Make script/test fail on flaky failures and enable -race (closes #32)
check / check (push) Waiting to run

script/test ended with a verbose rerun whose exit status became the
script's, so a test that failed once and passed on the retry gave a
green build. It now follows the REPO_POLICIES.md pattern: go vet, then
go test -count=1 -timeout 30s -race -cover; on failure a verbose rerun
for the details, then exit 1. -count=1 stays on both go test lines
because the Dockerfile keeps Go's build cache between builds.

The tests that gave the secret binary a minute, and the PGP unlocker
test's 30-second timer, now use 10 seconds, so a hang fails with the
test's own message before the package's 30-second timeout. The README
describes the new run.

Model: opus-5-5
This commit was merged in pull request #53.
This commit is contained in:
2026-10-07 03:22:34 +02:00
parent b109c4e5e1
commit ed6af50ea5
6 changed files with 41 additions and 18 deletions
+17 -9
View File
@@ -32,6 +32,12 @@ const (
// testMnemonic is a standard BIP39 mnemonic used for testing
//nolint:dupword // BIP39 test mnemonic intentionally repeats a word
testMnemonic = "abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about"
// commandWait is how long a test lets the secret binary run before it
// kills it and fails. It stays well under the 30 seconds script/test
// gives the whole package, so a command that hangs fails the test with
// the test's own message instead of Go's timeout panic.
commandWait = 10 * time.Second
)
// errEmptyValue indicates a concurrent reader received an empty secret value.
@@ -2583,7 +2589,7 @@ func TestRemoveWithoutTerminalFailsAtOnce(t *testing.T) {
_ = stdin.Close()
}()
ctx, cancel := context.WithTimeout(t.Context(), time.Minute)
ctx, cancel := context.WithTimeout(t.Context(), commandWait)
defer cancel()
cmd, secretDir := secretRmCommand(ctx, t)
@@ -2602,9 +2608,10 @@ func TestRemoveWithoutTerminalFailsAtOnce(t *testing.T) {
// the answer is read from. pty.Open returns the two ends of a new terminal:
// tty is the end a program uses as its terminal, and ptmx the end the test
// reads what the terminal shows from and types into. Reading ptmx stops at
// the context's deadline, when secret rm is killed too, so a terminal that
// stays open fails the test then instead of hanging it. The deadline works
// only while ptmx stays non-blocking, as pty.Open of the github.com/creack/pty
// the context's deadline, commandWait (10 seconds) after the test starts,
// when secret rm is killed too, so a terminal that stays open fails the test
// then with its own message instead of hanging it. The deadline works only
// while ptmx stays non-blocking, as pty.Open of the github.com/creack/pty
// commit in go.mod leaves it: calling ptmx.Fd() or going back to v1.1.24
// makes the read ignore the deadline, without any error.
@@ -2614,7 +2621,7 @@ func TestRemoveWithoutTerminalFailsAtOnce(t *testing.T) {
func TestRemoveIgnoresTerminalOnStdout(t *testing.T) {
t.Parallel()
ctx, cancel := context.WithTimeout(t.Context(), time.Minute)
ctx, cancel := context.WithTimeout(t.Context(), commandWait)
defer cancel()
cmd, secretDir := secretRmCommand(ctx, t)
@@ -2638,12 +2645,13 @@ func TestRemoveIgnoresTerminalOnStdout(t *testing.T) {
// The read ends once secret rm has exited and so closed the terminal.
shown, err := io.ReadAll(ptmx)
require.NotErrorIs(t, err, os.ErrDeadlineExceeded,
"the terminal was still open a minute after secret rm started: %s",
shown)
"the terminal was still open %s after secret rm started: %s",
commandWait, shown)
err = cmd.Wait()
require.NoError(t, ctx.Err(), "secret rm did not exit within a minute")
require.NoError(t, ctx.Err(), "secret rm did not exit within %s",
commandWait)
require.Error(t, err)
assert.Contains(t, string(shown), "pass --force")
assert.DirExists(t, secretDir)
@@ -2654,7 +2662,7 @@ func TestRemoveIgnoresTerminalOnStdout(t *testing.T) {
func TestRemoveAsksAtTerminalOnStdin(t *testing.T) {
t.Parallel()
ctx, cancel := context.WithTimeout(t.Context(), time.Minute)
ctx, cancel := context.WithTimeout(t.Context(), commandWait)
defer cancel()
cmd, secretDir := secretRmCommand(ctx, t)