All checks were successful
check / check (push) Successful in 5s
Updates golangci-lint to v2.12.2 everywhere it is pinned and installs the canonical `.golangci.yml`, then remediates every finding the new linter/config surfaces so `make check` is green. ## Version bump - `Dockerfile` lint stage: `golangci/golangci-lint:v2.11.3-alpine` -> `v2.12.2-alpine` (digest-pinned, date comment updated) - `Makefile` `deps` target: `go install` moved from the old v1 module path at `@latest` to the pinned `github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2` - `.golangci.yml` replaced with the canonical config (v2 schema; settings under `linters.settings` so the thresholds actually apply; `default: all` with the standard six disables) - `script/bootstrap` installs golangci-lint via the system package manager and carries no version pin, so it is unchanged - CI (`.gitea/workflows/check.yml`) only runs `script/cibuild`, so it needed no change ## Lint remediation The canonical config surfaced ~3,300 findings across 56k lines. All are fixed, behavior-preserving; incorporates and supersedes the per-package mechanical passes already merged to `main` (refs #61). Highlights: - `err113`: dynamic errors replaced with package sentinels + `%w` wrapping; comparisons via `errors.Is` - `goprintffuncname`: printf-style helpers renamed with an `f` suffix (`ui.Writer` message methods, `cli.ReportErrorf`, `database.Fatalf`) and all call sites updated - `revive` stutter renames: `blob.Handler`, `blob.WithReader`, `blob.ChunkPosition`, `storage.URL`, `storage.Info`; missing doc comments added - `contextcheck`/`noctx`: `context.Context` threaded through `blob.Packer` and the scanner call sites; context-aware `exec`/`sql` variants - `funlen`/`cyclop`/`gocognit`/`dupl`: oversized and duplicated functions split into focused helpers (production and test code) - tests: `t.Parallel()` added where safe (global logger init kept in the serial phase for `-race`), `t.TempDir()`/`t.Helper()` adopted, several suites converted to external test packages - `gosec`: bounded integer conversions, `ReadHeaderTimeout` on the test HTTP server; remaining warnings suppressed per-site with justifications - remaining `nolint` directives are rare, targeted, and each carries a reason (e.g. `nilnil` not-found contract in the repository layer, fx module globals, on-disk snake_case struct tags) - removed the deprecated `log.LogOptions` alias (callers migrated to `log.Options`) `make check` (tests with `-race`, lint, fmt-check) passes. Co-authored-by: sneak <sneak@sneak.berlin> Reviewed-on: #62 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
101 lines
3.1 KiB
Go
101 lines
3.1 KiB
Go
package vaultik_test
|
|
|
|
import (
|
|
"bytes"
|
|
"crypto/rand"
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
"io"
|
|
"testing"
|
|
|
|
"github.com/klauspost/compress/zstd"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
"sneak.berlin/go/vaultik/internal/crypto"
|
|
)
|
|
|
|
// TestTeeReaderWithDecryption tests that TeeReader correctly hashes all encrypted
|
|
// bytes when streaming through age decryption and zstd decompression.
|
|
// This validates the verification path: hash encrypted blob -> decrypt -> decompress.
|
|
func TestTeeReaderWithDecryption(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
// Test data - use random data that doesn't compress well (5MB)
|
|
testData := make([]byte, 5*1024*1024)
|
|
_, err := rand.Read(testData)
|
|
require.NoError(t, err)
|
|
|
|
// Compress the data
|
|
var compressedBuf bytes.Buffer
|
|
|
|
compressor, err := zstd.NewWriter(&compressedBuf,
|
|
zstd.WithEncoderLevel(zstd.SpeedDefault))
|
|
require.NoError(t, err)
|
|
_, err = compressor.Write(testData)
|
|
require.NoError(t, err)
|
|
err = compressor.Close()
|
|
require.NoError(t, err)
|
|
|
|
// Encrypt the compressed data
|
|
testRecipient := "age1cplgrwj77ta54dnmydvvmzn64ltk83ankxl5sww04mrt" +
|
|
"mu62kv3s89gmvv"
|
|
testSecretKey := "AGE-SECRET-KEY-1C77PYNTHXSHNNC6EYR2W52UWYXACXA5J" +
|
|
"T00J9CCW9986M3XY87PSGP89AQ"
|
|
|
|
encryptor, err := crypto.NewEncryptor([]string{testRecipient})
|
|
require.NoError(t, err)
|
|
|
|
var encryptedBuf bytes.Buffer
|
|
|
|
err = encryptor.EncryptStream(&encryptedBuf, bytes.NewReader(compressedBuf.Bytes()))
|
|
require.NoError(t, err)
|
|
|
|
encryptedData := encryptedBuf.Bytes()
|
|
|
|
// Calculate the expected hash of the encrypted data directly
|
|
expectedHash := sha256.Sum256(encryptedData)
|
|
expectedHashStr := hex.EncodeToString(expectedHash[:])
|
|
|
|
t.Logf("Encrypted data size: %d bytes", len(encryptedData))
|
|
t.Logf("Expected hash: %s", expectedHashStr)
|
|
|
|
// Now simulate what verifyBlob does: use TeeReader to hash while decrypting
|
|
decryptor, err := crypto.NewDecryptor(testSecretKey)
|
|
require.NoError(t, err)
|
|
|
|
// Create hasher and tee reader
|
|
hasher := sha256.New()
|
|
reader := bytes.NewReader(encryptedData)
|
|
teeReader := io.TeeReader(reader, hasher)
|
|
|
|
// Decrypt through the tee reader
|
|
decryptedReader, err := decryptor.DecryptStream(teeReader)
|
|
require.NoError(t, err)
|
|
|
|
// Decompress
|
|
decompressor, err := zstd.NewReader(decryptedReader)
|
|
require.NoError(t, err)
|
|
|
|
defer decompressor.Close()
|
|
|
|
// Read all decompressed data (simulating chunk verification)
|
|
decompressedData, err := io.ReadAll(decompressor)
|
|
require.NoError(t, err)
|
|
|
|
// Verify we got the original data back
|
|
assert.Equal(t, testData, decompressedData, "Decompressed data should match original")
|
|
|
|
// Drain remaining decompressed data (should be 0)
|
|
remaining, err := io.Copy(io.Discard, decompressor)
|
|
require.NoError(t, err)
|
|
assert.Equal(t, int64(0), remaining, "No remaining decompressed data")
|
|
|
|
// Calculate hash from tee reader
|
|
calculatedHashStr := hex.EncodeToString(hasher.Sum(nil))
|
|
t.Logf("Calculated hash (before drain): %s", calculatedHashStr)
|
|
|
|
// Verify the hash matches the direct hash of encrypted data
|
|
assert.Equal(t, expectedHashStr, calculatedHashStr,
|
|
"Hash calculated via TeeReader should match direct hash of encrypted data")
|
|
}
|