[keyman] phase 2: guard the directories nothing creates
encrypt read ~/.ssh and the tmp directory, and decrypt read <vault>/keys, with no existsSync between them. main.ts created vaultRoot and tmpDir but never keysDir, so decrypt on a fresh vault threw ENOENT instead of printing the "no encrypted keys" message it already had — the message was unreachable until something else created the directory. Both functions now fall through to their warning. main.ts creates all three directories, 0700: the vault holds the age identity and tmp holds plaintext private keys. age spawns go through runTool, which separates "not installed" (ENOENT, whose message is `spawn age ENOENT`) from "age refused" (whose reason is on stderr and nowhere in the thrown message). Tested against real processes, not a mocked execa — the shape of the failure is the point. list.ts kept statSync rather than switching to withFileTypes as planned: withFileTypes reports a symlinked key directory as a link and would have silently dropped it. `throwIfNoEntry: false` fixes the dangling-symlink throw and keeps following the good ones. Both cases now have a test. Also deletes the three debug logs (encrypt.ts printed both key arrays, decrypt.ts printed every candidate path from inside a filter). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
8fa0cfa271
commit
11c323b715
@@ -1,4 +1,37 @@
|
||||
import fs from 'node:fs';
|
||||
import { execa, type Options } from 'execa';
|
||||
|
||||
/**
|
||||
* Runs one of the external binaries keyman depends on.
|
||||
*
|
||||
* Two failures are worth telling apart, and an execa error tells a reader
|
||||
* neither: the binary not being installed (`ENOENT`, whose message is
|
||||
* `spawn <name> ENOENT`) and the binary refusing (whose reason is on stderr and
|
||||
* nowhere in the thrown message). `age` is a hard requirement, so its absence
|
||||
* has to read as an instruction.
|
||||
*
|
||||
* Returns only `stdout` — annotated rather than inferred because execa's result
|
||||
* type cannot be named from here (TS2883), and it is all any caller wants. Empty
|
||||
* when the output went somewhere else, as with `stdio: 'inherit'`.
|
||||
*/
|
||||
export async function runTool(
|
||||
binary: string,
|
||||
args: string[],
|
||||
options?: Options
|
||||
): Promise<{ stdout: string }> {
|
||||
try {
|
||||
// Called without the third argument when there are no options, so a test
|
||||
// asserting on the spawn sees the call it wrote.
|
||||
const result = options ? await execa(binary, args, options) : await execa(binary, args);
|
||||
return { stdout: typeof result.stdout === 'string' ? result.stdout : '' };
|
||||
} catch (error) {
|
||||
const failure = error as { code?: string; stderr?: string; shortMessage?: string };
|
||||
if (failure.code === 'ENOENT') {
|
||||
throw new Error(`\`${binary}\` was not found on PATH. Install it and try again.`);
|
||||
}
|
||||
throw new Error(`\`${binary}\` failed: ${failure.stderr?.trim() || failure.shortMessage}`);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Extracts the public key from an age key file.
|
||||
|
||||
Reference in New Issue
Block a user