Check errors by identity, not by message text, in tests (closes #49)
check / check (push) Failing after 3s

Tests that asserted a failure by a fragment of its message now use
errors.Is: a refactor returning the wrong error, or wrapping with %v
instead of %w, now fails them. New tests return each exported error of
internal/vault and pkg/bip85 that no test returned, and check wrapped
causes (os.ErrNotExist, ErrMnemonicMismatch through GetSecret,
ErrInvalidPathComponent through DeriveBIP85Entropy). The 999-versions
test moves into package secret to name its unexported error. Checks of
errors no test can name keep their text; they are listed on the issue.

Model: opus-5-5
This commit is contained in:
2026-10-04 20:04:59 +00:00
parent 2adc588ace
commit 4a6e30f9bf
18 changed files with 366 additions and 241 deletions
+3 -2
View File
@@ -1,6 +1,7 @@
package vault_test
import (
"os"
"path/filepath"
"testing"
@@ -36,8 +37,8 @@ func TestAddSecretFailsWithMissingPublicKey(t *testing.T) {
defer value.Destroy()
err := vlt.AddSecret(testSecretName, value, false)
require.Error(t, err, "AddSecret should fail when public key is missing")
assert.Contains(t, err.Error(), "failed to read long-term public key")
require.ErrorIs(t, err, os.ErrNotExist,
"AddSecret should fail when public key is missing")
// Verify that the secret directory was NOT created
secretDir := filepath.Join(vaultDir, "secrets.d", testSecretName)