Check errors by identity, not by message text, in tests (closes #49)
check / check (push) Failing after 4s

Tests that asserted a failure by a fragment of its message now use
errors.Is: a refactor returning the wrong error, or wrapping with %v
instead of %w, now fails them. New tests return each exported error of
internal/vault and pkg/bip85 that no test returned, and check wrapped
causes (os.ErrNotExist, ErrMnemonicMismatch through GetSecret,
ErrInvalidPathComponent through DeriveBIP85Entropy). The 999-versions
test moves into package secret to name its unexported error. Checks of
errors no test can name keep their text; they are listed on the issue.

Model: opus-5-5
This commit is contained in:
2026-10-04 20:44:24 +00:00
parent 2adc588ace
commit 79bc021412
19 changed files with 401 additions and 256 deletions
+5 -7
View File
@@ -320,10 +320,10 @@ func testVersionSerialLimits(
err = fs.MkdirAll(filepath.Join(secretDir, versionName), 0o755)
require.NoError(t, err)
// Should fail to create 1000th version
// Should fail to create 1000th version. The error is unexported in
// package secret, whose own test checks that it is the one returned.
_, err = secret.GenerateVersionName(fs, filepath.Dir(secretDir))
require.Error(t, err)
assert.Contains(t, err.Error(), "exceeded maximum versions per day")
}
func testVersionErrorCases(t *testing.T, vault *Vault, secretName string) {
@@ -331,20 +331,18 @@ func testVersionErrorCases(t *testing.T, vault *Vault, secretName string) {
// Try to get non-existent version
_, err := vault.GetSecretVersion(secretName, "99991231.999")
require.Error(t, err)
assert.Contains(t, err.Error(), "not found")
require.ErrorIs(t, err, ErrVersionNotFound)
// Try to get version of non-existent secret
_, err = vault.GetSecretVersion("nonexistent/secret", "")
require.Error(t, err)
require.ErrorIs(t, err, ErrSecretNotFound)
// Try to add secret without force when it exists
failBuffer := memguard.NewBufferFromBytes([]byte("should-fail"))
defer failBuffer.Destroy()
err = vault.AddSecret(secretName, failBuffer, false)
require.Error(t, err)
assert.Contains(t, err.Error(), "already exists")
require.ErrorIs(t, err, ErrSecretExists)
}
// TestVersionConcurrency tests concurrent version operations