1 # A toolchain switch triggered by a dependency must verify the downloaded
2 # toolchain against the checksum database, even when the main module's go.sum
3 # already lists a matching entry for golang.org/toolchain.
4
5 [!exec:/bin/sh] skip 'the fake proxy serves shell scripts instead of binaries'
6 env TESTGO_VERSION=go1.21.0
7 env GOTOOLCHAIN=local
8 env sumdb=$GOSUMDB
9 env proxy=$GOPROXY
10 env dbname=localhost.localdev/sumdb
11
12 # Record the toolchain in go.sum, then drop it from go.mod so that only
13 # the go.sum line remains, as it would in an attacker-supplied repository.
14 go get golang.org/toolchain@v0.0.1-go1.999testmod.$GOOS-$GOARCH
15 go mod edit -droprequire golang.org/toolchain
16 grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]* h1:' go.sum
17 go mod edit -require rsc.io/future@v1.0.0
18
19 # Point at a checksum database that disagrees with go.sum and the download.
20 # GONOSUMDB keeps rsc.io/future out of the way; it does not apply to the toolchain.
21 # Clear cached lookups and the cached tree head so the server is consulted.
22 go clean -modcache
23 rm $GOPATH/pkg/sumdb/$dbname/latest
24 env GOTOOLCHAIN=auto
25 env GONOSUMDB=rsc.io
26 env GOSUMDB=$sumdb' '$proxy/sumdb-wrong
27 ! go get .
28 stderr 'switching to go1.999testmod'
29 stderr 'golang.org/toolchain@v0.0.1-go1.999testmod.[a-z0-9\-]*: verifying (module|go.mod): checksum mismatch'
30 stderr 'localhost.localdev/sumdb: h1:wrong'
31 stderr 'SECURITY ERROR'
32
33 -- go.mod --
34 module example
35
36 go 1.21
37 -- example.go --
38 package example
39
40 import _ "rsc.io/future"
41
View as plain text