`tests/common/fake_nm.rs` stands up a fake `org.freedesktop.NetworkManager`
on a private bus so `cli.rs` and `flow_watch.rs` exercise the real
`nm` code paths without a live NetworkManager and without shelling out.
Replaces the previous command-capture scaffolding in those two files;
scenario coverage (captive portal, exit-node failover, 802.1x,
per-network DNS, schedule triggers, Tailscale recovery, SSID
verification) is preserved — 139 tests.
The watch loop could spin forever on a stopped Tailscale daemon (the
auto-start path was unreachable) while re-notifying every retry, report
"connected" when NM autoconnect won a race onto a different SSID, and
classify captive portals as healthy (200/302 accepted as internet). The
bread-bus subscription thread also read/wrote config and state files
concurrently with the watch loop. Fix all of those plus: EDITOR values
with arguments, scan --to silently ignoring unknown profiles, deleted
core profiles being resurrected, inline-network migration data loss,
login never retried, XDG-unaware install-service, detect persisting a
stale default profile, password length leaking through the mask, a
stdin/stdout pipe deadlock, and several minor UI/robustness issues.
Generated with Codebuff 🤖
Co-Authored-By: Codebuff <noreply@codebuff.com>
First connect (and reuse-with-password) no longer puts the secret on
nmcli's command line, so it is not visible in /proc/<pid>/cmdline.
networks.toml stays 0600; the local copy is still cleared after first
success.
Bug fixes:
- mask() panicked on multi-byte UTF-8 passwords (byte-slicing a char
boundary); now masks by char count and never echoes a real character
- `cd --shell` interpolated the config path into a shell -c string via
Debug formatting, which doesn't neutralize shell metacharacters; now
passed as a positional shell argument instead
- connecting to open (no-password) networks failed because an empty PSK
was always sent to nmcli, which nmcli treats as secured-with-no-password
instead of open; the password arg is now omitted entirely when empty
- five nmcli terse-output parse sites used a raw splitn(2, ':'), which
mis-splits any device/connection name containing a literal ':'; unified
on the existing escape-aware field splitter
- watch's health classifier silently read a config-deleted profile as
"healthy" off a bare internet check instead of surfacing the misconfig
- the nmcli-monitor thread seeded its debounce clock with
`Instant::now() - 10s`, which panics on the monotonic clock near boot —
exactly when the generated systemd unit tends to start the watcher
Architecture:
- extracted src/lib.rs + src/app.rs so command logic can be exercised
in-process by tests instead of only by spawning the compiled binary
- added a Runner trait (src/util.rs) so subprocess calls can be faked in
tests; flow::run and watch::classify are now covered by real in-process
tests of the connect state machine and health transitions, not just
their pure helpers
- Wi-Fi passwords are no longer kept in breadcrumbs' config once
NetworkManager durably holds them: NetworkDef.password is now optional,
and a successful password-based connect clears + persists it
immediately, so it's never sent again on subsequent connects
- saved networks (SSID + optional local password) moved out of
breadcrumbs.toml into a separate networks.toml; old configs with
inline [[networks]] still load and migrate automatically on next save
- corrected a false README claim that passwords are never in nmcli argv
Test count: 20 -> 89 (52 unit, 24 CLI integration, 13 in-process
state-machine tests). Full clean run: cargo build/build --release/
test/clippy --all-targets, verified from a `cargo clean` rebuild.