Function: sops--encrypt-and-write

sops--encrypt-and-write is a natively compiled function defined in sops.el.

Signature

(sops--encrypt-and-write)

Documentation

Encrypt current buffer via sops and write to the variable buffer-file-name(var)/buffer-file-name(fun).

Return t on success. Signals user-error on failure (aborts save).

Reads the full buffer (widened) so a narrowed buffer isn't silently truncated on save. Suppresses backups (make-backup-files) around the write because ciphertext backups accumulate without recovery value -- the user can't usefully edit them manually.

After write-region, refreshes visited-file-modtime so Emacs's modtime check (used by verify-visited-file-modtime) matches the file we just wrote. Without this, the next edit triggers a
"FILE has changed on disk; really edit the buffer?" prompt
because find-file recorded the *encrypted* file's modtime and our write replaced it.

On the first successful save of a sops-find-file 'creating buffer, transitions sops--state.status to 'decrypted so subsequent saves and reverts follow the normal v0.2 paths.

Source Code

;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--encrypt-and-write ()
  "Encrypt current buffer via sops and write to the variable `buffer-file-name'.
Return t on success.  Signals `user-error' on failure (aborts save).

Reads the full buffer (widened) so a narrowed buffer isn't silently
truncated on save.  Suppresses backups (`make-backup-files') around
the write because ciphertext backups accumulate without recovery
value -- the user can't usefully edit them manually.

After `write-region', refreshes `visited-file-modtime' so Emacs's
modtime check (used by `verify-visited-file-modtime') matches the
file we just wrote.  Without this, the next edit triggers a
\"FILE has changed on disk; really edit the buffer?\" prompt
because `find-file' recorded the *encrypted* file's modtime and
our write replaced it.

On the first successful save of a `sops-find-file' \\='creating
buffer, transitions `sops--state.status' to \\='decrypted so
subsequent saves and reverts follow the normal v0.2 paths."
  (run-hooks 'sops-before-encrypt-hook)
  (let* ((file buffer-file-name)
         (input-type (sops--input-type-for file))
         (args (append '("encrypt" "--filename-override")
                       (list file)
                       (when input-type (list "--input-type" input-type))
                       (sops--maybe-output-type
                        input-type sops-extra-encrypt-args)
                       sops-extra-encrypt-args))
         (result (sops--run args :input (save-restriction
                                          (widen)
                                          (buffer-substring-no-properties
                                           (point-min) (point-max)))))
         (exit (plist-get result :exit-status))
         (stdout (plist-get result :stdout)))
    (cond
     ((not (eq 0 exit))
      (sops--popup-error file args exit (plist-get result :stderr))
      (user-error "Sops encrypt failed (exit %d)" exit))
     ((zerop (length stdout))
      (sops--popup-error file args exit "sops: encrypt produced empty output\n")
      (user-error "Sops encrypt produced empty output")))
    (let ((coding-system-for-write 'no-conversion)
          (make-backup-files nil))
      (write-region stdout nil file nil 'silent))
    (set-visited-file-modtime)
    (set-buffer-modified-p nil)
    ;; First-save transition for sops-find-file's 'creating buffers.
    ;; After this, the buffer is indistinguishable from one decrypted
    ;; via the find-file-hook; reverts go through sops--revert-buffer.
    (when (and sops--state
               (eq (sops-state-status sops--state) 'creating))
      (setf (sops-state-status sops--state) 'decrypted))
    t))