Hash passwords with 1 MiB in tests so make test fits in 4 GiB (closes #261) #276

Merged
clawbot merged 1 commits from issue-261-test-memory into next 2026-10-03 03:01:59 +02:00
Collaborator

Fixes #261: on a build machine with 4 GiB, docker build . failed in RUN make test because the auth test binary ran out of memory and was killed.

Cause. upaasd hashes passwords with argon2id at 64 MiB per hash. The auth tests run up to 13 hashes at once (10 of them in the test of concurrent setup requests), the handlers tests up to 4, and the race detector multiplies what each one takes.

Change. The memory per hash is now the auth service's ArgonMemory field. New sets it to the same 64 MiB, and upaasd never changes it; the test helpers lower it to 1 MiB. The new TestHashPasswordWithUpaasdMemory checks that New sets 64 MiB and hashes and verifies a password with it. The session cookie test, which uses the other auth test helper, also still hashes at 64 MiB.

Peak memory of GOMAXPROCS=4 make test with an empty build cache: in the Dockerfile's Go 1.25 image, 3113 MiB before and 1008 MiB after; with this host's Go 1.26.5, 2747 MiB before and 1372 MiB after.
Method: the resident memory of every process of the run, summed every 50 ms from /proc.

  • Judgement call: the field is exported because the handlers tests, in another package, must lower it too.
  • Not run on a 4 GiB arm64 machine.
  • A stored hash does not record its memory, so it verifies only with the value it was made with; the hashes upaasd stores are unaffected.

Model: opus-5-5

Fixes https://git.eeqj.de/sneak/upaas/issues/261: on a build machine with 4 GiB, `docker build .` failed in `RUN make test` because the auth test binary ran out of memory and was killed. **Cause.** upaasd hashes passwords with argon2id at 64 MiB per hash. The auth tests run up to 13 hashes at once (10 of them in the test of concurrent setup requests), the handlers tests up to 4, and the race detector multiplies what each one takes. **Change.** The memory per hash is now the auth service's `ArgonMemory` field. `New` sets it to the same 64 MiB, and upaasd never changes it; the test helpers lower it to 1 MiB. The new `TestHashPasswordWithUpaasdMemory` checks that `New` sets 64 MiB and hashes and verifies a password with it. The session cookie test, which uses the other auth test helper, also still hashes at 64 MiB. **Peak memory** of `GOMAXPROCS=4 make test` with an empty build cache: in the Dockerfile's Go 1.25 image, 3113 MiB before and 1008 MiB after; with this host's Go 1.26.5, 2747 MiB before and 1372 MiB after. Method: the resident memory of every process of the run, summed every 50 ms from `/proc`. - Judgement call: the field is exported because the handlers tests, in another package, must lower it too. - Not run on a 4 GiB arm64 machine. - A stored hash does not record its memory, so it verifies only with the value it was made with; the hashes upaasd stores are unaffected. Model: opus-5-5
clawbot added the needs-review label 2026-10-03 02:47:07 +02:00
clawbot self-assigned this 2026-10-03 02:47:08 +02:00
clawbot added 1 commit 2026-10-03 02:47:08 +02:00
On a build machine with 4 GiB, docker build . failed: the auth test
binary was killed for lack of memory. upaasd hashes passwords with
argon2id at 64 MiB per hash; the auth and handlers tests run many such
hashes at once, and the race detector multiplies what each one takes,
so make test peaked at 2.7 GiB.

The memory per hash is now the auth service's ArgonMemory field. New
sets it to the same 64 MiB, which upaasd keeps; the test helpers lower
it to 1 MiB. A new test checks that New sets 64 MiB and hashes and
verifies a password with it. GOMAXPROCS=4 make test now peaks at about
1.4 GiB.

Model: opus-5-5
Author
Collaborator

Review passed: 55795dd rebased onto next at d3b9c6f.

Model: opus-5-5

Review passed: `55795dd` rebased onto `next` at `d3b9c6f`. Model: opus-5-5
clawbot merged commit 2a2c52074d into next 2026-10-03 03:01:59 +02:00
clawbot deleted branch issue-261-test-memory 2026-10-03 03:01:59 +02:00
Sign in to join this conversation.