keys, with no existsSync between them. main.ts created vaultRoot and tmpDir but never keysDir, so decrypt on a fresh vault threw ENOENT instead of printing the "no encrypted keys" message it already had — the message was unreachable until something else created the directory. Both functions now fall through to their warning. main.ts creates all three directories, 0700: the vault holds the age identity and tmp holds plaintext private keys. age spawns go through runTool, which separates "not installed" (ENOENT, whose message is `spawn age ENOENT`) from "age refused" (whose reason is on stderr and nowhere in the thrown message). Tested against real processes, not a mocked execa — the shape of the failure is the point. list.ts kept statSync rather than switching to withFileTypes as planned: withFileTypes reports a symlinked key directory as a link and would have silently dropped it. `throwIfNoEntry: false` fixes the dangling-symlink throw and keeps following the good ones. Both cases now have a test. Also deletes the three debug logs (encrypt.ts printed both key arrays, decrypt.ts printed every candidate path from inside a filter). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
8fa0cfa271
commit
11c323b715
@@ -1,7 +1,20 @@
|
||||
import fs from 'node:fs';
|
||||
import path from 'node:path';
|
||||
import { execa } from 'execa';
|
||||
import inquirer from 'inquirer';
|
||||
import { runTool } from './keyman.utils.js';
|
||||
|
||||
/**
|
||||
* Private keys in a directory that may not exist.
|
||||
*
|
||||
* A first run has neither `~/.ssh` nor the tmp directory, and an unguarded
|
||||
* readdir there threw before the "nothing to encrypt" message could be reached.
|
||||
*/
|
||||
function privateKeysIn(dir: string): string[] {
|
||||
if (!fs.existsSync(dir)) {
|
||||
return [];
|
||||
}
|
||||
return fs.readdirSync(dir).filter((key) => key.startsWith('id_') && !key.endsWith('.pub'));
|
||||
}
|
||||
|
||||
export async function encryptKeys(
|
||||
sshDir: string,
|
||||
@@ -9,14 +22,8 @@ export async function encryptKeys(
|
||||
tmpDir: string,
|
||||
pubkey: string
|
||||
) {
|
||||
const sshKeys = fs
|
||||
.readdirSync(sshDir)
|
||||
.filter((key) => key.startsWith('id_') && !key.endsWith('.pub'));
|
||||
const tmpKeys = fs
|
||||
.readdirSync(tmpDir)
|
||||
.filter((key) => key.startsWith('id_') && !key.endsWith('.pub'));
|
||||
console.log(tmpKeys);
|
||||
console.log(sshKeys);
|
||||
const sshKeys = privateKeysIn(sshDir);
|
||||
const tmpKeys = privateKeysIn(tmpDir);
|
||||
const keys = [...new Set([...sshKeys, ...tmpKeys])];
|
||||
|
||||
if (keys.length === 0) {
|
||||
@@ -36,10 +43,10 @@ export async function encryptKeys(
|
||||
for (const key of selectedKeys) {
|
||||
const keyPath = path.join(tmpKeys.includes(key) ? tmpDir : sshDir, key);
|
||||
const vaultPath = path.join(vaultDir, 'keys', key.replace('id_', ''));
|
||||
fs.mkdirSync(vaultPath, { recursive: true });
|
||||
fs.mkdirSync(vaultPath, { recursive: true, mode: 0o700 });
|
||||
|
||||
// Encrypt key using `age`
|
||||
await execa('age', ['-r', pubkey, '-o', path.join(vaultPath, `${key}.age`), keyPath]);
|
||||
await runTool('age', ['-r', pubkey, '-o', path.join(vaultPath, `${key}.age`), keyPath]);
|
||||
|
||||
// Copy public key and create README
|
||||
fs.copyFileSync(`${keyPath}.pub`, path.join(vaultPath, `${key}.pub`));
|
||||
|
||||
Reference in New Issue
Block a user