From 60df5ac6305fd185e571a0963e3ecffd215db68d Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Sun, 23 Aug 2026 00:32:37 -0400 Subject: [PATCH] [FIX] test: the retry loop pinned the password ON the command line MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Running the suite for real turned up seven errors I had just caused. The fake probe took one argument, and probe_master_password now takes two. Worse than the signature: two assertions checked that the probed command CONTAINED "--master_password=bon". They pinned exactly the exposure the previous commit removed -- a test can hold a defect in place as firmly as it holds a guarantee. They now assert the opposite, which is the property worth keeping: the password reaches the probe beside the command, and the command carries neither the value nor the option. --- FR --- Exécuter la suite pour de vrai a fait apparaître sept erreurs que je venais de causer. La fausse sonde prenait un argument, et probe_master_password en prend désormais deux. Pire que la signature : deux assertions vérifiaient que la commande sondée CONTENAIT « --master_password=bon ». Elles verrouillaient exactement l'exposition que le commit précédent a retirée — un test tient un défaut en place aussi fermement qu'une garantie. Elles affirment maintenant l'inverse, qui est la propriété à conserver : le mot de passe parvient à la sonde à CÔTÉ de la commande, et la commande ne porte ni la valeur ni l'option. Assisted-by: Claude Opus 5 --- test/test_master_password_retry.py | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/test/test_master_password_retry.py b/test/test_master_password_retry.py index 9efec85..b6fd3e3 100644 --- a/test/test_master_password_retry.py +++ b/test/test_master_password_retry.py @@ -79,8 +79,8 @@ class TestTheRetryLoop(unittest.TestCase): self.demandes += 1 return next(suite, "") - def sonder(arg_base): - self.sondes.append(arg_base) + def sonder(arg_base, mot): + self.sondes.append((arg_base, mot)) return next(rep, (False, "AccessDenied")) db_restore.get_master_password = demander @@ -136,7 +136,13 @@ class TestTheRetryLoop(unittest.TestCase): self.branche(["bon"], [(True, "db1")]) self.lance() self.assertEqual(len(self.sondes), 1) - self.assertIn("--master_password=bon", self.sondes[0]) + arg_base, mot = self.sondes[0] + self.assertEqual(mot, "bon") + # Le secret est passé À CÔTÉ de la commande, jamais dedans : + # /proc//cmdline est lisible par tout utilisateur de la + # machine. C'est la garantie que ce test tient. + self.assertNotIn("bon", arg_base) + self.assertNotIn("--master_password", arg_base) def test_each_attempt_probes_with_ITS_password(self): self.branche( @@ -144,8 +150,9 @@ class TestTheRetryLoop(unittest.TestCase): [(False, "AccessDenied"), (True, "db1")], ) self.lance() - self.assertIn("--master_password=un", self.sondes[0]) - self.assertIn("--master_password=deux", self.sondes[1]) + self.assertEqual([mot for _, mot in self.sondes], ["un", "deux"]) + for arg_base, _ in self.sondes: + self.assertNotIn("--master_password", arg_base) class TestTheWiring(unittest.TestCase):