Function: sops--run

sops--run is a natively compiled function defined in sops.el.

Signature

(sops--run ARGS &rest KEYS)

Documentation

Run sops with ARGS. KEYS is a plist of keyword options.

Keyword args:
  :input STRING -- write STRING to a temp file (mode 0600) and pass
                    its path to sops as the trailing argument. The
                    temp file is deleted in the unwind-protect cleanup.
                    Matches Emacs core's EPG/EPA convention: stdin is
                    reserved for prompt responses; payload bytes go
                    via the file path.
  :filter FN -- process filter (nil in v0.2; populated in future work)
Return plist (:exit-status N :stdout STR :stderr STR).

Source Code

;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--run (args &rest keys)
  "Run sops with ARGS.  KEYS is a plist of keyword options.
Keyword args:
  :input STRING  -- write STRING to a temp file (mode 0600) and pass
                    its path to sops as the trailing argument.  The
                    temp file is deleted in the `unwind-protect' cleanup.
                    Matches Emacs core's EPG/EPA convention: stdin is
                    reserved for prompt responses; payload bytes go
                    via the file path.
  :filter FN     -- process filter (nil in v0.2; populated in future work)
Return plist (:exit-status N :stdout STR :stderr STR)."
  (let* ((input (plist-get keys :input))
         (filter (plist-get keys :filter))
         (stdout-buf (generate-new-buffer " *sops-stdout*" t))
         (stderr-buf (generate-new-buffer " *sops-stderr*" t))
         (input-file (when input
                       (with-file-modes #o600
                         (make-temp-file "sops-input-"))))
         (done nil)
         (proc nil)
         (stderr-proc nil))
    (unwind-protect
        (let ((process-environment
               (cons "SOPS_DISABLE_VERSION_CHECK=true" process-environment)))
          (when input
            (let ((coding-system-for-write 'utf-8-unix))
              (write-region input nil input-file nil 'silent)))
          (setq proc
                (make-process
                 :name "sops"
                 :buffer stdout-buf
                 :stderr stderr-buf
                 :command (cons sops-executable
                                (if input-file
                                    (append args (list input-file))
                                  args))
                 :connection-type 'pipe
                 :filter filter
                 :sentinel (lambda (_p _event) (setq done t))))
          (setq stderr-proc (get-buffer-process stderr-buf))
          (set-process-coding-system proc 'utf-8-unix 'utf-8-unix)
          (while (and (not done) (process-live-p proc))
            (accept-process-output proc 0.1))
          (accept-process-output proc 0 nil t)
          ;; :stderr BUFFER creates a separate pipe process.  The final
          ;; stdout read above does not service it when JUST-THIS-ONE is t.
          (when stderr-proc
            (while (accept-process-output stderr-proc 0 nil t)))
          (list :exit-status (process-exit-status proc)
                :stdout (with-current-buffer stdout-buf (buffer-string))
                :stderr (with-current-buffer stderr-buf (buffer-string))))
      (when (and proc (process-live-p proc))
        (delete-process proc))
      (when (buffer-live-p stdout-buf) (kill-buffer stdout-buf))
      (when (buffer-live-p stderr-buf) (kill-buffer stderr-buf))
      (when (and input-file (file-exists-p input-file))
        (delete-file input-file)))))