fnox 1.36.0 makes the per-prompt shell hook much faster, batches fnox reencrypt by provider, fixes the YubiKey provider, which timed out on every challenge, and ships a fnox agent skill with each release.
Added
- fnox agent skill (#910) by @jdx. A new
fnoxskill teaches coding agents how to set up providers and profiles, inject secrets into commands, and diagnose authentication or resolution failures without printing secret values. The release Packslip now includes the skill, so you can install it with mise (you need a mise version with Packslip skill support):The generated skill links only work on your machine, so keep them out of version control.mise use packslip:github.com/jdx/fnox mise skills sync --dir .agents/skills
Fixed
fnox reencryptbatches encryption by provider (#880) by @davdroman.reencryptused to encrypt each secret on its own, even when the provider supports batching. For age secrets protected by Touch ID, this meant one unlock per value on an uncachedexec. fnox now makes one batch encryption call per provider. You can also use this to merge secrets that were encrypted separately, such as new values added withfnox set:Secrets you don't select stay unchanged, source files and profiles are kept as they were, and if a provider batch fails, fnox saves none of that batch's changes.fnox reencrypt --provider age
- YubiKey provider no longer times out (#905) by @mufasa71. The
yubikeyprovider always failed with "Timed out waiting for YubiKey response" and the key never blinked for touch. The cause was a wrong checksum on the HMAC-SHA1 challenge, which made the key drop the request. The checksum now matches Yubico's implementations, andfnox set/fnox getwork with touch-required slots.
Performance
- Faster per-prompt shell hook (#907) by @jdx. When nothing has changed,
fnox hook-env -s <shell>(run before every prompt byfnox activate) now exits before the full CLI starts up. This roughly halves wall time (3.7 ms to 1.9 ms in benchmarks) and cuts CPU time by about 4x. Config changes still trigger a full reload. SettingFNOX_SHELL_OUTPUT=debugorRUST_LOGmakes the hook take the normal path, so it still explains why it exited. - Faster startup for Linux GNU release binaries (#908) by @jdx. The official Linux GNU release binaries are now linked as non-PIE executables, which saves about 1 ms on every command. Together with #907, an unchanged shell hook drops from about 3.7 ms to 0.78 ms. The tradeoff: ASLR (address randomization) no longer covers fnox's own code and data, though the heap, stack and shared libraries are still randomized. musl, macOS and Windows builds,
cargo install, and other source builds are unchanged.
New Contributors
Full Changelog: v1.35.3...v1.36.0
💚 Sponsor fnox
fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.