Skip to content

Repository files navigation

keylock

Run a command behind an input lock, so a stray key can't interrupt it.

A multi-hour migration can be killed by one accidental Ctrl+C — or, if the script reacts to single keys, by any key at all. keylock runs the command in its own pseudo-terminal and sits in between: while the session is locked, every key, Ctrl+C, mouse click and paste is dropped. Output always passes through. It works in any terminal on macOS and Linux, including inside tmux, Herdr and over SSH.

Install

With Homebrew (macOS and Linux):

brew install bayoudhi/tap/keylock

With the install script (prebuilt binary for macOS or Linux):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/bayoudhi/keylock/releases/latest/download/keylock-cli-installer.sh | sh

With Cargo (the crate is keylock-cli; the command is keylock):

cargo install keylock-cli

Use

keylock run --locked -- ./migrate.sh     # start locked
keylock run -- ./migrate.sh              # start unlocked, lock later
To Do
Lock from inside the terminal Ctrl+] then l
Lock from another shell keylock on migrate.sh
Unlock from inside the terminal type unlock (no Enter needed)
Unlock from another shell keylock off migrate.sh
See sessions keylock ls
Check one session keylock status migrate.sh
Lock or unlock the session in a Herdr pane keylock on --pane w1:p3 / keylock off --pane w1:p3

While locked, the terminal title starts with 🔒, and typing rings the bell and briefly shows how to unlock.

Options for run:

  • --locked — start locked.
  • --name NAME — session name (default: the command's file name; -2, -3, … is added if the name is taken).
  • --phrase PHRASE — unlock phrase (default unlock, or $KEYLOCK_PHRASE).
  • --no-phrase — only keylock off can unlock.
  • --no-hotkey — pass Ctrl+] through to the command untouched.

To send a literal Ctrl+] to the command, press it twice.

The command sees KEYLOCK_NAME in its environment. keylock exits with the command's exit code (128 + signal number if it was killed by a signal).

Limits

  • The phrase guards against accidents, not people: it is visible in ps when passed with --phrase.
  • keylock can't stop the terminal, tab or pane itself from being closed.
  • It only protects commands started through it.
  • While locked, replies from the terminal are dropped too, so a program that queries the terminal (for example for the cursor position) gets no answer.

Herdr

Inside Herdr, keylock on/off/status --pane <pane_id> finds the session running in a pane (it still works after the pane is moved).

The keylock Herdr plugin adds keylock: lock pane and keylock: unlock pane to the command palette for the focused pane, locking or unlocking the session running there and reporting the result as a Herdr notification. The pane itself shows keylock's own 🔒 terminal title.

herdr plugin install bayoudhi/keylock/herdr-plugin

See herdr-plugin/README.md for keybindings.

Releasing

Bump version in Cargo.toml, commit, then tag and push:

git tag -a vX.Y.Z -m "keylock vX.Y.Z" && git push origin master vX.Y.Z

The Release workflow (dist) builds binaries for macOS and Linux (arm64 and x86_64), publishes a GitHub Release with an install script, pushes the formula to bayoudhi/homebrew-tap, and publishes the crate to crates.io. It needs two repository secrets: HOMEBREW_TAP_TOKEN and CARGO_REGISTRY_TOKEN.

License

MIT

About

Run a command behind an input lock so stray keys can't interrupt it

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages