fix(test): configure clangd and clang-tidy for native test tree (#3)
* fix(test): configure clangd and clang-tidy for native test tree
- Generate compile_commands.json from pio run -e native -t compiledb
so clangd resolves src/ headers in test files without errors.
- Fix .clangd PathMatch regex (relative path, not absolute) and add
-I.pio/build/native/unity_config so unity_config.h resolves.
- Remove overly broad Remove: -I* that was stripping all added paths.
- Add -Wno-format-security and UnusedIncludes: None to test block.
- Add test/.clang-tidy that inherits the root config and:
- Allows test_* functions to use snake_case (FunctionIgnoredRegexp)
- Disables cert-err33-c, cert-dcl50-cpp,
cppcoreguidelines-pro-type-cstyle-cast,
bugprone-argument-comment, bugprone-misplaced-widening-cast,
bugprone-implicit-widening-of-multiplication-result,
misc-unused-using-decls — all false positives in test context.
- Add /* intentionally empty */ comment to all empty setUp()/tearDown()
bodies (28 files) to suppress SonarLint c:S1186.
- Fix test_vault_task: change relative include ../../src/vault/vault_task.h
to vault/vault_task.h (consistent with all other test files; -Isrc
already in compile flags).
- Reorganise test/ into a module-mirroring subtree layout:
test/ble/, test/crypto/, test/hal/, test/ota/, test/platform/,
test/states/, test/totp/, test/ui/, test/vault/, test/web/
(old flat directories removed).
- Add sonar-project.properties exclusion e4: suppress c:S1186 on
test/**/*.cpp at SonarCloud level.
All 468 native unit tests pass (pio test -e native).
* fix(clangd): add -DESP_PLATFORM to global CompileFlags
All Kleidos targets are ESP32/ESP32-S3 (framework = espidf), so
ESP_PLATFORM is always defined at compile time. Without this flag in
the clangd config, the language server was activating #else branches
inside #ifdef ESP_PLATFORM blocks, hiding device code and showing
false diagnostics for src/ files.
The test/** fragment already has Remove: -DESP_PLATFORM, so native
unit-test files continue to compile without the flag.
* revert(clangd): remove incorrect -DESP_PLATFORM from global CompileFlags
Adding -DESP_PLATFORM globally caused 'too many errors' in src/ files
because compile_commands.json was generated from the native env and
lacked all ESP-IDF/Xtensa include paths.
The correct fix is to generate compile_commands.json from a device env:
./scripts/generate_compiledb.sh sticks3
This populates the DB with proper -DESP_PLATFORM and all IDF includes
for every src/ translation unit. The symlink at the project root then
points clangd to the right compilation context.
fix(test): configure clangd and clang-tidy for native test tree (#3)
* fix(test): configure clangd and clang-tidy for native test tree
- Generate compile_commands.json from pio run -e native -t compiledb
so clangd resolves src/ headers in test files without errors.
- Fix .clangd PathMatch regex (relative path, not absolute) and add
-I.pio/build/native/unity_config so unity_config.h resolves.
- Remove overly broad Remove: -I* that was stripping all added paths.
- Add -Wno-format-security and UnusedIncludes: None to test block.
- Add test/.clang-tidy that inherits the root config and:
- Allows test_* functions to use snake_case (FunctionIgnoredRegexp)
- Disables cert-err33-c, cert-dcl50-cpp,
cppcoreguidelines-pro-type-cstyle-cast,
bugprone-argument-comment, bugprone-misplaced-widening-cast,
bugprone-implicit-widening-of-multiplication-result,
misc-unused-using-decls — all false positives in test context.
- Add /* intentionally empty */ comment to all empty setUp()/tearDown()
bodies (28 files) to suppress SonarLint c:S1186.
- Fix test_vault_task: change relative include ../../src/vault/vault_task.h
to vault/vault_task.h (consistent with all other test files; -Isrc
already in compile flags).
- Reorganise test/ into a module-mirroring subtree layout:
test/ble/, test/crypto/, test/hal/, test/ota/, test/platform/,
test/states/, test/totp/, test/ui/, test/vault/, test/web/
(old flat directories removed).
- Add sonar-project.properties exclusion e4: suppress c:S1186 on
test/**/*.cpp at SonarCloud level.
All 468 native unit tests pass (pio test -e native).
* fix(clangd): add -DESP_PLATFORM to global CompileFlags
All Kleidos targets are ESP32/ESP32-S3 (framework = espidf), so
ESP_PLATFORM is always defined at compile time. Without this flag in
the clangd config, the language server was activating #else branches
inside #ifdef ESP_PLATFORM blocks, hiding device code and showing
false diagnostics for src/ files.
The test/** fragment already has Remove: -DESP_PLATFORM, so native
unit-test files continue to compile without the flag.
* revert(clangd): remove incorrect -DESP_PLATFORM from global CompileFlags
Adding -DESP_PLATFORM globally caused 'too many errors' in src/ files
because compile_commands.json was generated from the native env and
lacked all ESP-IDF/Xtensa include paths.
The correct fix is to generate compile_commands.json from a device env:
./scripts/generate_compiledb.sh sticks3
This populates the DB with proper -DESP_PLATFORM and all IDF includes
for every src/ translation unit. The symlink at the project root then
points clangd to the right compilation context.
Make the credential the full object the owner defined, everywhere
The ruling: a credential is user + password + web + notes + TOTP, the web
admin is the superset surface, and no surface may destroy what another
one wrote. This lands the investigation's NOW tier end to end.
The seam that closes a bug class: VaultStore::saveCredential now
read-modify-writes the stored extras, so a bare save from ANY surface —
the portal form, the device editors, a future caller — preserves notes,
brand and the embedded TOTP instead of silently rebuilding the record
from defaults. The portal edit no longer wipes notes (the GET now emits
them — behind the same X-Confirm-Plaintext consent as the password,
since notes hold recovery codes), and the device editors were moved off
the destructive path.
The TOTP write path exists at last: POST /api/credentials accepts an
optional totp object (base32 or a full otpauth:// URI; explicit null
detaches), the SPA credential form gains its 2FA section, and standalone
and embedded TOTP convert both ways. TOTP records gain an algorithm byte
(SHA-1 default, SHA-256 for the issuers that mandate it) verified
against the RFC 6238 Appendix B vectors, and every generate() call site
passes it.
Backups stop lying: exportAll/importAll round-trip the complete record —
notes, embedded TOTP, favorite, order, brand, timestamps — so the
portable paths (/api/backup, .kexp, SD) finally match what the page
promises. Credential saves stamp ctime/mtime from the trusted epoch when
the clock deserves it.
The 1Password import is real: the SPA import wizard parses .1pux in the
browser (a self-contained ZIP walker over DecompressionStream — the
12 MB export never touches the device; only export.data is read) and
vendor CSVs (1P8's Url header now matches; OTPAuth/Notes/Favorite/
Archived columns mapped), previews with per-vault selection, capacity
metering, dedup marks and an archived-skip toggle, then uploads through
the new POST /api/import/items — a merge importer that batches 32 items,
generates 20-character passwords on-device for passwordless rows when
asked, and reports per-item outcomes. Two flows that were dead on real
hardware come back with one-line fixes each: rekey read "new" where the
page sends "next", encrypted restore read X-Export-Passphrase where the
page sends X-Backup-Pass.
The drift class those two bugs belong to now has a test: qa/tests/portal/
test_spa_contract.py walks every SPA fetch against the firmware route
table, the mock and a key-name fixture (17 checks). The fixtures' two
documented drift entries were resolved the way they demanded.
The compressed-SPA budget rises to 64 KB by owner decision — the portal
is the device's full-featured surface now, and even the tightest 4 MB
board carries it with room (all five representative builds pass,
including both classic-ESP32 debug canaries).
Native: 2758/2758. Contract: 17/17. Builds: sticks3_debug, tdeck,
cardputer, m5stickc_plus1_debug, core2_v13_debug. Guards and hooks green.
Claude-Session: https://claude.ai/code/session_01Q2J5gQSFMTDLVzPUYog51r