Say which binary the smoke tests, and unmap loopback before judging reach - #14
Merged
Merged
Conversation
…each Two pre-existing defects, both found while validating an unrelated branch. The four --report checks did not fail because the report drifted: --report already names the backend and says live or demo on its mode line, and it does so in both modes. They failed because $bin defaults to `tui-secure` on PATH, which on a machine with the packaged tool installed is the last release, not the build under test. That release predates the flag, so each check died on "flag provided but not defined" while the privacy check right after them still passed, its `|| true` swallowing the same error. The suite now resolves the binary, prints it with its version, and stops with one legible message when it cannot answer --report at all. ParseSS judged reach by the spelling of the address, so a dual-stack socket bound to loopback and printed as "::ffff:127.0.0.1" was reported as reachable from another machine, which is the ports probe telling an operator a local-only port is exposed. Addresses are now unmapped before the loopback test, leaving a mapped routable address such as "::ffff:10.0.0.5" global; the textual rules stay as the fallback for what ss prints that is not an address. Closes #13 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MCypLQF5AD8JD831Ea9S9q
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #13
Two pre-existing defects, both found while validating an unrelated branch.
The four
--reportsmoke checksNeither the report nor the expectations drifted.
--reportalready names thebackend (
backend: host,backend: demo) and already says which kind of runit was on the mode line (
mode: live,mode: demo (sample data, ...)), inboth modes.
They failed because
$bindefaults totui-secureonPATH, and on a machinewith the packaged tool installed that is the last release rather than the build
being smoked. The release predates the flag, so all four died on
flag provided but not defined: -report, while the privacy check right after them stillpassed: its
|| trueswallows the same error andgrep -con empty outputprints the
0that check wants.The suite now resolves the binary, prints it with its version, and stops with
one legible message instead of four misleading failures:
The home directory is abbreviated on that line the way
--reportabbreviatesit, since the log is kept as public evidence.
ParseSSand IPv4-mapped loopbackglobalAddressjudged reach by the spelling of the address, so a dual-stacksocket bound to loopback and printed by
ssas::ffff:127.0.0.1was reportedas reachable from another machine — the ports probe telling an operator that a
local-only port is exposed. Addresses are unmapped before the loopback test
now; a mapped routable address such as
::ffff:10.0.0.5stays global, and thetextual rules remain the fallback for what
ssprints that is not an address(
localhost,*).Covered by
TestParseSSMappedAddresses.Verified
make lint(gofmt, vet, exec boundary clean, golangci-lint 0 issues)go test ./...greenTUI_LAB_BIN=$PWD/bin/tui-secure bash test/smoke.shon Fedora 42: 26 passed,0 failed, including the four
--reportchecks/usr/bin/tui-secure0.1.1 and nowreported as the single guard failure
No key bindings, shipped behaviour,
tool.jsonor rendered README text changed,so no
make readme.🤖 Generated with Claude Code
https://claude.ai/code/session_01MCypLQF5AD8JD831Ea9S9q