fetch: destination directory, skip files already present, save the manifest, require a signer (closes #101)
check / check (push) Failing after 3s
check / check (push) Failing after 3s
fetch takes --dest (default .) and writes every file there through the existing symlink and hard-link guards, which now work relative to that directory. A file already there with the listed size and hash is skipped; a leftover temp file is still replaced. Once every file verifies, the manifest is saved as index.mf through the same temp file and rename, so check runs on the result; a manifest that lists index.mf or its temp name at the top of the tree is refused, since saving would replace that file. --require-signature is shared with check and enforced through verifyRequiredSigner. Both refusals come before any file is downloaded or anything is written. Model: opus-5-5
This commit was merged in pull request #150.
This commit is contained in:
+22
-12
@@ -111,9 +111,10 @@ func TestVerifyRequiredSignerMessages(t *testing.T) {
|
||||
// string; the required signer is a fixed value that cannot match it. Requires
|
||||
// gpg and is skipped where it is absent, as the other signing tests are.
|
||||
//
|
||||
//nolint:paralleltest // signedChecker calls t.Setenv, which bars t.Parallel
|
||||
//nolint:paralleltest // signedManifest calls t.Setenv, which bars t.Parallel
|
||||
func TestSignerMismatchMessage(t *testing.T) {
|
||||
chk := signedChecker(t)
|
||||
chk := signedChecker(t,
|
||||
signedManifest(t, map[string][]byte{"f.txt": []byte("signed file")}))
|
||||
|
||||
embeddedFP, err := chk.ExtractEmbeddedSigningKeyFP(context.Background())
|
||||
require.NoError(t, err)
|
||||
@@ -125,9 +126,10 @@ func TestSignerMismatchMessage(t *testing.T) {
|
||||
" does not match required "+msgFpB)
|
||||
}
|
||||
|
||||
// signedChecker builds a Checker over a manifest signed by a throwaway GPG
|
||||
// key generated in a temporary GNUPGHOME.
|
||||
func signedChecker(t *testing.T) *mfer.Checker {
|
||||
// signedManifest returns a manifest of files signed by a throwaway GPG key
|
||||
// generated in a temporary GNUPGHOME, which it leaves set for the rest of
|
||||
// the test.
|
||||
func signedManifest(t *testing.T, files map[string][]byte) []byte {
|
||||
t.Helper()
|
||||
|
||||
_, err := exec.LookPath("gpg")
|
||||
@@ -159,17 +161,25 @@ func signedChecker(t *testing.T) *mfer.Checker {
|
||||
b := mfer.NewBuilder()
|
||||
b.SetSigningOptions(&mfer.SigningOptions{KeyID: mfer.GPGKeyID("test@mfer.test")})
|
||||
|
||||
content := []byte("signed file")
|
||||
_, err = b.AddFile("f.txt", mfer.FileSize(len(content)), mfer.ModTime{},
|
||||
bytes.NewReader(content), nil)
|
||||
require.NoError(t, err)
|
||||
for path, content := range files {
|
||||
_, err = b.AddFile(mfer.RelFilePath(path), mfer.FileSize(len(content)),
|
||||
mfer.ModTime{}, bytes.NewReader(content), nil)
|
||||
require.NoError(t, err)
|
||||
}
|
||||
|
||||
var buf bytes.Buffer
|
||||
|
||||
require.NoError(t, b.Build(context.Background(), &buf))
|
||||
|
||||
return buf.Bytes()
|
||||
}
|
||||
|
||||
// signedChecker builds a Checker over manifest, a signed manifest.
|
||||
func signedChecker(t *testing.T, manifest []byte) *mfer.Checker {
|
||||
t.Helper()
|
||||
|
||||
fs := afero.NewMemMapFs()
|
||||
require.NoError(t, afero.WriteFile(fs, "/index.mf", buf.Bytes(), 0o644))
|
||||
require.NoError(t, afero.WriteFile(fs, "/index.mf", manifest, 0o644))
|
||||
|
||||
chk, err := mfer.NewChecker(&mfer.CheckerOptions{
|
||||
ManifestPath: "/index.mf",
|
||||
@@ -300,7 +310,7 @@ func TestFetchFileHTTPStatusMessage(t *testing.T) {
|
||||
|
||||
// downloadFile logs each retry of the 500 to the process-global logger.
|
||||
err := runLocked(func() error {
|
||||
return downloadFile(context.Background(), testClient(), server.URL+"/x", "x",
|
||||
return downloadFile(context.Background(), testClient(), server.URL+"/x", ".", "x",
|
||||
&mfer.MFFilePath{}, nil)
|
||||
})
|
||||
require.ErrorIs(t, err, errHTTPStatus)
|
||||
@@ -355,7 +365,7 @@ func TestSizeMismatchMessage(t *testing.T) {
|
||||
|
||||
// finishDownload returns the size-mismatch error before it touches the
|
||||
// paths, digest, or entry, so those can be zero here.
|
||||
err := finishDownload("", "", 9, 10, nil, nil, nil, nil)
|
||||
err := finishDownload("", "", "", 9, 10, nil, nil, nil, nil)
|
||||
require.ErrorIs(t, err, errSizeMismatch)
|
||||
assert.EqualError(t, err, "size mismatch: expected 10 bytes, got 9")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user