Type-check and lint the macOS build from Linux (closes #50)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
script/lint-darwin (make lint-darwin; run by script/check, and its commands by the Dockerfile lint stage) runs go vet and golangci-lint with GOOS=darwin and cgo off. Compiling cgo for macOS needs Apple's SDK, so the three functions that call go-keychain, which is cgo there, move to keychainunlocker_cgo.go; a macOS build without cgo gets keychainunlocker_nocgo.go and the macse stub, whose errors name the missing macOS build with cgo. The rest of the keychain unlocker and its plain-Go tests are now checked; their findings are fixed without changing behaviour, and lines over 88 columns in the unchecked files are wrapped. Model: opus-5-5
This commit was merged in pull request #96.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
//go:build darwin
|
||||
// +build darwin
|
||||
|
||||
//nolint:testpackage // white-box test of unexported Secure Enclave helpers
|
||||
package secret
|
||||
|
||||
import (
|
||||
@@ -13,12 +13,14 @@ import (
|
||||
)
|
||||
|
||||
func TestNewSecureEnclaveUnlocker(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
fs := afero.NewMemMapFs()
|
||||
dir := "/tmp/test-se-unlocker"
|
||||
metadata := UnlockerMetadata{
|
||||
Type: "secure-enclave",
|
||||
Type: seUnlockerType,
|
||||
CreatedAt: time.Date(2026, 1, 15, 10, 30, 0, 0, time.UTC),
|
||||
Flags: []string{"secure-enclave", "macos"},
|
||||
Flags: []string{seUnlockerType, "macos"},
|
||||
}
|
||||
|
||||
unlocker := NewSecureEnclaveUnlocker(fs, dir, metadata)
|
||||
@@ -35,9 +37,11 @@ func TestNewSecureEnclaveUnlocker(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestSecureEnclaveUnlockerImplementsInterface(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
fs := afero.NewMemMapFs()
|
||||
metadata := UnlockerMetadata{
|
||||
Type: "secure-enclave",
|
||||
Type: seUnlockerType,
|
||||
CreatedAt: time.Now().UTC(),
|
||||
}
|
||||
|
||||
@@ -48,9 +52,11 @@ func TestSecureEnclaveUnlockerImplementsInterface(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestSecureEnclaveUnlockerGetIDFormat(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
fs := afero.NewMemMapFs()
|
||||
metadata := UnlockerMetadata{
|
||||
Type: "secure-enclave",
|
||||
Type: seUnlockerType,
|
||||
CreatedAt: time.Date(2026, 3, 10, 14, 30, 0, 0, time.UTC),
|
||||
}
|
||||
|
||||
@@ -63,6 +69,8 @@ func TestSecureEnclaveUnlockerGetIDFormat(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestGenerateSEKeyLabel(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
label, err := generateSEKeyLabel("test-vault")
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -72,6 +80,8 @@ func TestGenerateSEKeyLabel(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestSecureEnclaveUnlockerGetIdentityMissingFile(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
fs := afero.NewMemMapFs()
|
||||
dir := "/tmp/test-se-unlocker-missing"
|
||||
|
||||
@@ -84,10 +94,12 @@ func TestSecureEnclaveUnlockerGetIdentityMissingFile(t *testing.T) {
|
||||
"seKeyLabel": "berlin.sneak.app.secret.se.test",
|
||||
"seKeyHash": "abc123"
|
||||
}`
|
||||
require.NoError(t, afero.WriteFile(fs, dir+"/unlocker-metadata.json", []byte(metadataJSON), FilePerms))
|
||||
require.NoError(t, afero.WriteFile(
|
||||
fs, dir+"/unlocker-metadata.json", []byte(metadataJSON), FilePerms,
|
||||
))
|
||||
|
||||
metadata := UnlockerMetadata{
|
||||
Type: "secure-enclave",
|
||||
Type: seUnlockerType,
|
||||
CreatedAt: time.Date(2026, 1, 15, 10, 30, 0, 0, time.UTC),
|
||||
}
|
||||
|
||||
@@ -96,6 +108,6 @@ func TestSecureEnclaveUnlockerGetIdentityMissingFile(t *testing.T) {
|
||||
// GetIdentity should fail because the encrypted longterm key file is missing
|
||||
identity, err := unlocker.GetIdentity()
|
||||
assert.Nil(t, identity)
|
||||
assert.Error(t, err)
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), "failed to read SE-encrypted long-term key")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user