Relationships
#1768 vault read-secret appends a newline to piped output
Opened by psftw · 8/21/2026· Shipped 8/22/2026
swamp vault read-secret terminates its plain output with a newline even when
stdout is not a TTY. Piped or redirected output is therefore <value>\n, not
the secret bytes — anything that consumes the stream as-is stores a corrupted
secret. Expected: when stdout is not a TTY, output is exactly the stored bytes.
Repro (swamp 20260820.072114.0, fresh repo, local_encryption vault):
$ printf 'abc' | swamp vault put v probe # store exactly 3 bytes
$ swamp vault read-secret v probe --yes | xxd
00000000: 6162 630a abc.Expected: 3 bytes (abc). Actual: 4 bytes (abc\n).
Scope: vault put strips one trailing newline from stdin, so swamp-to-swamp
round-trips self-correct, and --json output is unaffected. The corruption
hits external consumers of the piped output — seeding another secret store
(e.g. systemd-creds encrypt), writing a key file, or any pipeline that
treats the stream as exact bytes.
Ask: omit the newline when stdout is not a TTY, or add a --raw flag.
Shipped
Click a lifecycle step above to view its details.