From e49586646b5800bfa19c65e70f411bcc12925907 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 03:15:22 +0200 Subject: [PATCH] A comment claimed a test that does not exist MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit I wrote that a test asserts the control plane's placeholder expression and the host's still agree. None does, and none in this repository could — a unit test here can only assert what this repository already believes. That is precisely the thing this project refuses to tolerate: a stated rule with no way to check it, which costs more than no rule because people believe it. Written by me, today, in the same file that closes a gap of the same kind. What actually proves it is the lab, and the comment now says so. --- internal/catalogue/secrets_into_files.go | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/internal/catalogue/secrets_into_files.go b/internal/catalogue/secrets_into_files.go index 49e3c3f..b77580a 100644 --- a/internal/catalogue/secrets_into_files.go +++ b/internal/catalogue/secrets_into_files.go @@ -24,9 +24,13 @@ import ( // placeholder is what a module's file content says where a sealed value belongs: ${secret:name}. // -// The same expression the host matches, written out again rather than shared. The two -// repositories agree on a wire format, and a format read on both sides is exactly the thing that -// must not be quietly changed on one of them; a test asserts they still agree. +// The same expression the host matches, written out again rather than shared: they are separate +// repositories and this is a wire format, like the shape of the declaration itself. +// +// **Nothing here can check that they agree, and the claim that something did was wrong.** A unit +// test in this repository can only assert what this repository already believes. What proves it is +// the lab, where a real host receives a real declaration and the file arrives filled — and where +// the two expressions disagreeing shows up as a placeholder written through to a machine. var placeholder = regexp.MustCompile(`\$\{secret:([a-z0-9][a-z0-9-]*)\}`) // secretsUsed are the names a file's content asks for, in the order they first appear.