# test: mock the OS keyring in the cli package TestMain

`1ea54e2`→[main](/content/gh/entireio/cli/commits/main/index.html)·

Soph·1mo ago·1 file·+9 added/-0 removed

The cli package's TestMain never routed go-keyring to its in-memory mock,
unlike the auth subpackage. The default tokenstore backend is the real OS
keychain, so any cli test that reaches a credential path without
UseFileBackendForTesting — or runs in the window after such a test restores
the global backend — would read the developer's real keychain and trigger a
macOS unlock prompt during `mise run test:ci`.

Call keyring.MockInit() once in TestMain so no cli test can touch the real
keychain, mirroring cmd/entire/cli/auth's TestMain.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

## Sessions

eb9e9029effeView transcript

## Changes

1

- cmd/entire/cli

- Mglobal_test.go+9

```
6 unmodified lines

7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24

6 unmodified lines

"github.com/go-git/go-git/v6/x/plugin"
	"github.com/go-git/go-git/v6/x/plugin/config"
	"github.com/zalando/go-keyring"

func TestMain(m *testing.M) {
	// Route the OS keyring to an in-memory mock for the whole package. The
	// default tokenstore backend is the real OS keychain, so any test that
	// reaches a credential path without UseFileBackendForTesting — or in the
	// window after such a test restores the backend — would otherwise read the
	// developer's real keychain and trigger a macOS unlock prompt. Mirrors the
	// auth subpackage's TestMain.
	keyring.MockInit()

// Register a default ConfigSource so tests that call ConfigScoped
	// (directly or indirectly via Commit/CreateTag) don't fail with
	// "no config loader registered".
```
