package blobgen_test import ( "bytes" "io" "testing" "github.com/stretchr/testify/require" "sneak.berlin/go/vaultik/internal/blobgen" ) // TestLimitReaderPassesExactSize checks that a stream of exactly the limit // reads back cleanly to EOF: the bound must not reject a legitimate blob // whose plaintext equals its recorded size. func TestLimitReaderPassesExactSize(t *testing.T) { t.Parallel() const n = 1000 r := blobgen.LimitReader(bytes.NewReader(bytes.Repeat([]byte("a"), n)), n) got, err := io.ReadAll(r) require.NoError(t, err) require.Len(t, got, n) } // TestLimitReaderFailsPastLimit feeds a large, highly compressible run of // zeros — the decompressed output a zip bomb would produce — through a // small limit and checks it fails within the bound rather than passing // the whole stream through. func TestLimitReaderFailsPastLimit(t *testing.T) { t.Parallel() const limit = 1000 r := blobgen.LimitReader( bytes.NewReader(bytes.Repeat([]byte{0}, limit*1000)), limit) n, err := io.Copy(io.Discard, r) require.ErrorIs(t, err, blobgen.ErrOutputTooLarge) require.LessOrEqual(t, n, int64(limit)+1, "reader must stop within one byte of the limit") }