From 9c6053ed8e7061f4f30003341816f4c01479b52e Mon Sep 17 00:00:00 2001 From: dev Date: Fri, 2 Oct 2026 03:46:20 +0200 Subject: [PATCH] CLI: the message of keygen -plain, and a broken prelude with -expect-author From the details of the review: author keygen -plain no longer speaks of a passphrase that the file does not have, and decrypt -expect-author leaves a prelude that does not parse to Open, which reports it at step 1 or 2 with its code, instead of calling it a capsule that is not of format 3. Co-Authored-By: Claude Opus 5.5 --- cmd/datekeys/author.go | 6 +++++- cmd/datekeys/main.go | 6 ++++-- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/cmd/datekeys/author.go b/cmd/datekeys/author.go index 91db762..3604663 100644 --- a/cmd/datekeys/author.go +++ b/cmd/datekeys/author.go @@ -148,7 +148,11 @@ func authorKeygen(args []string, stdout, stderr io.Writer, stdin io.Reader) erro return err } fmt.Fprintln(stdout, pub) - fmt.Fprintf(stderr, "Secret key written to %s: keep it, and its passphrase, secret. The line above is the public key: give it to whoever must know your signature.\n", *out) + secret := "keep it, and its passphrase, secret" + if *plain { + secret = "it is not encrypted: keep the file secret" + } + fmt.Fprintf(stderr, "Secret key written to %s: %s. The line above is the public key: give it to whoever must know your signature.\n", *out, secret) return nil } diff --git a/cmd/datekeys/main.go b/cmd/datekeys/main.go index ce8f324..2542dd3 100644 --- a/cmd/datekeys/main.go +++ b/cmd/datekeys/main.go @@ -392,9 +392,11 @@ func decrypt(args []string, stdout, stderr io.Writer, now func() time.Time) erro n, _ := src.ReadAt(pre[:], 0) var opened *capsule.Opened p, perr := capsule.ParsePrelude(pre[:n]) - if *expect != "" && (perr != nil || p.Format != capsule.Format3) { + if *expect != "" && perr == nil && p.Format != capsule.Format3 { // Only a capsule of format 3 has an author signature: fail before - // the release is requested and before anything is written. + // the release is requested and before anything is written. A prelude + // that does not parse is left to Open, which reports it at step 1 or + // 2 with its code. return errors.New("decrypt: -expect-author: only a capsule of format 3 has an author signature, and this is not one") } if perr == nil && p.Format == capsule.Format3 {