Function: sops--decrypt-buffer

sops--decrypt-buffer is a natively compiled function defined in sops.el.

Signature

(sops--decrypt-buffer)

Documentation

Decrypt current buffer's file via sops, replacing buffer contents.

Return t on success, nil on failure (popping an error buffer). Caller must have set the variable buffer-file-name(var)/buffer-file-name(fun) to the encrypted file path.

Source Code

;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--decrypt-buffer ()
  "Decrypt current buffer's file via sops, replacing buffer contents.
Return t on success, nil on failure (popping an error buffer).
Caller must have set the variable `buffer-file-name' to the encrypted file path."
  (run-hooks 'sops-before-decrypt-hook)
  (let* ((file buffer-file-name)
         (input-type (sops--input-type-for file))
         (args (append '("decrypt")
                       (when input-type (list "--input-type" input-type))
                       (sops--maybe-output-type
                        input-type sops-extra-decrypt-args)
                       sops-extra-decrypt-args
                       (list file)))
         (result (sops--run args))
         (exit (plist-get result :exit-status)))
    (if (eq 0 exit)
        (progn
          (let ((inhibit-read-only t))
            (erase-buffer)
            (insert (plist-get result :stdout)))
          (set-buffer-modified-p nil)
          ;; Re-detect major mode against the now-decrypted plaintext, but
          ;; via `set-auto-mode' (extension/auto-mode-alist only) rather
          ;; than `normal-mode' which would also process file-local
          ;; variables and `-*- eval: ... -*-' cookies.  The decrypted
          ;; content is not from a trusted source -- a third party with
          ;; write access to the ciphertext could embed malicious
          ;; cookies that `normal-mode' would honor at decrypt time.
          (set-auto-mode)
          t)
      (sops--popup-error file args exit (plist-get result :stderr))
      nil)))