Skip to content

Say which binary the smoke tests, and unmap loopback before judging reach - #14

Merged
edimarlnx merged 1 commit into
mainfrom
fix/report-smoke-and-mapped-loopback
Sep 2, 2026
Merged

edimarlnx merged 1 commit into
mainfrom
fix/report-smoke-and-mapped-loopback

Conversation

@edimarlnx

Copy link
Copy Markdown
Contributor

Closes #13

Two pre-existing defects, both found while validating an unrelated branch.

The four --report smoke checks

Neither the report nor the expectations drifted. --report already names the
backend (backend: host, backend: demo) and already says which kind of run
it was on the mode line (mode: live, mode: demo (sample data, ...)), in
both modes.

They failed because $bin defaults to tui-secure on PATH, and on a machine
with the packaged tool installed that is the last release rather than the build
being smoked. The release predates the flag, so all four died on flag provided but not defined: -report, while the privacy check right after them still
passed: its || true swallows the same error and grep -c on empty output
prints the 0 that check wants.

The suite now resolves the binary, prints it with its version, and stops with
one legible message instead of four misleading failures:

      binary=/usr/bin/tui-secure (tui-secure 0.1.1)
FAIL  the binary under test does not support --report
      | /usr/bin/tui-secure is too old for this suite; point TUI_LAB_BIN at the
      | build being tested, e.g. TUI_LAB_BIN=$PWD/bin/tui-secure

The home directory is abbreviated on that line the way --report abbreviates
it, since the log is kept as public evidence.

ParseSS and IPv4-mapped loopback

globalAddress judged reach by the spelling of the address, so a dual-stack
socket bound to loopback and printed by ss as ::ffff:127.0.0.1 was reported
as reachable from another machine — the ports probe telling an operator that a
local-only port is exposed. Addresses are unmapped before the loopback test
now; a mapped routable address such as ::ffff:10.0.0.5 stays global, and the
textual rules remain the fallback for what ss prints that is not an address
(localhost, *).

Covered by TestParseSSMappedAddresses.

Verified

  • make lint (gofmt, vet, exec boundary clean, golangci-lint 0 issues)
  • go test ./... green
  • TUI_LAB_BIN=$PWD/bin/tui-secure bash test/smoke.sh on Fedora 42: 26 passed,
    0 failed, including the four --report checks
  • the stale-binary path reproduced against /usr/bin/tui-secure 0.1.1 and now
    reported as the single guard failure

No key bindings, shipped behaviour, tool.json or rendered README text changed,
so no make readme.

🤖 Generated with Claude Code

https://claude.ai/code/session_01MCypLQF5AD8JD831Ea9S9q

…each

Two pre-existing defects, both found while validating an unrelated branch.

The four --report checks did not fail because the report drifted: --report
already names the backend and says live or demo on its mode line, and it does
so in both modes. They failed because $bin defaults to `tui-secure` on PATH,
which on a machine with the packaged tool installed is the last release, not
the build under test. That release predates the flag, so each check died on
"flag provided but not defined" while the privacy check right after them still
passed, its `|| true` swallowing the same error. The suite now resolves the
binary, prints it with its version, and stops with one legible message when it
cannot answer --report at all.

ParseSS judged reach by the spelling of the address, so a dual-stack socket
bound to loopback and printed as "::ffff:127.0.0.1" was reported as reachable
from another machine, which is the ports probe telling an operator a
local-only port is exposed. Addresses are now unmapped before the loopback
test, leaving a mapped routable address such as "::ffff:10.0.0.5" global; the
textual rules stay as the fallback for what ss prints that is not an address.

Closes #13

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MCypLQF5AD8JD831Ea9S9q
@edimarlnx
edimarlnx merged commit 9b637fb into main Sep 2, 2026
8 checks passed
@edimarlnx
edimarlnx deleted the fix/report-smoke-and-mapped-loopback branch September 2, 2026 01:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

smoke: the four --report checks fail on main (pre-existing)

1 participant