fix(desktop): skip OS keychain in test builds to prevent headless hangs

hydrate_keys and persist_agent_keys both call the OS keychain through the
SecretStore global singleton. In headless test environments (CI, locked
keychain) these calls block on the macOS Security daemon IPC
(SecKeychainFindGenericPassword / SecKeychainItemModifyAttributesAndData)
and cause tests to hang indefinitely.

Three tests in the Phase-3 seam suite were hanging:
  - test_record_mesh_change_after_preflight_aborts_before_stop
  - test_full_tail_stop_spawn_receipt_register_save
  - test_relay_mesh_preflight_precedes_stop

All three write agent records with non-empty pubkeys to disk then call
load_managed_agents_at or save_managed_agents_at, triggering keychain IPC.

Fix: gate hydrate_keys and persist_agent_keys with #[cfg(test)] early
returns. Test builds exercise the keychain-generic testable cores
(hydrate_keys_with / persist_agent_keys_with) via mock KeyStore impls
directly; the production wrappers are not exercised in unit tests and
must never be. Also add SecretStore::warm_cache_for_test for use by any
future test that needs to pre-seed the in-process cache without touching
the OS keychain.

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
This commit is contained in:
npub1mn7jgtj4w2pd0g0zeuhxsa6jy6p0rewxz4kujt98my82ahfmp72sxjexk7
2026-08-04 20:32:23 -04:00
co-authored by Will Pfleger
parent 4634fe1b39
commit 09207bcf29
@@ -352,6 +352,17 @@ pub(crate) fn backup_invalid_store(path: &Path) {
/// unreachable, leave it inline. This makes the strip deterministic on the
/// next reachable boot rather than waiting for a non-deterministic save.
fn hydrate_keys(records: &mut [ManagedAgentRecord]) {
// In test builds skip the OS keychain entirely. Tests use records with
// `private_key_nsec` inline (empty or pre-populated), and the testable
// core `hydrate_keys_with` is exercised directly with mock stores.
// Without this guard `load_managed_agents_at` blocks on a macOS Security
// daemon IPC call (`SecKeychainFindGenericPassword`) which hangs in
// headless test environments.
#[cfg(test)]
{
let _ = records;
return;
}
let Some(store) = agent_secret_store() else {
return;
};
@@ -527,6 +538,17 @@ fn write_agent_store_to_path(
/// in the JSON. Mutates `records` (a save-local clone) — the caller's in-memory
/// records keep their keys.
fn persist_agent_keys(records: &mut [ManagedAgentRecord]) {
// In test builds skip the OS keychain entirely. Tests exercise the
// testable core `persist_agent_keys_with` directly with mock stores;
// production-path tests (e.g. concurrency tests) operate on records with
// empty `private_key_nsec` where the keyring write is a no-op anyway.
// Without this guard `save_managed_agents_at` blocks on a macOS Security
// daemon IPC write call in headless test environments.
#[cfg(test)]
{
let _ = records;
return;
}
let Some(store) = agent_secret_store() else {
// No keyring backend: keys stay inline.
return;