Background
The Go SDK ships a runnable example at languages/golang/encrypt/example (mise run go:encrypt:example). It connects to ZeroKMS, the CipherStash key service, so it needs real credentials. No CI job runs it.
Problem
The example broke without anyone noticing. It encrypted rows through a cipher with Extend("tenant-42") and decrypted them through the Client, which refuses rows sealed with an extension. So it failed at its last step. #1094 fixed the call, but nothing stops the same kind of break from happening again. Examples that work as written matter a lot: developers copy them.
The tests use a deterministic test build of the guest (NewDeterministicClient) that needs no ZeroKMS. But that constructor lives in encrypt/export_test.go, so only package encrypt's own tests can call it. The example is package main in another directory, so it cannot reach it.
Proposal
- Make the example's
run take a *encrypt.Client, so a test can pass one in.
- Make a deterministic client available to tests outside package
encrypt, for example from an internal test-support package that reads the deterministic guest build.
- Add
encrypt/example/main_test.go, which calls run with that client. Then tests-golang.yml runs the example on every pull request.
Found in the review of #1094.
Background
The Go SDK ships a runnable example at
languages/golang/encrypt/example(mise run go:encrypt:example). It connects to ZeroKMS, the CipherStash key service, so it needs real credentials. No CI job runs it.Problem
The example broke without anyone noticing. It encrypted rows through a cipher with
Extend("tenant-42")and decrypted them through theClient, which refuses rows sealed with an extension. So it failed at its last step. #1094 fixed the call, but nothing stops the same kind of break from happening again. Examples that work as written matter a lot: developers copy them.The tests use a deterministic test build of the guest (
NewDeterministicClient) that needs no ZeroKMS. But that constructor lives inencrypt/export_test.go, so only packageencrypt's own tests can call it. The example ispackage mainin another directory, so it cannot reach it.Proposal
runtake a*encrypt.Client, so a test can pass one in.encrypt, for example from an internal test-support package that reads the deterministic guest build.encrypt/example/main_test.go, which callsrunwith that client. Thentests-golang.ymlruns the example on every pull request.Found in the review of #1094.