Function: sops--retry-decrypt-on-revert
sops--retry-decrypt-on-revert is a natively compiled function defined
in sops.el.
Signature
(sops--retry-decrypt-on-revert &rest ARGS)
Documentation
Retry sops decrypt as a revert-buffer-function after initial failure.
Installed in sops--find-file-hook when the first sops--decrypt-buffer
call exits non-zero -- without this hook, revert-buffer would fall
through to the default implementation which just re-reads the encrypted
bytes and never re-invokes sops, so the recovery hint printed into
*sops-error:* ("fix auth, then \\[revert-buffer]") would be a lie.
Re-reads the encrypted file from disk (in case the user also fixed
things externally) and re-runs sops--decrypt-buffer. On success,
disables read-only-mode and enables sops-mode(var)/sops-mode(fun) -- enabling sops-mode
installs the real sops--revert-buffer for subsequent reverts, so this
retry function only runs as long as decrypt keeps failing. On
continued failure, sops--decrypt-buffer pops the error buffer again
and the buffer stays read-only with ciphertext.
Source Code
;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--retry-decrypt-on-revert (&rest _args)
"Retry sops decrypt as a `revert-buffer-function' after initial failure.
Installed in `sops--find-file-hook' when the first `sops--decrypt-buffer'
call exits non-zero -- without this hook, `revert-buffer' would fall
through to the default implementation which just re-reads the encrypted
bytes and never re-invokes sops, so the recovery hint printed into
`*sops-error:*' (\"fix auth, then \\[revert-buffer]\") would be a lie.
Re-reads the encrypted file from disk (in case the user also fixed
things externally) and re-runs `sops--decrypt-buffer'. On success,
disables `read-only-mode' and enables `sops-mode' -- enabling sops-mode
installs the real `sops--revert-buffer' for subsequent reverts, so this
retry function only runs as long as decrypt keeps failing. On
continued failure, `sops--decrypt-buffer' pops the error buffer again
and the buffer stays read-only with ciphertext."
(save-restriction
(widen)
(set-visited-file-modtime)
(let ((inhibit-read-only t))
(erase-buffer)
(insert-file-contents buffer-file-name)))
(set-buffer-modified-p nil)
(when (sops--decrypt-buffer)
;; Mirror the find-file-hook failure path: set `buffer-read-only'
;; directly so `revert-buffer's read-only state restoration (inline
;; on Emacs 29.1, hook-driven on 30+) leaves us writable.
(setq buffer-read-only nil)
;; Pre-set state so the `sops-mode' enable guard skips its own
;; `sops--filestatus' re-check -- we just decrypted, the file is
;; sops-encrypted by definition.
(setq sops--state (sops-state-create :status 'decrypted))
(sops-mode 1)))