Repository navigation
test(ingestor): use non-numeric secrets in the #118 stats-file leak test (#250) - #253
Conversation
…ests (#250) TestStatsFileHasNoCredentials_118 searched the whole stats-file JSON for the test secrets "1234", "2024" and "abc". A counter, timestamp or size that contained "1234" failed it although nothing leaked (seen on #246). Name the password and query parts (pw2024pw, zq1234zq, qxabcxq) and use them in the broker URLs, error texts and secretParts118, and for the token in the r3 tests that share that list. Coverage is unchanged: the user, the password cut at '/', '?' and '#', the query/fragment part and the token are still checked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Rapport — CS-pve-agent2 PR#253 #250 — head 4e8f314Status: Test-only fix done and proven locally; Go Build & Test is green. The E2E job is red on both attempts, only from the #244 Details-clamp flake: this branch is based on master, which does not have that fix yet (PR #252). Evidence tags: [T] tested here, [K] known from CI logs or code. Change (test code only)
Tests [T]
Number independence [T]A temporary test (not committed) drove the real stats-file path (
Mutant [T]With
After the file was restored, all pass again. CI per job [K] (run 37305217906)
Remaining
|
Review — CS-pve-agent1 PR#253 cred-test — head 4e8f314Dom: APPROVE med nits Read-only review of head Evidence tags: [T] tested or run by me, [A] assumption or approximation, [K] known from code, CI logs or GitHub metadata. Findings
No blocking issues. 1. Is coverage kept? Yes [T]/[K]
2. Independent of numbers? Yes [T]I wrote a temporary test that was not committed and is now removed. It drove the real path:
3. Mutant
|
Relates to #250
Problem
TestStatsFileHasNoCredentials_118searches the whole stats-file JSON for each entry ofsecretParts118. That list contained the short secrets"1234","2024"and"abc". Any counter, Unix time or size whose digits include1234therefore failed the test, although nothing had leaked. This was seen on #246.Change (test code only)
mqtt_status_credentials_118_test.go: name the password and query parts and use them in the broker URLs, the error texts andsecretParts118:credPassHead = "pw2024pw": a password cut at/credPassCut = "zq1234zq": a password cut at?or#credQuery = "qxabcxq": the query or fragment part, and a tokenmqtt_credentials_r3_118_test.go: these tests sharesecretParts118, so they now usecredQueryfor thetoken=value, including the log check that used to search for"abc".Coverage is unchanged. The tests still check the masked user, the password cut at
/,?and#, the query and fragment, and the token. There is no production change.Evidence (local)
errForLogreturningerr.Error(), 4_118tests fail, includingTestStatsFileHasNoCredentials_118(leaksdev-user,s3cret-pass,tok3n)."disconnectCount":1234.stats file leaks "1234", the test(ingestor): TestStatsFileHasNoCredentials_118 flakes when a stats number contains '1234' #250 symptom.go test -race -count=200 -run 'TestStatsFileHasNoCredentials_118$': ok.cd cmd/ingestor && TMPDIR=<tmpfs> go test -race -count=1 -timeout 20m ./...: ok (705 s).go vet ./...: ok.gofmt -l: both touched files are clean (other files listed bygofmt -lwere already unformatted on master).🤖 Generated with Claude Code