Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Successful in 46s

The size tests skip a case whose secret needs more locked memory than
RLIMIT_MEMLOCK allows: memguard panics otherwise, and a plain
`docker build .` runs under an 8 MiB limit. script/cibuild still runs
every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:26:08 +00:00
parent 41cea400a7
commit 41078f1997
8 changed files with 75 additions and 7 deletions
+31
View File
@@ -17,11 +17,38 @@ import (
"github.com/spf13/cobra"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"golang.org/x/sys/unix"
)
// testVaultName is the vault name used by the size tests.
const testVaultName = "test-vault"
// lockedBytesPerSecretByte bounds the locked memory that storing a secret
// holds at once: the buffers it is read into reach up to 1.5 times its
// size, and they are then copied into one more buffer of its size.
const lockedBytesPerSecretByte = 3
// skipIfLockedMemoryTooLow skips the test when the locked-memory limit
// (RLIMIT_MEMLOCK) cannot hold a secret of size bytes. memguard panics,
// ending the whole test run, when it cannot lock a buffer, and a plain
// `docker build .` runs the tests under an 8 MiB limit.
func skipIfLockedMemoryTooLow(t *testing.T, size int) {
t.Helper()
var limit unix.Rlimit
err := unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit)
require.NoError(t, err)
//nolint:gosec // test sizes are never negative
need := lockedBytesPerSecretByte * uint64(size)
if limit.Cur < need {
t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+
"more than the locked-memory limit (RLIMIT_MEMLOCK) of %d bytes",
size, need, limit.Cur)
}
}
// newSizeTestVault creates an in-memory vault unlocked with the test
// mnemonic and returns the filesystem and vault.
//
@@ -59,6 +86,7 @@ func newSizeTestVault(t *testing.T) (afero.Fs, *vault.Vault) {
// verifies the outcome.
func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
t.Helper()
skipIfLockedMemoryTooLow(t, size)
fs, vlt := newSizeTestVault(t)
@@ -110,6 +138,7 @@ func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
// verifies the outcome.
func runImportSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
t.Helper()
skipIfLockedMemoryTooLow(t, size)
fs, vlt := newSizeTestVault(t)
@@ -300,6 +329,8 @@ func TestAddSecretBufferGrowth(t *testing.T) {
for _, size := range sizes {
t.Run(fmt.Sprintf("size_%d", size), func(t *testing.T) {
skipIfLockedMemoryTooLow(t, size)
fs, vlt := newSizeTestVault(t)
// Create test data of exactly the specified size