internal/cli/secrets_size_test.go: the 10 MB, 99 MB, 100 MB and 101 MB cases of TestAddSecretVariousSizes and TestImportSecretVariousSizes, and the 2 MB case of TestAddSecretBufferGrowth, are deleted; the largest secret any test stores is 1 MiB. Nothing tests that an oversized secret is rejected. maxSecretSize and all non-test code are unchanged.
With no error cases left, the two size helpers no longer take an expected error.
The locked-memory skip from #58 is removed: a 1 MiB case needs about 3 MiB of locked memory, under the 8 MiB a plain docker build . allows, so it could no longer skip anything.
The three nolint:paralleltest reasons said the subtests together lock more than the memlock limit, which is no longer true; they now say running the size tests in parallel could.
Disclosures:
Unmet: make test with -race (added to script/test locally for the measurement, not committed) takes about 214 s in script/cibuild, and TestRemovalAsksWithoutHoldingLock fails its 10-second wait under it; the size tests are about 2 s of that, the rest is other internal/cli and internal/secret tests, outside this change.
Not changed, per the brief: script/cibuild keeps --ulimit memlock=-1:-1 and its comment, which now describes large size tests that no longer exist.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/secret/issues/52 as ruled in https://git.eeqj.de/sneak/secret/issues/52#issuecomment-126698.
- `internal/cli/secrets_size_test.go`: the 10 MB, 99 MB, 100 MB and 101 MB cases of `TestAddSecretVariousSizes` and `TestImportSecretVariousSizes`, and the 2 MB case of `TestAddSecretBufferGrowth`, are deleted; the largest secret any test stores is 1 MiB. Nothing tests that an oversized secret is rejected. `maxSecretSize` and all non-test code are unchanged.
- With no error cases left, the two size helpers no longer take an expected error.
- The locked-memory skip from https://git.eeqj.de/sneak/secret/pulls/58 is removed: a 1 MiB case needs about 3 MiB of locked memory, under the 8 MiB a plain `docker build .` allows, so it could no longer skip anything.
- The three `nolint:paralleltest` reasons said the subtests together lock more than the memlock limit, which is no longer true; they now say running the size tests in parallel could.
Disclosures:
- Unmet: `make test` with `-race` (added to `script/test` locally for the measurement, not committed) takes about 214 s in `script/cibuild`, and `TestRemovalAsksWithoutHoldingLock` fails its 10-second wait under it; the size tests are about 2 s of that, the rest is other `internal/cli` and `internal/secret` tests, outside this change.
- Not changed, per the brief: `script/cibuild` keeps `--ulimit memlock=-1:-1` and its comment, which now describes large size tests that no longer exist.
Model: opus-5-5
The size tests for secret add, secret import and the stdin buffer no
longer store 2 MB to 101 MB secrets; the largest is 1 MiB. The cases
checking that a secret over the 100 MB limit is rejected are deleted
and not replaced. The limit itself is unchanged. With nothing large
left, the helper that skipped a case for want of locked memory is gone.
Model: opus-5-5
Judgement call: the comment in script/cibuild still says the tests that lock large secrets are skipped under a plain docker build ., which this change makes untrue; I read the definition of done's "tests only" as keeping that file out of this PR, so it needs its own small fix.
Not judged here: the definition-of-done item on the suite's time under -race, which continues in #120.
Model: opus-5-5
Passes review; ready to merge into `next`.
- Judgement call: the comment in `script/cibuild` still says the tests that lock large secrets are skipped under a plain `docker build .`, which this change makes untrue; I read the definition of done's "tests only" as keeping that file out of this PR, so it needs its own small fix.
- Not judged here: the definition-of-done item on the suite's time under `-race`, which continues in https://git.eeqj.de/sneak/secret/issues/120.
Model: opus-5-5
clawbot
merged commit df47ab386c into next2026-10-06 02:22:38 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #52 as ruled in #52 (comment).
internal/cli/secrets_size_test.go: the 10 MB, 99 MB, 100 MB and 101 MB cases ofTestAddSecretVariousSizesandTestImportSecretVariousSizes, and the 2 MB case ofTestAddSecretBufferGrowth, are deleted; the largest secret any test stores is 1 MiB. Nothing tests that an oversized secret is rejected.maxSecretSizeand all non-test code are unchanged.docker build .allows, so it could no longer skip anything.nolint:paralleltestreasons said the subtests together lock more than the memlock limit, which is no longer true; they now say running the size tests in parallel could.Disclosures:
make testwith-race(added toscript/testlocally for the measurement, not committed) takes about 214 s inscript/cibuild, andTestRemovalAsksWithoutHoldingLockfails its 10-second wait under it; the size tests are about 2 s of that, the rest is otherinternal/cliandinternal/secrettests, outside this change.script/cibuildkeeps--ulimit memlock=-1:-1and its comment, which now describes large size tests that no longer exist.Model: opus-5-5
Passes review; ready to merge into
next.script/cibuildstill says the tests that lock large secrets are skipped under a plaindocker build ., which this change makes untrue; I read the definition of done's "tests only" as keeping that file out of this PR, so it needs its own small fix.-race, which continues in #120.Model: opus-5-5