Function: sops--run
sops--run is a natively compiled function defined in sops.el.
Signature
(sops--run ARGS &rest KEYS)
Documentation
Run sops with ARGS. KEYS is a plist of keyword options.
Keyword args:
:input STRING -- write STRING to a temp file (mode 0600) and pass
its path to sops as the trailing argument. The
temp file is deleted in the unwind-protect cleanup.
Matches Emacs core's EPG/EPA convention: stdin is
reserved for prompt responses; payload bytes go
via the file path.
:filter FN -- process filter (nil in v0.2; populated in future work)
Return plist (:exit-status N :stdout STR :stderr STR).
Source Code
;; Defined in /nix/store/vihl6lkzddv9xrsrsznvqdjq27g2i30p-emacs-packages-deps/share/emacs/site-lisp/elpa/sops-20260920.2121/sops.el
(defun sops--run (args &rest keys)
"Run sops with ARGS. KEYS is a plist of keyword options.
Keyword args:
:input STRING -- write STRING to a temp file (mode 0600) and pass
its path to sops as the trailing argument. The
temp file is deleted in the `unwind-protect' cleanup.
Matches Emacs core's EPG/EPA convention: stdin is
reserved for prompt responses; payload bytes go
via the file path.
:filter FN -- process filter (nil in v0.2; populated in future work)
Return plist (:exit-status N :stdout STR :stderr STR)."
(let* ((input (plist-get keys :input))
(filter (plist-get keys :filter))
(stdout-buf (generate-new-buffer " *sops-stdout*" t))
(stderr-buf (generate-new-buffer " *sops-stderr*" t))
(input-file (when input
(with-file-modes #o600
(make-temp-file "sops-input-"))))
(done nil)
(proc nil)
(stderr-proc nil))
(unwind-protect
(let ((process-environment
(cons "SOPS_DISABLE_VERSION_CHECK=true" process-environment)))
(when input
(let ((coding-system-for-write 'utf-8-unix))
(write-region input nil input-file nil 'silent)))
(setq proc
(make-process
:name "sops"
:buffer stdout-buf
:stderr stderr-buf
:command (cons sops-executable
(if input-file
(append args (list input-file))
args))
:connection-type 'pipe
:filter filter
:sentinel (lambda (_p _event) (setq done t))))
(setq stderr-proc (get-buffer-process stderr-buf))
(set-process-coding-system proc 'utf-8-unix 'utf-8-unix)
(while (and (not done) (process-live-p proc))
(accept-process-output proc 0.1))
(accept-process-output proc 0 nil t)
;; :stderr BUFFER creates a separate pipe process. The final
;; stdout read above does not service it when JUST-THIS-ONE is t.
(when stderr-proc
(while (accept-process-output stderr-proc 0 nil t)))
(list :exit-status (process-exit-status proc)
:stdout (with-current-buffer stdout-buf (buffer-string))
:stderr (with-current-buffer stderr-buf (buffer-string))))
(when (and proc (process-live-p proc))
(delete-process proc))
(when (buffer-live-p stdout-buf) (kill-buffer stdout-buf))
(when (buffer-live-p stderr-buf) (kill-buffer stderr-buf))
(when (and input-file (file-exists-p input-file))
(delete-file input-file)))))