Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Successful in 46s
check / check (push) Successful in 46s
The size tests skip a case whose secret needs more locked memory than RLIMIT_MEMLOCK allows: memguard panics otherwise, and a plain `docker build .` runs under an 8 MiB limit. script/cibuild still runs every case. The build stage stamps the VERSION build argument, else `git describe --tags --always`, and fails when .git is present but yields no version. `make build` stamps `git describe` too instead of the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is now the canonical copy. Model: opus-5-5
This commit is contained in:
@@ -17,11 +17,38 @@ import (
|
||||
"github.com/spf13/cobra"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
|
||||
// testVaultName is the vault name used by the size tests.
|
||||
const testVaultName = "test-vault"
|
||||
|
||||
// lockedBytesPerSecretByte bounds the locked memory that storing a secret
|
||||
// holds at once: the buffers it is read into reach up to 1.5 times its
|
||||
// size, and they are then copied into one more buffer of its size.
|
||||
const lockedBytesPerSecretByte = 3
|
||||
|
||||
// skipIfLockedMemoryTooLow skips the test when the locked-memory limit
|
||||
// (RLIMIT_MEMLOCK) cannot hold a secret of size bytes. memguard panics,
|
||||
// ending the whole test run, when it cannot lock a buffer, and a plain
|
||||
// `docker build .` runs the tests under an 8 MiB limit.
|
||||
func skipIfLockedMemoryTooLow(t *testing.T, size int) {
|
||||
t.Helper()
|
||||
|
||||
var limit unix.Rlimit
|
||||
|
||||
err := unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit)
|
||||
require.NoError(t, err)
|
||||
|
||||
//nolint:gosec // test sizes are never negative
|
||||
need := lockedBytesPerSecretByte * uint64(size)
|
||||
if limit.Cur < need {
|
||||
t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+
|
||||
"more than the locked-memory limit (RLIMIT_MEMLOCK) of %d bytes",
|
||||
size, need, limit.Cur)
|
||||
}
|
||||
}
|
||||
|
||||
// newSizeTestVault creates an in-memory vault unlocked with the test
|
||||
// mnemonic and returns the filesystem and vault.
|
||||
//
|
||||
@@ -59,6 +86,7 @@ func newSizeTestVault(t *testing.T) (afero.Fs, *vault.Vault) {
|
||||
// verifies the outcome.
|
||||
func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
||||
t.Helper()
|
||||
skipIfLockedMemoryTooLow(t, size)
|
||||
|
||||
fs, vlt := newSizeTestVault(t)
|
||||
|
||||
@@ -110,6 +138,7 @@ func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
||||
// verifies the outcome.
|
||||
func runImportSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
||||
t.Helper()
|
||||
skipIfLockedMemoryTooLow(t, size)
|
||||
|
||||
fs, vlt := newSizeTestVault(t)
|
||||
|
||||
@@ -300,6 +329,8 @@ func TestAddSecretBufferGrowth(t *testing.T) {
|
||||
|
||||
for _, size := range sizes {
|
||||
t.Run(fmt.Sprintf("size_%d", size), func(t *testing.T) {
|
||||
skipIfLockedMemoryTooLow(t, size)
|
||||
|
||||
fs, vlt := newSizeTestVault(t)
|
||||
|
||||
// Create test data of exactly the specified size
|
||||
|
||||
Reference in New Issue
Block a user