[keyman] phase 2: guard the directories nothing creates

encrypt read ~/.ssh and the tmp directory, and decrypt read <vault>/keys,
with no existsSync between them. main.ts created vaultRoot and tmpDir but
never keysDir, so decrypt on a fresh vault threw ENOENT instead of
printing the "no encrypted keys" message it already had — the message was
unreachable until something else created the directory.

Both functions now fall through to their warning. main.ts creates all
three directories, 0700: the vault holds the age identity and tmp holds
plaintext private keys.

age spawns go through runTool, which separates "not installed" (ENOENT,
whose message is `spawn age ENOENT`) from "age refused" (whose reason is
on stderr and nowhere in the thrown message). Tested against real
processes, not a mocked execa — the shape of the failure is the point.

list.ts kept statSync rather than switching to withFileTypes as planned:
withFileTypes reports a symlinked key directory as a link and would have
silently dropped it. `throwIfNoEntry: false` fixes the dangling-symlink
throw and keeps following the good ones. Both cases now have a test.

Also deletes the three debug logs (encrypt.ts printed both key arrays,
decrypt.ts printed every candidate path from inside a filter).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Benjamin Diedrichsen
2026-07-30 14:33:26 +02:00
parent 8fa0cfa271
commit 11c323b715
10 changed files with 183 additions and 22 deletions
+17
View File
@@ -69,6 +69,23 @@ describe('decryptKeys', () => {
expect(prompt).not.toHaveBeenCalled();
});
it('warns instead of throwing when the vault has no keys directory', async () => {
fs.rmSync(keyDir, { recursive: true });
await expect(decryptKeys(sshDir, vaultDir, AGE_KEY)).resolves.toBeUndefined();
expect(messages(logSpy)).toContain('No encrypted keys found.');
});
it('reports a missing age binary rather than an ENOENT', async () => {
vaultKey('prod');
prompt.mockResolvedValue({ selectedKeys: ['prod'], decryptMode: LOCAL });
execa.mockRejectedValue(Object.assign(new Error('spawn age ENOENT'), { code: 'ENOENT' }));
await expect(decryptKeys(sshDir, vaultDir, AGE_KEY)).rejects.toThrow(
'`age` was not found on PATH'
);
});
it('offers only directories that actually contain an encrypted key', async () => {
vaultKey('prod');
fs.mkdirSync(path.join(keyDir, 'empty'), { recursive: true });
+27
View File
@@ -66,6 +66,33 @@ describe('encryptKeys', () => {
expect(prompt).not.toHaveBeenCalled();
});
it('warns instead of throwing when the .ssh directory does not exist', async () => {
fs.rmSync(sshDir, { recursive: true });
await expect(encryptKeys(sshDir, vaultDir, tmpDir, PUBKEY)).resolves.toBeUndefined();
expect(messages(logSpy)).toContain('No private SSH keys found to encrypt.');
});
it('still offers the .ssh keys when the tmp directory does not exist', async () => {
fs.rmSync(tmpDir, { recursive: true });
key(sshDir, 'id_prod', 'ssh');
prompt.mockResolvedValue({ selectedKeys: [] });
await encryptKeys(sshDir, vaultDir, tmpDir, PUBKEY);
expect(choices()).toEqual(['id_prod']);
});
it('reports a missing age binary rather than an ENOENT', async () => {
key(sshDir, 'id_prod', 'ssh');
prompt.mockResolvedValue({ selectedKeys: ['id_prod'] });
execa.mockRejectedValue(Object.assign(new Error('spawn age ENOENT'), { code: 'ENOENT' }));
await expect(encryptKeys(sshDir, vaultDir, tmpDir, PUBKEY)).rejects.toThrow(
'`age` was not found on PATH'
);
});
it('ignores public keys and unrelated files when building the list', async () => {
fs.writeFileSync(path.join(sshDir, 'known_hosts'), '');
fs.writeFileSync(path.join(sshDir, 'id_orphan.pub'), 'PUBLIC');
+19
View File
@@ -182,6 +182,25 @@ describe('listKeys', () => {
expect(row('id_real')).toBeDefined();
});
it('keeps listing when the vault holds a dangling symlink', async () => {
vaultKey('real');
fs.symlinkSync(path.join(root, 'gone'), path.join(vaultDir, 'broken'));
await expect(listKeys(sshDir, vaultDir, tmpDir)).resolves.toBeUndefined();
expect(row('id_real')).toBeDefined();
});
it('follows a symlink pointing at a real vault directory', async () => {
const elsewhere = path.join(root, 'elsewhere', 'prod');
touch(elsewhere, 'id_prod.age');
fs.mkdirSync(vaultDir, { recursive: true });
fs.symlinkSync(elsewhere, path.join(vaultDir, 'prod'));
await listKeys(sshDir, vaultDir, tmpDir);
expect(row('id_prod')).toBeDefined();
});
it('ignores loose files sitting next to the vault directories', async () => {
vaultKey('real');
fs.writeFileSync(path.join(vaultDir, 'README.md'), '');
+11
View File
@@ -106,6 +106,17 @@ describe('keyman', () => {
expect(output()).toContain(paths.keyPath);
expect(fs.existsSync(paths.vaultRoot)).toBe(true);
expect(fs.existsSync(paths.tmpDir)).toBe(true);
// keysDir too: decrypt reads it, and nothing created it before the first
// encrypt, so a fresh vault could not be decrypted from.
expect(fs.existsSync(paths.keysDir)).toBe(true);
});
it('creates the vault directories private to the owner', async () => {
await keyman();
for (const dir of [paths.vaultRoot, paths.keysDir, paths.tmpDir]) {
expect(fs.statSync(dir).mode & 0o777, dir).toBe(0o700);
}
});
it('quits without running any operation', async () => {
+40 -1
View File
@@ -9,7 +9,7 @@ import fs from 'node:fs';
import os from 'node:os';
import path from 'node:path';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
import { extractAgePublicKey } from '../src/keyman.utils.js';
import { extractAgePublicKey, runTool } from '../src/keyman.utils.js';
describe('extractAgePublicKey', () => {
let tmpDir: string;
@@ -77,3 +77,42 @@ describe('extractAgePublicKey', () => {
expect(errorSpy.mock.calls[0][0]).toContain('Failed to read key file');
});
});
/**
* These spawn real processes rather than mocking execa. The whole point of
* runTool is the shape of an execa failure, and a mock would only assert what
* this test already assumes.
*/
describe('runTool', () => {
it('returns the result on success', async () => {
const result = await runTool('node', ['-e', 'process.stdout.write("hi")']);
expect(result.stdout).toBe('hi');
});
it('passes options through', async () => {
const result = await runTool('node', ['-e', 'process.stdout.write(process.env.PROBE ?? "")'], {
env: { PROBE: 'from-options' },
});
expect(result.stdout).toBe('from-options');
});
it('reports a missing binary as an instruction rather than an ENOENT', async () => {
await expect(runTool('keyman-no-such-binary', [])).rejects.toThrow(
'`keyman-no-such-binary` was not found on PATH. Install it and try again.'
);
});
it('surfaces what the binary wrote to stderr', async () => {
await expect(
runTool('node', ['-e', 'process.stderr.write("no recipient\\n"); process.exit(1)'])
).rejects.toThrow('`node` failed: no recipient');
});
it('falls back to the command summary when stderr is empty', async () => {
await expect(runTool('node', ['-e', 'process.exit(3)'])).rejects.toThrow(
/`node` failed: .*exit code 3/
);
});
});