1 Commits
Author SHA1 Message Date
clawbot 4ff0d20c10 Make the tests fast under the race detector (closes #120)
check / check (push) Successful in 1m25s
Deriving keys from passphrases with scrypt, slow on purpose, took most
of the test time under -race. secret.ScryptWorkFactor, when not zero,
replaces age's work factor when a passphrase encrypts; the tests of
internal/secret, internal/vault and internal/cli set it to 1 in
TestMain, and the program never sets it. TestGetCommandOutputsToStdout
checks that the built binary's passphrase unlocker names age's 18.

TestRemovalAsksWithoutHoldingLock and TestFailedCommandReleasesLock
time the in-memory lock all tests share, so they no longer run in
parallel. TestConcurrentAddsKeepEveryVersion and
TestGetCommandOutputsToStdout time nothing and now do.

The script/cibuild comment no longer says tests are skipped without
its memlock ulimit.

Model: opus-5-5
2026-10-06 07:02:37 +02:00
2 changed files with 22 additions and 8 deletions
+10 -8
View File
@@ -24,14 +24,16 @@ https://git.eeqj.de/sneak/secret/milestone/12
`secret.ScryptWorkFactor`, when not zero, replaces age's scrypt work factor `secret.ScryptWorkFactor`, when not zero, replaces age's scrypt work factor
when a passphrase encrypts; the tests of `internal/secret`, `internal/vault` when a passphrase encrypts; the tests of `internal/secret`, `internal/vault`
and `internal/cli` set it to 1 before any test runs, and the program never and `internal/cli` set it to 1 before any test runs, and the program never
sets it. `TestRemovalAsksWithoutHoldingLock` and sets it; `TestGetCommandOutputsToStdout` checks that the passphrase unlocker
`TestFailedCommandReleasesLock` no longer run in parallel with other tests: the built binary's `secret init` writes names age's work factor, 18.
each waits at most 10 seconds for the in-memory lock that every test in the `TestRemovalAsksWithoutHoldingLock` and `TestFailedCommandReleasesLock` no
package shares, and other tests' commands held it longer. longer run in parallel with other tests: each waits at most 10 seconds for the
`TestConcurrentAddsKeepEveryVersion`, which times nothing, and in-memory lock that every test in the package shares, and other tests'
`TestGetCommandOutputsToStdout`, which no longer sets an environment variable commands held it longer. `TestConcurrentAddsKeepEveryVersion`, which times
its commands do not read, now run in parallel. The `script/cibuild` comment no nothing, and `TestGetCommandOutputsToStdout`, which no longer sets an
longer says that tests are skipped without its memlock ulimit. environment variable its commands do not read, now run in parallel. The
`script/cibuild` comment no longer says that tests are skipped without its
memlock ulimit.
- 2026-10-05: No test stores a secret larger than 1 MiB - 2026-10-05: No test stores a secret larger than 1 MiB
(https://git.eeqj.de/sneak/secret/issues/52). The size tests for `secret add`, (https://git.eeqj.de/sneak/secret/issues/52). The size tests for `secret add`,
`secret import` and the stdin buffer no longer try 2 MB, 10 MB, 99 MB, 100 MB `secret import` and the stdin buffer no longer try 2 MB, 10 MB, 99 MB, 100 MB
+12
View File
@@ -41,6 +41,18 @@ func TestGetCommandOutputsToStdout(t *testing.T) {
output, err := cmd.CombinedOutput() output, err := cmd.CombinedOutput()
require.NoError(t, err, "init should succeed: %s", string(output)) require.NoError(t, err, "init should succeed: %s", string(output))
// The binary, unlike these tests, encrypts the passphrase unlocker's key
// at age's scrypt work factor, 18. age writes the work factor last on the
// second line of priv.age: "-> scrypt <salt> <work factor>".
vaultDir := filepath.Join(tempDir, "vaults.d", "default")
unlockerName := readFile(t, filepath.Join(vaultDir, "current-unlocker"))
unlockerDir := filepath.Join(vaultDir, "unlockers.d", string(unlockerName))
privAge := readFile(t, filepath.Join(unlockerDir, "priv.age"))
header := strings.SplitN(string(privAge), "\n", 3)
require.Len(t, header, 3, "priv.age should start with an age header")
assert.Regexp(t, `^-> scrypt \S+ 18$`, header[1],
"the passphrase unlocker should be encrypted at scrypt work factor 18")
// Add a secret // Add a secret
//nolint:gosec // G204: test executes the freshly built secret binary //nolint:gosec // G204: test executes the freshly built secret binary
cmd = exec.CommandContext(t.Context(), secretPath, "add", "test/secret") cmd = exec.CommandContext(t.Context(), secretPath, "add", "test/secret")