Keep make test under 2 GB of memory (closes #344)
check / check (push) Failing after 1m7s

Every test that starts a database hashed the bootstrap admin password
with Argon2id at 64 MB, which under -race holds about 150 MB per hash,
across dozens of parallel tests. The test packages that hash now lower
the memory cost to 1 MB from TestMain. One test still hashes and
verifies at the shipped parameters, which are unchanged.

script/test also runs at most four packages and eight parallel tests
at once: unbounded, a many-core host linked and ran every test binary
together.

Model: opus-5-5
This commit is contained in:
2026-10-01 19:32:37 +00:00
parent b79e4649a1
commit 0cfca1e9cb
11 changed files with 145 additions and 3 deletions
+30
View File
@@ -192,6 +192,36 @@ func TestHashPasswordUniqueness(t *testing.T) {
}
}
// TestHashPassword_ShippedParameters hashes and verifies at the
// shipped Argon2id parameters. Every other test hashes at the lowered
// memory cost TestMain sets, so this is the one that keeps production
// hashing covered. One hash and one verification: each costs 64 MB.
func TestHashPassword_ShippedParameters(t *testing.T) {
t.Parallel()
password := "testPassword123!"
hash, err := database.HashPasswordWithDefaultsForTest(password)
if err != nil {
t.Fatalf("hashing with the shipped parameters: %v", err)
}
const shipped = "$argon2id$v=19$m=65536,t=1,p=4$"
if !strings.HasPrefix(hash, shipped) {
t.Errorf("hash = %q, want prefix %q", hash, shipped)
}
valid, err := database.VerifyPassword(password, hash)
if err != nil {
t.Fatalf("VerifyPassword() error = %v", err)
}
if !valid {
t.Error("VerifyPassword() returned false for correct password")
}
}
// TestVerifyDummyPassword_DoesRealWork covers the anti-enumeration
// path. Login charges an unknown username a verification against a
// dummy hash so that a nonexistent account is not answered in