1 Commits
Author SHA1 Message Date
clawbot f2fe5c64ee Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Successful in 1m2s
The size tests skip a case whose secret needs more locked memory than
the process can lock, found by locking a buffer of that size: memguard
panics otherwise, and a plain `docker build .` runs under an 8 MiB
RLIMIT_MEMLOCK. script/cibuild, or any process allowed to lock past the
limit, runs every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
2026-10-02 12:05:26 +00:00
2 changed files with 26 additions and 13 deletions
+2 -2
View File
@@ -26,8 +26,8 @@ Bring the repo into policy compliance in one commit:
# Completed Steps # Completed Steps
- 2026-10-02: A plain `docker build .` builds again: the size tests - 2026-10-02: A plain `docker build .` builds again: the size tests
skip a case that needs more locked memory than the limit allows, skip a case that needs more locked memory than the process can
and run every case under `script/cibuild`. The image stamps the lock, and run every case under `script/cibuild`. The image stamps the
`VERSION` build argument, else `git describe --tags --always`, into `VERSION` build argument, else `git describe --tags --always`, into
`Version`, and fails if `.git` is present but yields no version; `Version`, and fails if `.git` is present but yields no version;
`make build` stamps `git describe` too, not a fixed `0.1.0`. `make build` stamps `git describe` too, not a fixed `0.1.0`.
+24 -11
View File
@@ -28,24 +28,37 @@ const testVaultName = "test-vault"
// size, and they are then copied into one more buffer of its size. // size, and they are then copied into one more buffer of its size.
const lockedBytesPerSecretByte = 3 const lockedBytesPerSecretByte = 3
// skipIfLockedMemoryTooLow skips the test when the locked-memory limit // skipIfLockedMemoryTooLow skips the test when this process cannot lock
// (RLIMIT_MEMLOCK) cannot hold a secret of size bytes. memguard panics, // the memory a secret of size bytes needs, found by locking a buffer of
// ending the whole test run, when it cannot lock a buffer, and a plain // that size and releasing it. memguard panics, ending the whole test run,
// `docker build .` runs the tests under an 8 MiB limit. // when it cannot lock a buffer, and a plain `docker build .` runs the
// tests under an 8 MiB locked-memory limit (RLIMIT_MEMLOCK). A process
// allowed to lock past that limit runs every case.
func skipIfLockedMemoryTooLow(t *testing.T, size int) { func skipIfLockedMemoryTooLow(t *testing.T, size int) {
t.Helper() t.Helper()
var limit unix.Rlimit need := lockedBytesPerSecretByte * size
err := unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit) buf, err := unix.Mmap(-1, 0, need,
unix.PROT_READ|unix.PROT_WRITE, unix.MAP_PRIVATE|unix.MAP_ANON)
require.NoError(t, err) require.NoError(t, err)
//nolint:gosec // test sizes are never negative lockErr := unix.Mlock(buf)
need := lockedBytesPerSecretByte * uint64(size)
if limit.Cur < need { // Unmapping the buffer also unlocks it.
err = unix.Munmap(buf)
require.NoError(t, err)
if lockErr != nil {
var limit unix.Rlimit
err = unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit)
require.NoError(t, err)
t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+ t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+
"more than the locked-memory limit (RLIMIT_MEMLOCK) of %d bytes", "which could not be locked under the locked-memory limit "+
size, need, limit.Cur) "(RLIMIT_MEMLOCK) of %d bytes: %v",
size, need, limit.Cur, lockErr)
} }
} }