Files
mesh-catalog/modules/gnome-keyring/cmd/gnome-keyring-tools/main.go
T
jochen e810afb3eb gnome-keyring: the secret service as a module, claiming node-secret-service (hq ADR 0208, ADR 0102)
PAM lines written into login and passwd as blocks, so login unlocks the keyring
on both workstations; no daemon of its own; gcr's ssh agent named for the session
until the environment can say a runtime-directory path. Go tools unlocked, lock,
collections and ssh-keys, never reading a secret.
2026-10-04 13:15:39 +02:00

58 lines
2.0 KiB
Go

// gnome-keyring's Go tools bundle (novox/hq ADR 0188, ADR 0193, ADR 0208): the secret service's
// tools, served by the node's runtime as the operator account. node-secret-service has no verbs yet
// (ADR 0208 §2), so every tool here is the module's own. None of them ever reads a secret: they ask the
// Secret Service for names, counts and lock states, and the ssh agent for fingerprints.
package main
import (
"fmt"
"os"
stdio "git.novox.be/novox/mesh-sdk/go"
)
func main() {
if err := stdio.Serve("", tools()); err != nil {
fmt.Fprintln(os.Stderr, err)
os.Exit(1)
}
}
func tools() []stdio.Tool {
return []stdio.Tool{
{
Name: "gnome_keyring_unlocked",
Description: "Is the operator's keyring unlocked: the login keyring and the default one, each locked " +
"or not, and whether the keyring daemon runs.",
Run: func(map[string]any) (any, error) { return Unlocked() },
},
{
Name: "gnome_keyring_lock",
Description: "Lock a keyring now (the login keyring unless another is named): programs must ask " +
"for its password again. Unlocking is the operator's, at their desktop.",
Input: map[string]any{
"collection": map[string]any{"type": "string", "description": "the keyring's id, as gnome_keyring_collections answers it (default login)"},
},
Run: func(args map[string]any) (any, error) {
c, err := text(args, "collection", false)
if err != nil {
return nil, err
}
return Lock(c)
},
},
{
Name: "gnome_keyring_collections",
Description: "The operator's keyrings: each one's id, label, whether it is locked, how many items it " +
"holds, when it was created and changed, and which is the default. Never an item, never a secret.",
Run: func(map[string]any) (any, error) { return Collections() },
},
{
Name: "gnome_keyring_ssh_keys",
Description: "The keys the session's ssh agent (gcr's) holds, by fingerprint, size, type and comment. " +
"Never a key.",
Run: func(map[string]any) (any, error) { return SSHKeys() },
},
}
}