Make the tests fast under the race detector (closes #120)
check / check (push) Successful in 1m25s
check / check (push) Successful in 1m25s
Deriving keys from passphrases with scrypt, slow on purpose, took most of the test time under -race. secret.ScryptWorkFactor, when not zero, replaces age's work factor when a passphrase encrypts; the tests of internal/secret, internal/vault and internal/cli set it to 1 in TestMain, and the program never sets it. TestGetCommandOutputsToStdout checks that the built binary's passphrase unlocker names age's 18. TestRemovalAsksWithoutHoldingLock and TestFailedCommandReleasesLock time the in-memory lock all tests share, so they no longer run in parallel. TestConcurrentAddsKeepEveryVersion and TestGetCommandOutputsToStdout time nothing and now do. The script/cibuild comment no longer says tests are skipped without its memlock ulimit. Model: opus-5-5
This commit was merged in pull request #123.
This commit is contained in:
@@ -15,11 +15,11 @@ import (
|
||||
// TestGetCommandOutputsToStdout tests that 'secret get' outputs the secret
|
||||
// value to stdout, not stderr
|
||||
func TestGetCommandOutputsToStdout(t *testing.T) {
|
||||
// Create a temporary directory for our vault
|
||||
tempDir := t.TempDir()
|
||||
t.Parallel()
|
||||
|
||||
// Set environment variables for the test
|
||||
t.Setenv(secret.EnvStateDir, tempDir)
|
||||
// Create a temporary directory for our vault; each command is given it
|
||||
// in its environment
|
||||
tempDir := t.TempDir()
|
||||
|
||||
// Find the secret binary path
|
||||
wd, err := filepath.Abs("../..")
|
||||
@@ -41,6 +41,18 @@ func TestGetCommandOutputsToStdout(t *testing.T) {
|
||||
output, err := cmd.CombinedOutput()
|
||||
require.NoError(t, err, "init should succeed: %s", string(output))
|
||||
|
||||
// The binary, unlike these tests, encrypts the passphrase unlocker's key
|
||||
// at age's scrypt work factor, 18. age writes the work factor last on the
|
||||
// second line of priv.age: "-> scrypt <salt> <work factor>".
|
||||
vaultDir := filepath.Join(tempDir, "vaults.d", "default")
|
||||
unlockerName := readFile(t, filepath.Join(vaultDir, "current-unlocker"))
|
||||
unlockerDir := filepath.Join(vaultDir, "unlockers.d", string(unlockerName))
|
||||
privAge := readFile(t, filepath.Join(unlockerDir, "priv.age"))
|
||||
header := strings.SplitN(string(privAge), "\n", 3)
|
||||
require.Len(t, header, 3, "priv.age should start with an age header")
|
||||
assert.Regexp(t, `^-> scrypt \S+ 18$`, header[1],
|
||||
"the passphrase unlocker should be encrypted at scrypt work factor 18")
|
||||
|
||||
// Add a secret
|
||||
//nolint:gosec // G204: test executes the freshly built secret binary
|
||||
cmd = exec.CommandContext(t.Context(), secretPath, "add", "test/secret")
|
||||
|
||||
Reference in New Issue
Block a user