Text file src/cmd/go/testdata/script/gotoolchain_switch_gosum.txt

     1  # A toolchain switch triggered by a dependency must verify the downloaded
     2  # toolchain against the checksum database, even when the main module's go.sum
     3  # already lists a matching entry for golang.org/toolchain.
     4  
     5  [!exec:/bin/sh] skip 'the fake proxy serves shell scripts instead of binaries'
     6  env TESTGO_VERSION=go1.21.0
     7  env GOTOOLCHAIN=local
     8  env sumdb=$GOSUMDB
     9  env proxy=$GOPROXY
    10  env dbname=localhost.localdev/sumdb
    11  
    12  # Record the toolchain in go.sum, then drop it from go.mod so that only
    13  # the go.sum line remains, as it would in an attacker-supplied repository.
    14  go get golang.org/toolchain@v0.0.1-go1.999testmod.$GOOS-$GOARCH
    15  go mod edit -droprequire golang.org/toolchain
    16  grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]* h1:' go.sum
    17  go mod edit -require rsc.io/future@v1.0.0
    18  
    19  # Point at a checksum database that disagrees with go.sum and the download.
    20  # GONOSUMDB keeps rsc.io/future out of the way; it does not apply to the toolchain.
    21  # Clear cached lookups and the cached tree head so the server is consulted.
    22  go clean -modcache
    23  rm $GOPATH/pkg/sumdb/$dbname/latest
    24  env GOTOOLCHAIN=auto
    25  env GONOSUMDB=rsc.io
    26  env GOSUMDB=$sumdb' '$proxy/sumdb-wrong
    27  ! go get .
    28  stderr 'switching to go1.999testmod'
    29  stderr 'golang.org/toolchain@v0.0.1-go1.999testmod.[a-z0-9\-]*: verifying (module|go.mod): checksum mismatch'
    30  stderr 'localhost.localdev/sumdb: h1:wrong'
    31  stderr 'SECURITY ERROR'
    32  
    33  -- go.mod --
    34  module example
    35  
    36  go 1.21
    37  -- example.go --
    38  package example
    39  
    40  import _ "rsc.io/future"
    41  

View as plain text