Function: sops--retry-decrypt-on-revert

sops--retry-decrypt-on-revert is a natively compiled function defined in sops.el.

Signature

(sops--retry-decrypt-on-revert &rest ARGS)

Documentation

Retry sops decrypt as a revert-buffer-function after initial failure.

Installed in sops--find-file-hook when the first sops--decrypt-buffer call exits non-zero -- without this hook, revert-buffer would fall through to the default implementation which just re-reads the encrypted bytes and never re-invokes sops, so the recovery hint printed into
*sops-error:* ("fix auth, then \\[revert-buffer]") would be a lie.

Re-reads the encrypted file from disk (in case the user also fixed things externally) and re-runs sops--decrypt-buffer. On success, disables read-only-mode and enables sops-mode(var)/sops-mode(fun) -- enabling sops-mode installs the real sops--revert-buffer for subsequent reverts, so this retry function only runs as long as decrypt keeps failing. On continued failure, sops--decrypt-buffer pops the error buffer again and the buffer stays read-only with ciphertext.

Source Code

;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--retry-decrypt-on-revert (&rest _args)
  "Retry sops decrypt as a `revert-buffer-function' after initial failure.
Installed in `sops--find-file-hook' when the first `sops--decrypt-buffer'
call exits non-zero -- without this hook, `revert-buffer' would fall
through to the default implementation which just re-reads the encrypted
bytes and never re-invokes sops, so the recovery hint printed into
`*sops-error:*' (\"fix auth, then \\[revert-buffer]\") would be a lie.

Re-reads the encrypted file from disk (in case the user also fixed
things externally) and re-runs `sops--decrypt-buffer'.  On success,
disables `read-only-mode' and enables `sops-mode' -- enabling sops-mode
installs the real `sops--revert-buffer' for subsequent reverts, so this
retry function only runs as long as decrypt keeps failing.  On
continued failure, `sops--decrypt-buffer' pops the error buffer again
and the buffer stays read-only with ciphertext."
  (save-restriction
    (widen)
    (set-visited-file-modtime)
    (let ((inhibit-read-only t))
      (erase-buffer)
      (insert-file-contents buffer-file-name)))
  (set-buffer-modified-p nil)
  (when (sops--decrypt-buffer)
    ;; Mirror the find-file-hook failure path: set `buffer-read-only'
    ;; directly so `revert-buffer's read-only state restoration (inline
    ;; on Emacs 29.1, hook-driven on 30+) leaves us writable.
    (setq buffer-read-only nil)
    ;; Pre-set state so the `sops-mode' enable guard skips its own
    ;; `sops--filestatus' re-check -- we just decrypted, the file is
    ;; sops-encrypted by definition.
    (setq sops--state (sops-state-create :status 'decrypted))
    (sops-mode 1)))