diff options
| author | Danilo M. <danix@danix.xyz> | 2026-08-09 14:56:59 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-08-09 14:56:59 +0200 |
| commit | 37e2b3d9da2297e18431b4dd9e21170aff673b3e (patch) | |
| tree | cd2e73067d9fcbe628f436bfc96b2b706c21bffd /docs/superpowers | |
| parent | 22e177e4d2723df8612fbad2851c03d66724b2c4 (diff) | |
| download | llamachat-37e2b3d9da2297e18431b4dd9e21170aff673b3e.tar.gz llamachat-37e2b3d9da2297e18431b4dd9e21170aff673b3e.zip | |
docs: stop crediting from None with secret hygiene
A TimeoutExpired chained without from None already prints no secret,
since its __str__ shows only the command and the duration. The suppressed
display buys a tidier traceback, not a narrower leak, and the comments
claimed otherwise. The from None calls stay.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'docs/superpowers')
| -rw-r--r-- | docs/superpowers/plans/2026-08-09-external-providers.md | 14 |
1 files changed, 7 insertions, 7 deletions
diff --git a/docs/superpowers/plans/2026-08-09-external-providers.md b/docs/superpowers/plans/2026-08-09-external-providers.md index d34fffc..158306b 100644 --- a/docs/superpowers/plans/2026-08-09-external-providers.md +++ b/docs/superpowers/plans/2026-08-09-external-providers.md @@ -589,8 +589,9 @@ def test_key_resolution(): assert "gpg-agent" in str(exc) # The partial stdout a timeout captures must never reach the message. assert "partial-secret" not in str(exc) - # `from None` suppresses the chained traceback. It does not clear - # __context__, so this pins the display behavior, not unreachability. + # `from None` suppresses the chained-traceback display. It does not + # clear __context__, and the chained traceback would not have shown + # the secret anyway, so this pins tidiness, not secret hygiene. assert exc.__suppress_context__ and exc.__cause__ is None # A non-zero exit quotes gpg's stderr, which is the only useful part, and @@ -712,11 +713,10 @@ class KeyResolver: def _from_pass(self, provider: Provider, entry: str) -> str: try: out = self._runner(["pass", "show", entry], timeout=KEY_TIMEOUT) - # Every raise below is `from None`. Both TimeoutExpired and - # CalledProcessError carry a .stdout that can hold a partial secret, - # and this keeps it out of any printed traceback. Note it suppresses - # display only: __context__ still references the original, so the - # real guarantee is that no handler here puts stdout in the message. + # Every raise below is `from None`. It suppresses the chained-traceback + # display only, __context__ still references the original with its + # .stdout, so the real guarantee is that no handler here puts stdout + # in the message. except subprocess.TimeoutExpired: # The likely cause is a pinentry that never appeared, not one # sitting in front of the user: no $DISPLAY inherited, no |
