@@ -353,9 +353,9 @@ func TestRemovalWithoutTerminalFailsAtOnce(t *testing.T) {
|
||||
// for its answer, another command can take the state directory lock and
|
||||
// change the secret, and that the removal then removes nothing, since the
|
||||
// secret is no longer what the question named.
|
||||
//
|
||||
//nolint:paralleltest // times commands against the in-memory lock all tests share
|
||||
func TestRemovalAsksWithoutHoldingLock(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
r := newRemoval(t, "rm")
|
||||
|
||||
answers, answerWriter := io.Pipe()
|
||||
|
||||
@@ -52,8 +52,12 @@ func runSecretWithStdin(stdin string, env map[string]string, args ...string) (st
|
||||
return cli.ExecuteCommandInProcess(args, stdin, env)
|
||||
}
|
||||
|
||||
// TestMain runs before all tests and ensures the binary is built
|
||||
// TestMain runs before all tests and ensures the binary is built. It also
|
||||
// makes passphrase encryption in the tests cheap (see
|
||||
// secret.ScryptWorkFactor); the binary keeps age's work factor.
|
||||
func TestMain(m *testing.M) {
|
||||
secret.ScryptWorkFactor = 1
|
||||
|
||||
// Get the current working directory
|
||||
wd, err := os.Getwd()
|
||||
if err != nil {
|
||||
|
||||
@@ -235,9 +235,9 @@ func TestEncryptPipedIntoAdd(t *testing.T) {
|
||||
|
||||
// TestFailedCommandReleasesLock checks that a command failing after it
|
||||
// took the state directory lock leaves the lock free for the next command.
|
||||
//
|
||||
//nolint:paralleltest // times commands against the in-memory lock all tests share
|
||||
func TestFailedCommandReleasesLock(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
fs := afero.NewMemMapFs()
|
||||
cli := NewCLIInstanceWithStateDir(fs, testStateDir)
|
||||
|
||||
|
||||
@@ -28,6 +28,17 @@ var (
|
||||
// terminal to read the mnemonic from, reading it failed, or it was empty.
|
||||
var ErrMnemonicNotRead = errors.New("failed to read mnemonic")
|
||||
|
||||
// ScryptWorkFactor is, when not zero, the scrypt work factor that
|
||||
// EncryptWithPassphrase uses instead of age's, 18: log2 of scrypt's cost
|
||||
// parameter N. Deriving a key with age's takes about a second and 256 MiB, on
|
||||
// purpose, since so does every guess at the passphrase. Only tests set it,
|
||||
// lower, before any test runs, so that the passphrase unlockers they create
|
||||
// cost nothing; the program leaves it zero. Decryption takes the work factor
|
||||
// from the encrypted data, so it needs no setting.
|
||||
//
|
||||
//nolint:gochecknoglobals // set by the tests of the packages that use this one
|
||||
var ScryptWorkFactor int
|
||||
|
||||
// EncryptToRecipient encrypts data to a recipient using age
|
||||
// The data parameter should be a LockedBuffer for secure memory handling
|
||||
func EncryptToRecipient(
|
||||
@@ -142,6 +153,10 @@ func EncryptWithPassphrase(
|
||||
return nil, fmt.Errorf("failed to create scrypt recipient: %w", err)
|
||||
}
|
||||
|
||||
if ScryptWorkFactor != 0 {
|
||||
recipient.SetWorkFactor(ScryptWorkFactor)
|
||||
}
|
||||
|
||||
return EncryptToRecipient(data, recipient)
|
||||
}
|
||||
|
||||
|
||||
@@ -25,6 +25,14 @@ var (
|
||||
errNotImplementedInMock = errors.New("not implemented in mock")
|
||||
)
|
||||
|
||||
// TestMain makes passphrase encryption in the tests cheap; see
|
||||
// ScryptWorkFactor.
|
||||
func TestMain(m *testing.M) {
|
||||
ScryptWorkFactor = 1
|
||||
|
||||
os.Exit(m.Run())
|
||||
}
|
||||
|
||||
// MockVault is a test implementation of the VaultInterface
|
||||
type MockVault struct {
|
||||
name string
|
||||
|
||||
@@ -3,6 +3,7 @@ package vault_test
|
||||
import (
|
||||
"bytes"
|
||||
"errors"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"slices"
|
||||
"testing"
|
||||
@@ -28,6 +29,14 @@ const (
|
||||
testPassphrase = "test-passphrase"
|
||||
)
|
||||
|
||||
// TestMain makes passphrase encryption in the tests cheap; see
|
||||
// secret.ScryptWorkFactor.
|
||||
func TestMain(m *testing.M) {
|
||||
secret.ScryptWorkFactor = 1
|
||||
|
||||
os.Exit(m.Run())
|
||||
}
|
||||
|
||||
// testMnemonicBuffer returns testMnemonic in a locked buffer that is
|
||||
// destroyed when the test ends.
|
||||
func testMnemonicBuffer(t *testing.T) *memguard.LockedBuffer {
|
||||
|
||||
Reference in New Issue
Block a user