From 49c2df16117482d01452e507d55336f393eb7a79 Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Thu, 2 Jul 2026 16:32:25 -0500 Subject: [PATCH] #41 Fix flaky TestSealOpenRoundtrip (deterministic) TestSealOpenRoundtrip scanned the whole ~36-byte sealed frame for the plaintext with bytes.Contains(sealed, pt). For the 1-byte case ("x"), any of the ~29 random bytes (nonce+ciphertext+tag) equalling that byte tripped the assertion, so it failed ~11% of runs (1-(255/256)^29). Living on main, that spuriously failed ~11% of CI runs. Replace the probabilistic per-byte scan with a deterministic check that the sealed frame is never the bare plaintext (it always carries the header+nonce+tag, so it differs in both length and content). The round-trip Open(Seal(x)) == x assertion is unchanged. Verbatim-leak coverage already lives deterministically in TestNoPlaintextLeak, which uses a multi-byte marker where a chance match is negligible. Test-only change; no production code touched. Verified: go test ./internal/crypto/... -count=100 passes; the previously-flaky test passes 500 consecutive runs; go vet ./... clean. Co-Authored-By: Claude Opus 4.8 --- internal/crypto/crypto_test.go | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/internal/crypto/crypto_test.go b/internal/crypto/crypto_test.go index 77cba68..dce5248 100644 --- a/internal/crypto/crypto_test.go +++ b/internal/crypto/crypto_test.go @@ -46,8 +46,19 @@ func TestSealOpenRoundtrip(t *testing.T) { if err != nil { t.Fatalf("Seal(%d bytes): %v", len(pt), err) } - if len(pt) > 0 && bytes.Contains(sealed, pt) { - t.Errorf("sealed frame contains the plaintext verbatim (len %d)", len(pt)) + // The sealed frame is never the bare plaintext: it always prepends the + // 7-byte header + 12-byte nonce and appends the 16-byte GCM tag, so it + // differs from the plaintext in both length and leading bytes. This is + // a deterministic check. + // + // We deliberately do NOT scan the frame for the plaintext byte-by-byte + // (the old `bytes.Contains(sealed, pt)`): with a random nonce and + // ciphertext, a 1-byte plaintext coincides with some frame byte + // ~11% of the time, which made this test flaky (issue #41). + // Verbatim-leak coverage lives in TestNoPlaintextLeak, which uses a + // multi-byte marker where a chance match is negligible. + if bytes.Equal(sealed, pt) { + t.Errorf("sealed frame equals the plaintext (len %d)", len(pt)) } got, err := Open(kr, sealed) if err != nil { -- 2.47.3