[keyman] phase 2: guard the directories nothing creates

encrypt read ~/.ssh and the tmp directory, and decrypt read <vault>/keys,
with no existsSync between them. main.ts created vaultRoot and tmpDir but
never keysDir, so decrypt on a fresh vault threw ENOENT instead of
printing the "no encrypted keys" message it already had — the message was
unreachable until something else created the directory.

Both functions now fall through to their warning. main.ts creates all
three directories, 0700: the vault holds the age identity and tmp holds
plaintext private keys.

age spawns go through runTool, which separates "not installed" (ENOENT,
whose message is `spawn age ENOENT`) from "age refused" (whose reason is
on stderr and nowhere in the thrown message). Tested against real
processes, not a mocked execa — the shape of the failure is the point.

list.ts kept statSync rather than switching to withFileTypes as planned:
withFileTypes reports a symlinked key directory as a link and would have
silently dropped it. `throwIfNoEntry: false` fixes the dangling-symlink
throw and keeps following the good ones. Both cases now have a test.

Also deletes the three debug logs (encrypt.ts printed both key arrays,
decrypt.ts printed every candidate path from inside a filter).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Benjamin Diedrichsen
2026-07-30 14:33:26 +02:00
parent 8fa0cfa271
commit 11c323b715
10 changed files with 183 additions and 22 deletions
+19
View File
@@ -182,6 +182,25 @@ describe('listKeys', () => {
expect(row('id_real')).toBeDefined();
});
it('keeps listing when the vault holds a dangling symlink', async () => {
vaultKey('real');
fs.symlinkSync(path.join(root, 'gone'), path.join(vaultDir, 'broken'));
await expect(listKeys(sshDir, vaultDir, tmpDir)).resolves.toBeUndefined();
expect(row('id_real')).toBeDefined();
});
it('follows a symlink pointing at a real vault directory', async () => {
const elsewhere = path.join(root, 'elsewhere', 'prod');
touch(elsewhere, 'id_prod.age');
fs.mkdirSync(vaultDir, { recursive: true });
fs.symlinkSync(elsewhere, path.join(vaultDir, 'prod'));
await listKeys(sshDir, vaultDir, tmpDir);
expect(row('id_prod')).toBeDefined();
});
it('ignores loose files sitting next to the vault directories', async () => {
vaultKey('real');
fs.writeFileSync(path.join(vaultDir, 'README.md'), '');