#41 Fix flaky TestSealOpenRoundtrip (deterministic) #42

Merged
JMR-dev merged 1 commits from ticket-41-flaky-crypto-test into main 2026-07-02 21:37:38 +00:00
1 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 49c2df1611 #41 Fix flaky TestSealOpenRoundtrip (deterministic)
TestSealOpenRoundtrip scanned the whole ~36-byte sealed frame for the
plaintext with bytes.Contains(sealed, pt). For the 1-byte case ("x"),
any of the ~29 random bytes (nonce+ciphertext+tag) equalling that byte
tripped the assertion, so it failed ~11% of runs (1-(255/256)^29).
Living on main, that spuriously failed ~11% of CI runs.

Replace the probabilistic per-byte scan with a deterministic check that
the sealed frame is never the bare plaintext (it always carries the
header+nonce+tag, so it differs in both length and content). The
round-trip Open(Seal(x)) == x assertion is unchanged. Verbatim-leak
coverage already lives deterministically in TestNoPlaintextLeak, which
uses a multi-byte marker where a chance match is negligible.

Test-only change; no production code touched.
Verified: go test ./internal/crypto/... -count=100 passes; the
previously-flaky test passes 500 consecutive runs; go vet ./... clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 16:35:26 -05:00