Skip to content

test(debug): integration coverage for the hidden-input .in gate #549

Description

@fentas

Follow-up from the PR #548 review (Phase 1 of the debug module).

The .in recorder tee is gated on slaveIsHiddenInput(pty.master) so password entry (sudo/ssh/passwd/read -s) is never recorded (src/proxy.zig). The gate reuses the same predicate as the existing redaction fast-path (verified correct by reading in review), but there's no automated test that a keystroke typed under echo-off is actually dropped from the report — it's a proxy-level gate, so the unit suite (which doesn't compile proxy.zig) can't reach it, and the current debug_capture e2e has no hidden-input phase.

Proposed: an e2e scenario that puts the tty into canonical no-echo (stty -echo → ICANON && !ECHO, which triggers the gate) or uses a getpass-style reader, types a marker, captures a report, then asserts the marker is absent from the report file. Care needed to keep it deterministic (the assertion command must not itself echo the marker value into the in stream — reference it via a shell var).

Also low: the term tee now has a unit test (src/proxy/io_tests.zig), so that half of the review's test-gap finding is closed; this issue tracks the hidden-input half.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions