Text file
src/cmd/go/testdata/script/mod_download_toolchain_gosum.txt
1 # A matching line in go.sum must not bypass checksum database verification
2 # for a downloaded toolchain, since useSumDB requires the checksum database
3 # for golang.org/toolchain even when GOSUMDB=off.
4
5 env GOTOOLCHAIN=local
6 env sumdb=$GOSUMDB
7 env proxy=$GOPROXY
8 env dbname=localhost.localdev/sumdb
9
10 go get golang.org/toolchain@v0.0.1-go1.999testmod.$GOOS-$GOARCH
11 grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]* h1:' go.sum
12 grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]*/go.mod h1:' go.sum
13
14 # With the checksum database disabled, the matching go.sum entry
15 # must not be accepted on its own.
16 env GOSUMDB=off
17 ! go mod download golang.org/toolchain
18 stderr 'checksum database disabled by GOSUMDB=off'
19
20 # With a checksum database that disagrees with go.sum, the download
21 # must be rejected even though go.sum matches the downloaded bits.
22 # Clear cached lookups and the cached tree head so the server is consulted.
23 go clean -modcache
24 rm $GOPATH/pkg/sumdb/$dbname/latest
25 env GOSUMDB=$sumdb' '$proxy/sumdb-wrong
26 ! go mod download golang.org/toolchain
27 stderr 'verifying (module|go.mod): checksum mismatch'
28 stderr 'localhost.localdev/sumdb: h1:wrong'
29 stderr 'SECURITY ERROR'
30
31 -- go.mod --
32 module example.com/m
33
34 go 1.21
35
View as plain text