Function: sops--find-file-hook

sops--find-file-hook is a natively compiled function defined in sops.el.

Signature

(sops--find-file-hook)

Documentation

On find-file: if file matches prefilter and is sops-encrypted, decrypt.

Skips remote (TRAMP) files in v0.2 — local sops binary cannot read TRAMP paths. Remote support belongs in the separate tramp-sops package.

Source Code

;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--find-file-hook ()
  "On find-file: if file matches prefilter and is sops-encrypted, decrypt.
Skips remote (TRAMP) files in v0.2 — local sops binary cannot read TRAMP
paths.  Remote support belongs in the separate `tramp-sops' package."
  (when (and buffer-file-name
             (not (file-remote-p buffer-file-name))
             (sops--prefilter-p buffer-file-name)
             (file-readable-p buffer-file-name))
    (condition-case err
        (when (sops--ensure-version)
          (when (sops--filestatus buffer-file-name)
            (if (sops--decrypt-buffer)
                (progn
                  ;; Pre-set state so the `sops-mode' enable guard skips
                  ;; its own `sops--filestatus' re-check -- we just
                  ;; validated above and ran decrypt successfully.
                  (setq sops--state
                        (sops-state-create :status 'decrypted))
                  (sops-mode 1))
              ;; Decrypt failed: park the retry function on
              ;; `revert-buffer-function' so the popped error buffer's
              ;; "M-x revert-buffer to retry" hint actually works.  On
              ;; successful retry, sops-mode activation replaces this with
              ;; the real `sops--revert-buffer'.
              (setq-local revert-buffer-function
                          #'sops--retry-decrypt-on-revert)
              ;; Set `buffer-read-only' directly rather than calling
              ;; `read-only-mode' so we don't populate
              ;; `read-only-mode--state'.  `revert-buffer' on Emacs 29.1
              ;; (inline) and 30+ (`revert-buffer-restore-read-only')
              ;; both capture that state pre-revert and re-apply
              ;; `buffer-read-only' from it post-revert, which would
              ;; undo the `(setq buffer-read-only nil)' our retry path
              ;; performs on successful re-decrypt.  With the state var
              ;; left untouched, the captured value is nil and the
              ;; restoration is a no-op.
              (setq buffer-read-only t))))
      (user-error
       ;; sops missing or too old: log once, do nothing
       (message "sops: %s" (error-message-string err))))))