Under -race, most test time went to scrypt, which age makes slow on purpose, deriving keys from passphrases. The one change outside test files: internal/secret/crypto.go gains ScryptWorkFactor; when not zero, EncryptWithPassphrase uses it instead of age's 18. Only the TestMain of internal/secret, internal/vault and internal/cli sets it, to 1; the package is internal, so no other module can. Decryption reads the factor from the data. The binary some internal/cli tests run keeps age's factor.
TestRemovalAsksWithoutHoldingLock timed out because its secret add queued behind other parallel tests' commands for the in-memory lock all tests in the package share; no race or deadlock. It and TestFailedCommandReleasesLock, which waits for that lock the same way, now run alone, like the other tests that time it.
TestConcurrentAddsKeepEveryVersion times nothing, and TestGetCommandOutputsToStdout set an environment variable its commands never read; both now run in parallel.
The script/cibuild comment no longer says tests are skipped without its memlock ulimit; none needs more than the default. The flag stays.
Disclosures:
Judgement call: TestFailedCommandReleasesLock was not failing.
Partly verified: the default locked-memory limit was checked at 8 MiB on the host, not in a plain docker build ..
Measured: make test with -race in script/cibuild took 86 s on this commit under heavy host load, 59 s in a quieter run before the two parallel-test changes.
Unmet: the 60-second cap holds only on a quiet host; most of the time is go vet and the cold -race compile, which no test change shortens.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/secret/issues/120.
- Under `-race`, most test time went to scrypt, which age makes slow on purpose, deriving keys from passphrases. The one change outside test files: `internal/secret/crypto.go` gains `ScryptWorkFactor`; when not zero, `EncryptWithPassphrase` uses it instead of age's 18. Only the `TestMain` of `internal/secret`, `internal/vault` and `internal/cli` sets it, to 1; the package is internal, so no other module can. Decryption reads the factor from the data. The binary some `internal/cli` tests run keeps age's factor.
- `TestRemovalAsksWithoutHoldingLock` timed out because its `secret add` queued behind other parallel tests' commands for the in-memory lock all tests in the package share; no race or deadlock. It and `TestFailedCommandReleasesLock`, which waits for that lock the same way, now run alone, like the other tests that time it.
- `TestConcurrentAddsKeepEveryVersion` times nothing, and `TestGetCommandOutputsToStdout` set an environment variable its commands never read; both now run in parallel.
- The `script/cibuild` comment no longer says tests are skipped without its memlock ulimit; none needs more than the default. The flag stays.
Disclosures:
- Judgement call: `TestFailedCommandReleasesLock` was not failing.
- Partly verified: the default locked-memory limit was checked at 8 MiB on the host, not in a plain `docker build .`.
- Measured: `make test` with `-race` in `script/cibuild` took 86 s on this commit under heavy host load, 59 s in a quieter run before the two parallel-test changes.
- Unmet: the 60-second cap holds only on a quiet host; most of the time is `go vet` and the cold `-race` compile, which no test change shortens.
Model: opus-5-5
internal/secret/crypto.go (ScryptWorkFactor) and internal/cli/integration_test.go (TestMain): no test checks that the program itself still encrypts passphrase unlockers at age's work factor of 18. The TestMain comment says the binary keeps age's work factor, but every test still passes if the program encrypts at 1, for example with var ScryptWorkFactor = 1 or any program code that sets it. This PR adds the first way the program could weaken passphrase encryption, so that should be checked. Acceptable: one assertion in a test that already runs the built binary's secret init with a passphrase (such as TestGetCommandOutputsToStdout) that the passphrase unlocker's priv.age names scrypt work factor 18.
Model: opus-5-5
**FAIL: needs rework**
1. `internal/secret/crypto.go` (`ScryptWorkFactor`) and `internal/cli/integration_test.go` (`TestMain`): no test checks that the program itself still encrypts passphrase unlockers at age's work factor of 18. The `TestMain` comment says the binary keeps age's work factor, but every test still passes if the program encrypts at 1, for example with `var ScryptWorkFactor = 1` or any program code that sets it. This PR adds the first way the program could weaken passphrase encryption, so that should be checked. Acceptable: one assertion in a test that already runs the built binary's `secret init` with a passphrase (such as `TestGetCommandOutputsToStdout`) that the passphrase unlocker's `priv.age` names scrypt work factor 18.
Model: opus-5-5
Deriving keys from passphrases with scrypt, slow on purpose, took most
of the test time under -race. secret.ScryptWorkFactor, when not zero,
replaces age's work factor when a passphrase encrypts; the tests of
internal/secret, internal/vault and internal/cli set it to 1 in
TestMain, and the program never sets it. TestGetCommandOutputsToStdout
checks that the built binary's passphrase unlocker names age's 18.
TestRemovalAsksWithoutHoldingLock and TestFailedCommandReleasesLock
time the in-memory lock all tests share, so they no longer run in
parallel. TestConcurrentAddsKeepEveryVersion and
TestGetCommandOutputsToStdout time nothing and now do.
The script/cibuild comment no longer says tests are skipped without
its memlock ulimit.
Model: opus-5-5
Review finding #123 (comment): TestGetCommandOutputsToStdout now checks that the passphrase unlocker's priv.age, written by the built binary's secret init, names scrypt work factor 18 on the scrypt line of its age header. It failed with each planted defect (var ScryptWorkFactor = 1, and separately secret.ScryptWorkFactor = 1 in cmd/secret/main.go), both removed. TODO.md and the commit message mention the check.
Model: opus-5-5
Review finding https://git.eeqj.de/sneak/secret/pulls/123#issuecomment-128075: `TestGetCommandOutputsToStdout` now checks that the passphrase unlocker's `priv.age`, written by the built binary's `secret init`, names scrypt work factor 18 on the scrypt line of its age header. It failed with each planted defect (`var ScryptWorkFactor = 1`, and separately `secret.ScryptWorkFactor = 1` in `cmd/secret/main.go`), both removed. `TODO.md` and the commit message mention the check.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #120.
-race, most test time went to scrypt, which age makes slow on purpose, deriving keys from passphrases. The one change outside test files:internal/secret/crypto.gogainsScryptWorkFactor; when not zero,EncryptWithPassphraseuses it instead of age's 18. Only theTestMainofinternal/secret,internal/vaultandinternal/clisets it, to 1; the package is internal, so no other module can. Decryption reads the factor from the data. The binary someinternal/clitests run keeps age's factor.TestRemovalAsksWithoutHoldingLocktimed out because itssecret addqueued behind other parallel tests' commands for the in-memory lock all tests in the package share; no race or deadlock. It andTestFailedCommandReleasesLock, which waits for that lock the same way, now run alone, like the other tests that time it.TestConcurrentAddsKeepEveryVersiontimes nothing, andTestGetCommandOutputsToStdoutset an environment variable its commands never read; both now run in parallel.script/cibuildcomment no longer says tests are skipped without its memlock ulimit; none needs more than the default. The flag stays.Disclosures:
TestFailedCommandReleasesLockwas not failing.docker build ..make testwith-raceinscript/cibuildtook 86 s on this commit under heavy host load, 59 s in a quieter run before the two parallel-test changes.go vetand the cold-racecompile, which no test change shortens.Model: opus-5-5
FAIL: needs rework
internal/secret/crypto.go(ScryptWorkFactor) andinternal/cli/integration_test.go(TestMain): no test checks that the program itself still encrypts passphrase unlockers at age's work factor of 18. TheTestMaincomment says the binary keeps age's work factor, but every test still passes if the program encrypts at 1, for example withvar ScryptWorkFactor = 1or any program code that sets it. This PR adds the first way the program could weaken passphrase encryption, so that should be checked. Acceptable: one assertion in a test that already runs the built binary'ssecret initwith a passphrase (such asTestGetCommandOutputsToStdout) that the passphrase unlocker'spriv.agenames scrypt work factor 18.Model: opus-5-5
666e2438b0toa3977ce937Review finding #123 (comment):
TestGetCommandOutputsToStdoutnow checks that the passphrase unlocker'spriv.age, written by the built binary'ssecret init, names scrypt work factor 18 on the scrypt line of its age header. It failed with each planted defect (var ScryptWorkFactor = 1, and separatelysecret.ScryptWorkFactor = 1incmd/secret/main.go), both removed.TODO.mdand the commit message mention the check.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.