From 37e2b3d9da2297e18431b4dd9e21170aff673b3e Mon Sep 17 00:00:00 2001 From: "Danilo M." Date: Sun, 9 Aug 2026 14:56:59 +0200 Subject: docs: stop crediting from None with secret hygiene A TimeoutExpired chained without from None already prints no secret, since its __str__ shows only the command and the duration. The suppressed display buys a tidier traceback, not a narrower leak, and the comments claimed otherwise. The from None calls stay. Co-Authored-By: Claude Opus 5 --- docs/superpowers/plans/2026-08-09-external-providers.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) (limited to 'docs') diff --git a/docs/superpowers/plans/2026-08-09-external-providers.md b/docs/superpowers/plans/2026-08-09-external-providers.md index d34fffc..158306b 100644 --- a/docs/superpowers/plans/2026-08-09-external-providers.md +++ b/docs/superpowers/plans/2026-08-09-external-providers.md @@ -589,8 +589,9 @@ def test_key_resolution(): assert "gpg-agent" in str(exc) # The partial stdout a timeout captures must never reach the message. assert "partial-secret" not in str(exc) - # `from None` suppresses the chained traceback. It does not clear - # __context__, so this pins the display behavior, not unreachability. + # `from None` suppresses the chained-traceback display. It does not + # clear __context__, and the chained traceback would not have shown + # the secret anyway, so this pins tidiness, not secret hygiene. assert exc.__suppress_context__ and exc.__cause__ is None # A non-zero exit quotes gpg's stderr, which is the only useful part, and @@ -712,11 +713,10 @@ class KeyResolver: def _from_pass(self, provider: Provider, entry: str) -> str: try: out = self._runner(["pass", "show", entry], timeout=KEY_TIMEOUT) - # Every raise below is `from None`. Both TimeoutExpired and - # CalledProcessError carry a .stdout that can hold a partial secret, - # and this keeps it out of any printed traceback. Note it suppresses - # display only: __context__ still references the original, so the - # real guarantee is that no handler here puts stdout in the message. + # Every raise below is `from None`. It suppresses the chained-traceback + # display only, __context__ still references the original with its + # .stdout, so the real guarantee is that no handler here puts stdout + # in the message. except subprocess.TimeoutExpired: # The likely cause is a pinentry that never appeared, not one # sitting in front of the user: no $DISPLAY inherited, no -- cgit v1.2.3