# A toolchain switch triggered by a dependency must verify the downloaded # toolchain against the checksum database, even when the main module's go.sum # already lists a matching entry for golang.org/toolchain. [!exec:/bin/sh] skip 'the fake proxy serves shell scripts instead of binaries' env TESTGO_VERSION=go1.21.0 env GOTOOLCHAIN=local env sumdb=$GOSUMDB env proxy=$GOPROXY env dbname=localhost.localdev/sumdb # Record the toolchain in go.sum, then drop it from go.mod so that only # the go.sum line remains, as it would in an attacker-supplied repository. go get golang.org/toolchain@v0.0.1-go1.999testmod.$GOOS-$GOARCH go mod edit -droprequire golang.org/toolchain grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]* h1:' go.sum go mod edit -require rsc.io/future@v1.0.0 # Point at a checksum database that disagrees with go.sum and the download. # GONOSUMDB keeps rsc.io/future out of the way; it does not apply to the toolchain. # Clear cached lookups and the cached tree head so the server is consulted. go clean -modcache rm $GOPATH/pkg/sumdb/$dbname/latest env GOTOOLCHAIN=auto env GONOSUMDB=rsc.io env GOSUMDB=$sumdb' '$proxy/sumdb-wrong ! go get . stderr 'switching to go1.999testmod' stderr 'golang.org/toolchain@v0.0.1-go1.999testmod.[a-z0-9\-]*: verifying (module|go.mod): checksum mismatch' stderr 'localhost.localdev/sumdb: h1:wrong' stderr 'SECURITY ERROR' -- go.mod -- module example go 1.21 -- example.go -- package example import _ "rsc.io/future"