Function: sops--encrypt-and-write
sops--encrypt-and-write is a natively compiled function defined in
sops.el.
Signature
(sops--encrypt-and-write)
Documentation
Encrypt current buffer via sops and write to the variable buffer-file-name(var)/buffer-file-name(fun).
Return t on success. Signals user-error on failure (aborts save).
Reads the full buffer (widened) so a narrowed buffer isn't silently
truncated on save. Suppresses backups (make-backup-files) around
the write because ciphertext backups accumulate without recovery
value -- the user can't usefully edit them manually.
After write-region, refreshes visited-file-modtime so Emacs's
modtime check (used by verify-visited-file-modtime) matches the
file we just wrote. Without this, the next edit triggers a
"FILE has changed on disk; really edit the buffer?" prompt
because find-file recorded the *encrypted* file's modtime and
our write replaced it.
On the first successful save of a sops-find-file 'creating
buffer, transitions sops--state.status to 'decrypted so
subsequent saves and reverts follow the normal v0.2 paths.
Source Code
;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--encrypt-and-write ()
"Encrypt current buffer via sops and write to the variable `buffer-file-name'.
Return t on success. Signals `user-error' on failure (aborts save).
Reads the full buffer (widened) so a narrowed buffer isn't silently
truncated on save. Suppresses backups (`make-backup-files') around
the write because ciphertext backups accumulate without recovery
value -- the user can't usefully edit them manually.
After `write-region', refreshes `visited-file-modtime' so Emacs's
modtime check (used by `verify-visited-file-modtime') matches the
file we just wrote. Without this, the next edit triggers a
\"FILE has changed on disk; really edit the buffer?\" prompt
because `find-file' recorded the *encrypted* file's modtime and
our write replaced it.
On the first successful save of a `sops-find-file' \\='creating
buffer, transitions `sops--state.status' to \\='decrypted so
subsequent saves and reverts follow the normal v0.2 paths."
(run-hooks 'sops-before-encrypt-hook)
(let* ((file buffer-file-name)
(input-type (sops--input-type-for file))
(args (append '("encrypt" "--filename-override")
(list file)
(when input-type (list "--input-type" input-type))
(sops--maybe-output-type
input-type sops-extra-encrypt-args)
sops-extra-encrypt-args))
(result (sops--run args :input (save-restriction
(widen)
(buffer-substring-no-properties
(point-min) (point-max)))))
(exit (plist-get result :exit-status))
(stdout (plist-get result :stdout)))
(cond
((not (eq 0 exit))
(sops--popup-error file args exit (plist-get result :stderr))
(user-error "Sops encrypt failed (exit %d)" exit))
((zerop (length stdout))
(sops--popup-error file args exit "sops: encrypt produced empty output\n")
(user-error "Sops encrypt produced empty output")))
(let ((coding-system-for-write 'no-conversion)
(make-backup-files nil))
(write-region stdout nil file nil 'silent))
(set-visited-file-modtime)
(set-buffer-modified-p nil)
;; First-save transition for sops-find-file's 'creating buffers.
;; After this, the buffer is indistinguishable from one decrypted
;; via the find-file-hook; reverts go through sops--revert-buffer.
(when (and sops--state
(eq (sops-state-status sops--state) 'creating))
(setf (sops-state-status sops--state) 'decrypted))
t))