Check errors by identity, not by message text, in tests (closes #49)
check / check (push) Failing after 1s

Tests that asserted a failure by a fragment of its message now use
errors.Is: a refactor returning the wrong error, or wrapping with %v
instead of %w, now fails them. New tests return each exported error of
internal/vault and pkg/bip85 that no test returned, and check wrapped
causes (os.ErrNotExist, ErrMnemonicMismatch through GetSecret,
ErrInvalidPathComponent through DeriveBIP85Entropy). The 999-versions
test moves into package secret to name its unexported error. Checks of
errors no test can name keep their text; they are listed on the issue.

Model: opus-5-5
This commit was merged in pull request #112.
This commit is contained in:
2026-10-04 23:25:06 +02:00
parent 2adc588ace
commit 176095e3d1
19 changed files with 401 additions and 256 deletions
+8 -2
View File
@@ -4,6 +4,8 @@
package secret
import (
"os"
"path/filepath"
"testing"
"time"
@@ -106,6 +108,10 @@ func TestSecureEnclaveUnlockerGetIdentityMissingFile(t *testing.T) {
// GetIdentity should fail because the encrypted longterm key file is missing
identity, err := unlocker.GetIdentity()
assert.Nil(t, identity)
require.Error(t, err)
assert.Contains(t, err.Error(), "failed to read SE-encrypted long-term key")
var cause *os.PathError
require.ErrorAs(t, err, &cause)
require.ErrorIs(t, err, os.ErrNotExist)
assert.Equal(t, filepath.Join(dir, seLongtermFilename), cause.Path)
}