Give each failure one error value (closes #113)
check / check (push) Failing after 2s

internal/cli drops its copies of vault.ErrSecretNotFound, ErrVaultNotFound,
ErrVersionNotFound and ErrSecretExists and of the secret package's keychain
and Secure Enclave errors, and its second error for an unknown unlocker
type, an invalid mnemonic, a length below 1, an unsupported secret type and
an oversized secret. vault.ErrNilValueBuffer becomes
secret.ErrNilValueBuffer. Every error of secret.ReadPassphrase wraps
ErrPassphraseNotRead. ResolveGPGKeyFingerprint returns ErrGPGKeyNotFound for
a key the keyring lacks. storeInKeychain returns errNilDataBuffer. bip85's
ErrPasswordTooShort and ErrEncodedTooShort go with their unreachable checks,
as does the macOS check in macOS-only code. Tests that matched these
errors' text use errors.Is.

Model: opus-5-5
This commit is contained in:
2026-10-04 22:55:36 +00:00
parent 176095e3d1
commit 3e6ff1d8cc
28 changed files with 271 additions and 162 deletions
+8 -12
View File
@@ -1216,9 +1216,8 @@ func test12bMoveSecret(t *testing.T, testMnemonic string, runSecret func(...stri
// Test error cases
// Try to move non-existent secret
output, err = runSecret("move", "test/nonexistent", "test/destination")
require.Error(t, err, "move non-existent should fail")
assert.Contains(t, output, "not found", "should indicate source not found")
_, err = runSecret("move", "test/nonexistent", "test/destination")
require.ErrorIs(t, err, vault.ErrSecretNotFound, "move non-existent should fail")
// Try to move to existing destination
_, err = runSecretWithStdin("dest-value", map[string]string{
@@ -1226,9 +1225,8 @@ func test12bMoveSecret(t *testing.T, testMnemonic string, runSecret func(...stri
}, "add", "test/existing-dest")
require.NoError(t, err, "add test/existing-dest should succeed")
output, err = runSecret("move", "test/renamed", "test/existing-dest")
require.Error(t, err, "move to existing destination should fail")
assert.Contains(t, output, "already exists", "should indicate destination exists")
_, err = runSecret("move", "test/renamed", "test/existing-dest")
require.ErrorIs(t, err, vault.ErrSecretExists, "move to existing destination should fail")
// Verify the source wasn't removed since move failed
getOutput, err = runSecretWithEnv(map[string]string{
@@ -1933,12 +1931,11 @@ func test23ErrorHandling(t *testing.T, tempDir, secretPath, testMnemonic string,
// Import to non-existent vault with test passphrase
testPassphrase := "test-passphrase-123" // Define testPassphrase locally
output, err := runSecretWithEnv(map[string]string{
_, err = runSecretWithEnv(map[string]string{
secret.EnvMnemonic: testMnemonic,
secret.EnvUnlockPassphrase: testPassphrase,
}, "vault", "import", "nonexistent")
require.Error(t, err, "import to non-existent vault should fail")
assert.Contains(t, output, "does not exist", "should indicate vault doesn't exist")
require.ErrorIs(t, err, vault.ErrVaultNotFound, "import to non-existent vault should fail")
// Get specific version that doesn't exist
_, err = runSecretWithEnv(map[string]string{
@@ -1947,11 +1944,10 @@ func test23ErrorHandling(t *testing.T, tempDir, secretPath, testMnemonic string,
require.ErrorIs(t, err, vault.ErrVersionNotFound, "get non-existent version should fail")
// Promote non-existent version
output, err = runSecretWithEnv(map[string]string{
_, err = runSecretWithEnv(map[string]string{
secret.EnvMnemonic: testMnemonic,
}, "version", "promote", "database/password", "99999999.999")
require.Error(t, err, "promote non-existent version should fail")
assert.Contains(t, output, "not found", "should indicate version not found")
require.ErrorIs(t, err, vault.ErrVersionNotFound, "promote non-existent version should fail")
}
func test24EnvironmentVariables(t *testing.T, tempDir, secretPath, testMnemonic, testPassphrase string) {