[FIX] test: the retry loop pinned the password ON the command line

Running the suite for real turned up seven errors I had just caused. The
fake probe took one argument, and probe_master_password now takes two.

Worse than the signature: two assertions checked that the probed command
CONTAINED "--master_password=bon". They pinned exactly the exposure the
previous commit removed -- a test can hold a defect in place as firmly as
it holds a guarantee.

They now assert the opposite, which is the property worth keeping: the
password reaches the probe beside the command, and the command carries
neither the value nor the option.

--- FR ---

Exécuter la suite pour de vrai a fait apparaître sept erreurs que je
venais de causer. La fausse sonde prenait un argument, et
probe_master_password en prend désormais deux.

Pire que la signature : deux assertions vérifiaient que la commande sondée
CONTENAIT « --master_password=bon ». Elles verrouillaient exactement
l'exposition que le commit précédent a retirée — un test tient un défaut
en place aussi fermement qu'une garantie.

Elles affirment maintenant l'inverse, qui est la propriété à conserver :
le mot de passe parvient à la sonde à CÔTÉ de la commande, et la commande
ne porte ni la valeur ni l'option.

Assisted-by: Claude Opus 5
This commit is contained in:
Mathieu Benoit 2026-08-23 00:32:37 -04:00
parent 3f97b0a49c
commit 60df5ac630

View file

@ -79,8 +79,8 @@ class TestTheRetryLoop(unittest.TestCase):
self.demandes += 1
return next(suite, "")
def sonder(arg_base):
self.sondes.append(arg_base)
def sonder(arg_base, mot):
self.sondes.append((arg_base, mot))
return next(rep, (False, "AccessDenied"))
db_restore.get_master_password = demander
@ -136,7 +136,13 @@ class TestTheRetryLoop(unittest.TestCase):
self.branche(["bon"], [(True, "db1")])
self.lance()
self.assertEqual(len(self.sondes), 1)
self.assertIn("--master_password=bon", self.sondes[0])
arg_base, mot = self.sondes[0]
self.assertEqual(mot, "bon")
# Le secret est passé À CÔTÉ de la commande, jamais dedans :
# /proc/<pid>/cmdline est lisible par tout utilisateur de la
# machine. C'est la garantie que ce test tient.
self.assertNotIn("bon", arg_base)
self.assertNotIn("--master_password", arg_base)
def test_each_attempt_probes_with_ITS_password(self):
self.branche(
@ -144,8 +150,9 @@ class TestTheRetryLoop(unittest.TestCase):
[(False, "AccessDenied"), (True, "db1")],
)
self.lance()
self.assertIn("--master_password=un", self.sondes[0])
self.assertIn("--master_password=deux", self.sondes[1])
self.assertEqual([mot for _, mot in self.sondes], ["un", "deux"])
for arg_base, _ in self.sondes:
self.assertNotIn("--master_password", arg_base)
class TestTheWiring(unittest.TestCase):