Text file src/cmd/go/testdata/script/mod_download_toolchain_gosum.txt

     1  # A matching line in go.sum must not bypass checksum database verification
     2  # for a downloaded toolchain, since useSumDB requires the checksum database
     3  # for golang.org/toolchain even when GOSUMDB=off.
     4  
     5  env GOTOOLCHAIN=local
     6  env sumdb=$GOSUMDB
     7  env proxy=$GOPROXY
     8  env dbname=localhost.localdev/sumdb
     9  
    10  go get golang.org/toolchain@v0.0.1-go1.999testmod.$GOOS-$GOARCH
    11  grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]* h1:' go.sum
    12  grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]*/go.mod h1:' go.sum
    13  
    14  # With the checksum database disabled, the matching go.sum entry
    15  # must not be accepted on its own.
    16  env GOSUMDB=off
    17  ! go mod download golang.org/toolchain
    18  stderr 'checksum database disabled by GOSUMDB=off'
    19  
    20  # With a checksum database that disagrees with go.sum, the download
    21  # must be rejected even though go.sum matches the downloaded bits.
    22  # Clear cached lookups and the cached tree head so the server is consulted.
    23  go clean -modcache
    24  rm $GOPATH/pkg/sumdb/$dbname/latest
    25  env GOSUMDB=$sumdb' '$proxy/sumdb-wrong
    26  ! go mod download golang.org/toolchain
    27  stderr 'verifying (module|go.mod): checksum mismatch'
    28  stderr 'localhost.localdev/sumdb: h1:wrong'
    29  stderr 'SECURITY ERROR'
    30  
    31  -- go.mod --
    32  module example.com/m
    33  
    34  go 1.21
    35  

View as plain text