Compare commits
1
Commits
666e2438b0
..
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4ff0d20c10 |
@@ -24,14 +24,16 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
|||||||
`secret.ScryptWorkFactor`, when not zero, replaces age's scrypt work factor
|
`secret.ScryptWorkFactor`, when not zero, replaces age's scrypt work factor
|
||||||
when a passphrase encrypts; the tests of `internal/secret`, `internal/vault`
|
when a passphrase encrypts; the tests of `internal/secret`, `internal/vault`
|
||||||
and `internal/cli` set it to 1 before any test runs, and the program never
|
and `internal/cli` set it to 1 before any test runs, and the program never
|
||||||
sets it. `TestRemovalAsksWithoutHoldingLock` and
|
sets it; `TestGetCommandOutputsToStdout` checks that the passphrase unlocker
|
||||||
`TestFailedCommandReleasesLock` no longer run in parallel with other tests:
|
the built binary's `secret init` writes names age's work factor, 18.
|
||||||
each waits at most 10 seconds for the in-memory lock that every test in the
|
`TestRemovalAsksWithoutHoldingLock` and `TestFailedCommandReleasesLock` no
|
||||||
package shares, and other tests' commands held it longer.
|
longer run in parallel with other tests: each waits at most 10 seconds for the
|
||||||
`TestConcurrentAddsKeepEveryVersion`, which times nothing, and
|
in-memory lock that every test in the package shares, and other tests'
|
||||||
`TestGetCommandOutputsToStdout`, which no longer sets an environment variable
|
commands held it longer. `TestConcurrentAddsKeepEveryVersion`, which times
|
||||||
its commands do not read, now run in parallel. The `script/cibuild` comment no
|
nothing, and `TestGetCommandOutputsToStdout`, which no longer sets an
|
||||||
longer says that tests are skipped without its memlock ulimit.
|
environment variable its commands do not read, now run in parallel. The
|
||||||
|
`script/cibuild` comment no longer says that tests are skipped without its
|
||||||
|
memlock ulimit.
|
||||||
- 2026-10-05: No test stores a secret larger than 1 MiB
|
- 2026-10-05: No test stores a secret larger than 1 MiB
|
||||||
(https://git.eeqj.de/sneak/secret/issues/52). The size tests for `secret add`,
|
(https://git.eeqj.de/sneak/secret/issues/52). The size tests for `secret add`,
|
||||||
`secret import` and the stdin buffer no longer try 2 MB, 10 MB, 99 MB, 100 MB
|
`secret import` and the stdin buffer no longer try 2 MB, 10 MB, 99 MB, 100 MB
|
||||||
|
|||||||
@@ -41,6 +41,18 @@ func TestGetCommandOutputsToStdout(t *testing.T) {
|
|||||||
output, err := cmd.CombinedOutput()
|
output, err := cmd.CombinedOutput()
|
||||||
require.NoError(t, err, "init should succeed: %s", string(output))
|
require.NoError(t, err, "init should succeed: %s", string(output))
|
||||||
|
|
||||||
|
// The binary, unlike these tests, encrypts the passphrase unlocker's key
|
||||||
|
// at age's scrypt work factor, 18. age writes the work factor last on the
|
||||||
|
// second line of priv.age: "-> scrypt <salt> <work factor>".
|
||||||
|
vaultDir := filepath.Join(tempDir, "vaults.d", "default")
|
||||||
|
unlockerName := readFile(t, filepath.Join(vaultDir, "current-unlocker"))
|
||||||
|
unlockerDir := filepath.Join(vaultDir, "unlockers.d", string(unlockerName))
|
||||||
|
privAge := readFile(t, filepath.Join(unlockerDir, "priv.age"))
|
||||||
|
header := strings.SplitN(string(privAge), "\n", 3)
|
||||||
|
require.Len(t, header, 3, "priv.age should start with an age header")
|
||||||
|
assert.Regexp(t, `^-> scrypt \S+ 18$`, header[1],
|
||||||
|
"the passphrase unlocker should be encrypted at scrypt work factor 18")
|
||||||
|
|
||||||
// Add a secret
|
// Add a secret
|
||||||
//nolint:gosec // G204: test executes the freshly built secret binary
|
//nolint:gosec // G204: test executes the freshly built secret binary
|
||||||
cmd = exec.CommandContext(t.Context(), secretPath, "add", "test/secret")
|
cmd = exec.CommandContext(t.Context(), secretPath, "add", "test/secret")
|
||||||
|
|||||||
Reference in New Issue
Block a user