mirror of
https://github.com/go-admin-team/go-admin.git
synced 2026-09-22 18:37:43 +00:00
AfterListen promises a hook that the port answers. The bind was moved onto the caller's goroutine to keep that promise, but with ssl enabled there was a second way to fail after the announcement: ServeTLS reads the certificate files itself, on the serving goroutine, so a bad path or an unreadable key surfaced once the hooks had already run. tls.LoadX509KeyPair now runs before anything is announced, and its error is returned from startServing the way a failed bind is. ServeTLS still does the real work - handing it a tls.Listener built here instead would take over the HTTP/2 negotiation it sets up, and quietly drop h2 for every TLS deployment. The cost is one extra read of the certificate at startup. The fatal in the serving goroutine said "listen:". Neither the bind nor the certificate reaches it any more, so it says "serve:". The test covers the certificate path alongside the bind: neither may announce the phase, and neither may seal it. The counter-proof is not clean, and saying so is the point. Removing the check does turn the run red, but through log.Fatal killing the process from the serving goroutine - "fatal serve: open no-such.pem: no such file or directory" - rather than through the assertion. That still demonstrates the defect, because the process could only get there after startServing had returned successfully and the phase had been announced; it cannot be observed from inside the test, because the fatal races the assertion that would report it. Also: the redis-backed queue tests now fail instead of skipping when CI is set and GO_ADMIN_TEST_REDIS_ADDR is not. A workflow that renamed the variable or dropped the service would otherwise stay green while those two tests quietly did nothing - the same shape as the defect they exist to cover. Locally, with no CI in the environment, they still skip.