Text file src/cmd/go/testdata/script/fipssnap_modcache.txt

     1  # The module cache copy of a FIPS snapshot is used only if the module
     2  # cache records the module zip hash from GOROOT/lib/fips140/fips140.sum
     3  # for it, the way downloaded modules are checked against go.sum.
     4  # Otherwise it is discarded and the snapshot is unpacked again.
     5  #
     6  # This detects a cache entry that was not unpacked from the bundled
     7  # snapshot (or whose hash record is missing). Like go.sum, it does not
     8  # protect the module cache from being modified in place: the replaced
     9  # source file below stands in for stale contents, not an attacker.
    10  
    11  env snap=v1.26.0
    12  env GOFIPS140=$snap
    13  env GOMODCACHE=$WORK/modcache
    14  env GOFLAGS=-modcacherw
    15  
    16  # Go+BoringCrypto conflicts with GOFIPS140.
    17  [GOEXPERIMENT:boringcrypto] skip
    18  
    19  env ziphash=$GOMODCACHE/cache/download/golang.org/fips140/@v/$snap.ziphash
    20  env srcfile=$GOMODCACHE/golang.org/fips140@$snap/fips140/$snap/sha256/sha256.go
    21  
    22  # unpacking the snapshot records its module zip hash in the module cache
    23  go list -f '{{.DefaultGODEBUG}}'
    24  stdout fips140=on
    25  exists $ziphash
    26  exists $srcfile
    27  grep '^h1:dtoPX1ALGGp4rMLzyh6oqIkYRXnXxRkpPWu56l5DFpM=$' $ziphash
    28  cp $ziphash good.ziphash
    29  
    30  # a recorded hash that does not match fips140.sum
    31  # discards the cached copy and unpacks the snapshot again
    32  cp bad.ziphash $ziphash
    33  rm $srcfile
    34  cp stale/sha256.go $srcfile
    35  go list -f '{{.DefaultGODEBUG}}'
    36  stdout fips140=on
    37  exists $srcfile
    38  ! grep stale $srcfile
    39  cmp $ziphash good.ziphash
    40  
    41  # so does a missing hash
    42  rm $ziphash
    43  rm $srcfile
    44  cp stale/sha256.go $srcfile
    45  go list -f '{{.DefaultGODEBUG}}'
    46  stdout fips140=on
    47  exists $srcfile
    48  ! grep stale $srcfile
    49  cmp $ziphash good.ziphash
    50  
    51  -- go.mod --
    52  module m
    53  -- x.go --
    54  package main
    55  import _ "crypto/sha256"
    56  func main() {
    57  }
    58  -- bad.ziphash --
    59  h1:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
    60  -- stale/sha256.go --
    61  package sha256 // stale
    62  

View as plain text