TestRedactSlashHidesHamrpassKey: with `logging: true`, every prompt (including `/hamrpass `) is written to .codehamr/log.txt. The log is meant to be easy to share for bug reports, so a key in there is a quiet leak even at 0o600. redactSlash is the seam every dbgWritef on a slash payload routes
(t *testing.T)
| 619 | dir := t.TempDir() |
| 620 | OpenDebugLog(dir) |
| 621 | t.Cleanup(CloseDebugLog) |
| 622 | st, err := os.Stat(filepath.Join(dir, "log.txt")) |
| 623 | if err != nil { |
| 624 | t.Fatal(err) |
| 625 | } |
| 626 | if got := st.Mode().Perm(); got != 0o600 { |
| 627 | t.Fatalf("log.txt perms = %v, want 0o600", got) |
| 628 | } |
| 629 | } |
| 630 | |
| 631 | // TestVerboseLogCapturesTurnRecords drives a realistic two round turn (reasoning |
| 632 | // → bash tool call → final answer) with logging on, and asserts the verbose |
| 633 | // records that make a session reconstructable for later debugging actually land |
| 634 | // in log.txt: the session header, the per round request/packing summary, the |
| 635 | // streamed reasoning, the tool result, and the round/turn metrics. Also pins the |
| 636 | // dated timestamp: a bare clock can't be correlated across a day boundary. This |
| 637 | // is the regression guard against a refactor silently gutting the debug log. |
| 638 | func TestVerboseLogCapturesTurnRecords(t *testing.T) { |
| 639 | var round int |
| 640 | handler := func(w http.ResponseWriter, _ *http.Request) { |
| 641 | w.Header().Set("Content-Type", "text/event-stream") |
| 642 | round++ |
| 643 | if round == 1 { |
| 644 | fmt.Fprintf(w, "data: %s\n\n", `{"type":"response.reasoning_text.delta","delta":"let me check the file"}`) |
| 645 | fmt.Fprintf(w, "data: %s\n\n", `{"type":"response.output_item.done","output_index":0,"item":{"type":"function_call","call_id":"c1","name":"bash","arguments":"{\"cmd\":\"echo HAMMER\"}"}}`) |
| 646 | fmt.Fprintf(w, "data: %s\n\n", `{"type":"response.completed","response":{"usage":{"output_tokens":5}}}`) |
| 647 | return |
| 648 | } |
| 649 | fmt.Fprintf(w, "data: %s\n\n", `{"type":"response.output_text.delta","delta":"all done"}`) |
nothing calls this directly
no test coverage detected