Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ee49371459 |
@@ -23,9 +23,8 @@ javascript library is planned.
|
|||||||
|
|
||||||
# Build Status
|
# Build Status
|
||||||
|
|
||||||
CI runs `script/cibuild`, which builds the Docker image with `--no-cache`, so
|
CI runs via `script/cibuild` (`docker build .`), which executes `make check`
|
||||||
the formatting, lint and test steps in the `Dockerfile` run on every build. The
|
(formatting, linting, tests). The `main` branch must always be green.
|
||||||
`main` branch must always be green.
|
|
||||||
|
|
||||||
# Entrypoints
|
# Entrypoints
|
||||||
|
|
||||||
@@ -57,8 +56,8 @@ provide:
|
|||||||
Docker lint stage, whose image has no node
|
Docker lint stage, whose image has no node
|
||||||
- `script/check` — run `script/test`, `script/lint`, and `script/fmt-check`
|
- `script/check` — run `script/test`, `script/lint`, and `script/fmt-check`
|
||||||
- `script/docker` — build the Docker image tagged with the project name
|
- `script/docker` — build the Docker image tagged with the project name
|
||||||
- `script/cibuild` — CI entrypoint: builds the image with the same command as
|
- `script/cibuild` — CI entrypoint: `docker build .` (the Dockerfile runs the
|
||||||
`script/docker`, uncached, so the checks in the Dockerfile run every time
|
checks)
|
||||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then
|
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then
|
||||||
`script/check`
|
`script/check`
|
||||||
- `script/install-precommit` — install the git pre-commit hook that runs
|
- `script/install-precommit` — install the git pre-commit hook that runs
|
||||||
|
|||||||
@@ -24,12 +24,10 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-10-03: pinned the CLI error messages by driving the functions that emit
|
- 2026-10-03: every gpg run is killed after one minute or when its caller's
|
||||||
them in `internal/cli/errmsg_test.go`, and made the freshen mtime-presence
|
context ends, and a timeout reads as "gpg timed out" under the failing
|
||||||
test distinguish an absent mtime from the epoch (#87)
|
operation; `Builder.Build` and `Checker.ExtractEmbeddedSigningKeyFP` take a
|
||||||
- 2026-10-03: `script/cibuild` builds the image with the same command as
|
context, which reaches gpg (#62)
|
||||||
`script/docker`, `--no-cache` included, so the checks in the Dockerfile run on
|
|
||||||
every build, also on an unchanged tree (#89)
|
|
||||||
- 2026-10-03: `fetch` removes whatever sits at a file's temp name and then
|
- 2026-10-03: `fetch` removes whatever sits at a file's temp name and then
|
||||||
creates the temp file only if that name is free, so a hard link left there
|
creates the temp file only if that name is free, so a hard link left there
|
||||||
cannot make it write into a file outside the destination directory (#115)
|
cannot make it write into a file outside the destination directory (#115)
|
||||||
@@ -118,8 +116,7 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
|
|||||||
- Add decompression size limit via io.LimitReader in deserializeInner()
|
- Add decompression size limit via io.LimitReader in deserializeInner()
|
||||||
- Fix errors.Is dead code in checker; make AddFile verify totalRead == size
|
- Fix errors.Is dead code in checker; make AddFile verify totalRead == size
|
||||||
- Export manifest type or define a public interface (pending)
|
- Export manifest type or define a public interface (pending)
|
||||||
- Replace GPG subprocess with pure-Go crypto (pending); add timeouts to
|
- Replace GPG subprocess with pure-Go crypto (pending)
|
||||||
remaining subprocess calls
|
|
||||||
- CLI:
|
- CLI:
|
||||||
- Kebab-case primary flag names; fix fetch URL construction with
|
- Kebab-case primary flag names; fix fetch URL construction with
|
||||||
url.JoinPath; add http.Client timeout and retry with backoff to fetch;
|
url.JoinPath; add http.Client timeout and retry with backoff to fetch;
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
package cli
|
package cli
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
@@ -126,7 +127,9 @@ func (mfa *CLIApp) fetchManifestToTemp(url string) (string, error) {
|
|||||||
|
|
||||||
// verifyRequiredSigner enforces the --require-signature fingerprint
|
// verifyRequiredSigner enforces the --require-signature fingerprint
|
||||||
// against the manifest's embedded signing key.
|
// against the manifest's embedded signing key.
|
||||||
func verifyRequiredSigner(chk *mfer.Checker, requiredSigner string) error {
|
func verifyRequiredSigner(
|
||||||
|
ctx context.Context, chk *mfer.Checker, requiredSigner string,
|
||||||
|
) error {
|
||||||
// Validate fingerprint format: must be exactly 40 hex characters
|
// Validate fingerprint format: must be exactly 40 hex characters
|
||||||
if len(requiredSigner) != fingerprintHexLen {
|
if len(requiredSigner) != fingerprintHexLen {
|
||||||
return fmt.Errorf("%w, got %d", errInvalidFingerprint, len(requiredSigner))
|
return fmt.Errorf("%w, got %d", errInvalidFingerprint, len(requiredSigner))
|
||||||
@@ -145,7 +148,7 @@ func verifyRequiredSigner(chk *mfer.Checker, requiredSigner string) error {
|
|||||||
// Extract fingerprint from the embedded public key (not from the
|
// Extract fingerprint from the embedded public key (not from the
|
||||||
// signer field). This validates the key is importable and gets its
|
// signer field). This validates the key is importable and gets its
|
||||||
// actual fingerprint.
|
// actual fingerprint.
|
||||||
embeddedFP, err := chk.ExtractEmbeddedSigningKeyFP()
|
embeddedFP, err := chk.ExtractEmbeddedSigningKeyFP(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf(
|
return fmt.Errorf(
|
||||||
"failed to extract fingerprint from embedded signing key: %w", err)
|
"failed to extract fingerprint from embedded signing key: %w", err)
|
||||||
@@ -303,7 +306,7 @@ func (mfa *CLIApp) checkManifestOperation(ctx *cli.Context) error {
|
|||||||
// Check signature requirement
|
// Check signature requirement
|
||||||
requiredSigner := ctx.String("require-signature")
|
requiredSigner := ctx.String("require-signature")
|
||||||
if requiredSigner != "" {
|
if requiredSigner != "" {
|
||||||
err = verifyRequiredSigner(chk, requiredSigner)
|
err = verifyRequiredSigner(ctx.Context, chk, requiredSigner)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
+135
-320
@@ -2,352 +2,167 @@
|
|||||||
package cli
|
package cli
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"fmt"
|
||||||
"context"
|
|
||||||
"flag"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"os"
|
|
||||||
"os/exec"
|
|
||||||
"path/filepath"
|
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/spf13/afero"
|
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
"github.com/stretchr/testify/require"
|
"github.com/stretchr/testify/require"
|
||||||
urfcli "github.com/urfave/cli/v2"
|
|
||||||
"sneak.berlin/go/mfer/mfer"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// These tests pin the exact rendered text of the CLI's user-visible error
|
// errMsgCase is one pinned user-visible error message.
|
||||||
// messages. The messages are grepped for in CI pipelines and quoted in bug
|
type errMsgCase struct {
|
||||||
// reports, so a reword is a deliberate change, never a refactoring side
|
name string
|
||||||
// effect.
|
err error
|
||||||
//
|
want string
|
||||||
// Every case drives the real function that emits the message and asserts on
|
}
|
||||||
// what it returns. No production format string is restated here: a test that
|
|
||||||
// only re-rendered a copied format string would keep passing after the real
|
|
||||||
// message changed, which is exactly the regression these tests exist to
|
|
||||||
// catch.
|
|
||||||
|
|
||||||
// Full 40-hex fingerprints used where a message embeds one.
|
|
||||||
const (
|
const (
|
||||||
msgFpA = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
|
msgFpA = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
|
||||||
msgFpB = "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB"
|
msgFpB = "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB"
|
||||||
)
|
)
|
||||||
|
|
||||||
// runLocked runs fn while holding runMu, so operations that write to the
|
func checkErrMsgCases(t *testing.T, cases []errMsgCase) {
|
||||||
// process-global logger do not race the other CLI runs.
|
|
||||||
func runLocked(fn func() error) error {
|
|
||||||
runMu.Lock()
|
|
||||||
defer runMu.Unlock()
|
|
||||||
|
|
||||||
return fn()
|
|
||||||
}
|
|
||||||
|
|
||||||
// unsignedChecker builds a Checker over a freshly scanned, unsigned manifest.
|
|
||||||
func unsignedChecker(t *testing.T) *mfer.Checker {
|
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
fs := afero.NewMemMapFs()
|
for _, tc := range cases {
|
||||||
require.NoError(t, fs.MkdirAll("/d", 0o755))
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
require.NoError(t, afero.WriteFile(fs, "/d/f.txt", []byte("hi"), 0o644))
|
t.Parallel()
|
||||||
|
assert.Equal(t, tc.want, tc.err.Error())
|
||||||
s := mfer.NewScannerWithOptions(&mfer.ScannerOptions{Fs: fs})
|
})
|
||||||
require.NoError(t, s.EnumeratePath("/d", nil))
|
}
|
||||||
|
|
||||||
var buf bytes.Buffer
|
|
||||||
|
|
||||||
require.NoError(t, s.ToManifest(context.Background(), &buf, nil))
|
|
||||||
require.NoError(t, afero.WriteFile(fs, "/d/index.mf", buf.Bytes(), 0o644))
|
|
||||||
|
|
||||||
chk, err := mfer.NewChecker("/d/index.mf", "/d", fs)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.False(t, chk.IsSigned())
|
|
||||||
|
|
||||||
return chk
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNoManifestFoundMessage(t *testing.T) {
|
// TestErrorMessagesVerbatim pins the exact rendered text of the CLI's
|
||||||
t.Parallel()
|
// user-visible error messages.
|
||||||
|
|
||||||
_, err := findManifest(afero.NewMemMapFs(), "/tmp/x")
|
|
||||||
require.ErrorIs(t, err, errNoManifestFound)
|
|
||||||
assert.EqualError(t, err,
|
|
||||||
"no manifest found in /tmp/x (looked for index.mf and .index.mf)")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestVerifyRequiredSignerMessages(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
t.Run("invalid fingerprint length", func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
err := verifyRequiredSigner(unsignedChecker(t), "12345678")
|
|
||||||
require.ErrorIs(t, err, errInvalidFingerprint)
|
|
||||||
assert.EqualError(t, err,
|
|
||||||
"invalid fingerprint: must be exactly 40 hex characters, got 8")
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("manifest not signed", func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
err := verifyRequiredSigner(unsignedChecker(t), msgFpA)
|
|
||||||
require.ErrorIs(t, err, errManifestNotSigned)
|
|
||||||
assert.EqualError(t, err,
|
|
||||||
"manifest is not signed, but signature from "+msgFpA+" is required")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSignerMismatchMessage drives verifyRequiredSigner against a real signed
|
|
||||||
// manifest. The embedded fingerprint is whatever the generated key produced,
|
|
||||||
// so it is read back from the checker and substituted into the expected
|
|
||||||
// string; the required signer is a fixed value that cannot match it. Requires
|
|
||||||
// gpg and is skipped where it is absent, as the other signing tests are.
|
|
||||||
//
|
//
|
||||||
//nolint:paralleltest // signedChecker calls t.Setenv, which bars t.Parallel
|
// These strings are an interface: they are grepped for in CI pipelines
|
||||||
func TestSignerMismatchMessage(t *testing.T) {
|
// and quoted in bug reports. The messages are assembled by wrapping
|
||||||
chk := signedChecker(t)
|
// static sentinels, and it is easy to change what a user sees while
|
||||||
|
// only meaning to make an error matchable with errors.Is - which is
|
||||||
embeddedFP, err := chk.ExtractEmbeddedSigningKeyFP()
|
// precisely what happened once already. Any change to a string below is
|
||||||
require.NoError(t, err)
|
// therefore a deliberate, separately stated change, never a side effect
|
||||||
|
// of a refactor.
|
||||||
err = verifyRequiredSigner(chk, msgFpB)
|
func TestErrorMessagesVerbatim(t *testing.T) {
|
||||||
require.ErrorIs(t, err, errSignerMismatch)
|
|
||||||
assert.EqualError(t, err,
|
|
||||||
"embedded signing key fingerprint "+embeddedFP+
|
|
||||||
" does not match required "+msgFpB)
|
|
||||||
}
|
|
||||||
|
|
||||||
// signedChecker builds a Checker over a manifest signed by a throwaway GPG
|
|
||||||
// key generated in a temporary GNUPGHOME.
|
|
||||||
func signedChecker(t *testing.T) *mfer.Checker {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
_, err := exec.LookPath("gpg")
|
|
||||||
if err != nil {
|
|
||||||
t.Skip("gpg not installed, skipping signing test")
|
|
||||||
}
|
|
||||||
|
|
||||||
gpgHome := t.TempDir()
|
|
||||||
params := "%no-protection\n" +
|
|
||||||
"Key-Type: RSA\nKey-Length: 2048\n" +
|
|
||||||
"Name-Real: MFER Test Key\nName-Email: test@mfer.test\n" +
|
|
||||||
"Expire-Date: 0\n%commit\n"
|
|
||||||
paramsFile := filepath.Join(gpgHome, "key-params")
|
|
||||||
require.NoError(t, os.WriteFile(paramsFile, []byte(params), 0o600))
|
|
||||||
|
|
||||||
//nolint:gosec // paramsFile is a test-controlled path inside t.TempDir()
|
|
||||||
cmd := exec.CommandContext(context.Background(), "gpg",
|
|
||||||
"--batch", "--gen-key", paramsFile)
|
|
||||||
|
|
||||||
cmd.Env = append(os.Environ(), "GNUPGHOME="+gpgHome)
|
|
||||||
|
|
||||||
out, err := cmd.CombinedOutput()
|
|
||||||
if err != nil {
|
|
||||||
t.Skipf("failed to generate test GPG key: %v: %s", err, out)
|
|
||||||
}
|
|
||||||
|
|
||||||
t.Setenv("GNUPGHOME", gpgHome)
|
|
||||||
|
|
||||||
b := mfer.NewBuilder()
|
|
||||||
b.SetSigningOptions(&mfer.SigningOptions{KeyID: mfer.GPGKeyID("test@mfer.test")})
|
|
||||||
|
|
||||||
content := []byte("signed file")
|
|
||||||
_, err = b.AddFile("f.txt", mfer.FileSize(len(content)), mfer.ModTime{},
|
|
||||||
bytes.NewReader(content), nil)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
var buf bytes.Buffer
|
|
||||||
|
|
||||||
require.NoError(t, b.Build(&buf))
|
|
||||||
|
|
||||||
fs := afero.NewMemMapFs()
|
|
||||||
require.NoError(t, afero.WriteFile(fs, "/index.mf", buf.Bytes(), 0o644))
|
|
||||||
|
|
||||||
chk, err := mfer.NewChecker("/index.mf", "/", fs)
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.True(t, chk.IsSigned())
|
|
||||||
|
|
||||||
return chk
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestPathDoesNotExistMessage(t *testing.T) {
|
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
set := flag.NewFlagSet("gen", flag.ContinueOnError)
|
checkErrMsgCases(t, []errMsgCase{
|
||||||
require.NoError(t, set.Parse([]string{"nope"}))
|
{
|
||||||
|
name: "check: no manifest found",
|
||||||
mfa := &CLIApp{Fs: afero.NewMemMapFs()}
|
err: fmt.Errorf("%w in %s (looked for index.mf and .index.mf)",
|
||||||
ctx := urfcli.NewContext(nil, set, nil)
|
errNoManifestFound, "/tmp/x"),
|
||||||
|
want: "no manifest found in /tmp/x " +
|
||||||
_, err := mfa.collectInputPaths(ctx.Args())
|
"(looked for index.mf and .index.mf)",
|
||||||
require.ErrorIs(t, err, errPathNotExist)
|
},
|
||||||
assert.EqualError(t, err, "path does not exist: nope")
|
{
|
||||||
}
|
name: "check: invalid fingerprint length",
|
||||||
|
err: fmt.Errorf("%w, got %d", errInvalidFingerprint, 8),
|
||||||
func TestOutputFileExistsMessage(t *testing.T) {
|
want: "invalid fingerprint: must be exactly 40 hex characters, got 8",
|
||||||
t.Parallel()
|
},
|
||||||
|
{
|
||||||
fs := afero.NewMemMapFs()
|
name: "check: manifest not signed",
|
||||||
require.NoError(t, fs.MkdirAll("/d", 0o755))
|
err: fmt.Errorf("%w, but signature from %s is required",
|
||||||
require.NoError(t, afero.WriteFile(fs, "/d/f.txt", []byte("hi"), 0o644))
|
errManifestNotSigned, msgFpA),
|
||||||
require.NoError(t, afero.WriteFile(fs, "/out.mf", []byte("old"), 0o644))
|
want: "manifest is not signed, but signature from " + msgFpA +
|
||||||
|
" is required",
|
||||||
set := flag.NewFlagSet("gen", flag.ContinueOnError)
|
},
|
||||||
set.String("output", "", "")
|
{
|
||||||
set.Bool("force", false, "")
|
name: "check: signer mismatch",
|
||||||
require.NoError(t, set.Parse([]string{"/d"}))
|
err: fmt.Errorf("embedded signing key fingerprint %s %w %s",
|
||||||
require.NoError(t, set.Set("output", "/out.mf"))
|
msgFpA, errSignerMismatch, msgFpB),
|
||||||
|
want: "embedded signing key fingerprint " + msgFpA +
|
||||||
mfa := &CLIApp{Fs: fs}
|
" does not match required " + msgFpB,
|
||||||
ctx := urfcli.NewContext(nil, set, nil)
|
},
|
||||||
|
{
|
||||||
// generateManifestOperation writes to the process-global logger during
|
name: "gen: path does not exist",
|
||||||
// enumeration, so serialize with the other CLI runs.
|
err: fmt.Errorf("%w: %s", errPathNotExist, "nope"),
|
||||||
err := runLocked(func() error { return mfa.generateManifestOperation(ctx) })
|
want: "path does not exist: nope",
|
||||||
require.ErrorIs(t, err, errOutputExists)
|
},
|
||||||
assert.EqualError(t, err,
|
{
|
||||||
"output file /out.mf already exists (use --force to overwrite)")
|
name: "gen: output file exists",
|
||||||
}
|
err: fmt.Errorf("output file %s %w", "index.mf", errOutputExists),
|
||||||
|
want: "output file index.mf already exists " +
|
||||||
// TestUnknownCommandMessage drives the root command's action. run only logs
|
"(use --force to overwrite)",
|
||||||
// the error that action returns, so the test lets run build the app with no
|
},
|
||||||
// command given and then runs that same app on an unknown command to get the
|
{
|
||||||
// error itself.
|
name: "mfer: unknown command",
|
||||||
func TestUnknownCommandMessage(t *testing.T) {
|
err: fmt.Errorf("%w %q", errUnknownCommand, "bogus"),
|
||||||
t.Parallel()
|
want: `unknown command "bogus"`,
|
||||||
|
},
|
||||||
mfa := &CLIApp{
|
|
||||||
appname: testApp,
|
|
||||||
Stdout: &bytes.Buffer{},
|
|
||||||
Stderr: &bytes.Buffer{},
|
|
||||||
Fs: afero.NewMemMapFs(),
|
|
||||||
}
|
|
||||||
|
|
||||||
// run points the process-global logger at this app's output, so
|
|
||||||
// serialize with the other CLI runs.
|
|
||||||
err := runLocked(func() error {
|
|
||||||
mfa.run([]string{testApp})
|
|
||||||
|
|
||||||
return mfa.app.Run([]string{testApp, "bogus"})
|
|
||||||
})
|
|
||||||
require.ErrorIs(t, err, errUnknownCommand)
|
|
||||||
assert.EqualError(t, err, `unknown command "bogus"`)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestManifestLoaderHTTPStatusMessage(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
server := httptest.NewServer(
|
|
||||||
http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusNotFound)
|
|
||||||
}))
|
|
||||||
defer server.Close()
|
|
||||||
|
|
||||||
mfa := &CLIApp{Fs: afero.NewMemMapFs()}
|
|
||||||
|
|
||||||
_, err := mfa.openManifestReader(server.URL + "/foo.mf")
|
|
||||||
require.ErrorIs(t, err, errHTTPStatus)
|
|
||||||
assert.EqualError(t, err,
|
|
||||||
"failed to fetch "+server.URL+"/foo.mf: HTTP 404")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFetchManifestHTTPStatusMessage(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
server := httptest.NewServer(
|
|
||||||
http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusNotFound)
|
|
||||||
}))
|
|
||||||
defer server.Close()
|
|
||||||
|
|
||||||
set := flag.NewFlagSet("fetch", flag.ContinueOnError)
|
|
||||||
require.NoError(t, set.Parse([]string{server.URL}))
|
|
||||||
|
|
||||||
mfa := &CLIApp{Fs: afero.NewMemMapFs()}
|
|
||||||
ctx := urfcli.NewContext(nil, set, nil)
|
|
||||||
|
|
||||||
// fetchManifestOperation logs to the process-global logger.
|
|
||||||
err := runLocked(func() error { return mfa.fetchManifestOperation(ctx) })
|
|
||||||
require.ErrorIs(t, err, errHTTPStatus)
|
|
||||||
assert.EqualError(t, err, "failed to fetch manifest: HTTP 404")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFetchFileHTTPStatusMessage(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
server := httptest.NewServer(
|
|
||||||
http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusInternalServerError)
|
|
||||||
}))
|
|
||||||
defer server.Close()
|
|
||||||
|
|
||||||
err := downloadFile(context.Background(), server.URL+"/x", "x",
|
|
||||||
&mfer.MFFilePath{}, nil)
|
|
||||||
require.ErrorIs(t, err, errHTTPStatus)
|
|
||||||
assert.EqualError(t, err, "HTTP 500")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestURLRequiredMessage(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
set := flag.NewFlagSet("fetch", flag.ContinueOnError)
|
|
||||||
require.NoError(t, set.Parse([]string{}))
|
|
||||||
|
|
||||||
mfa := &CLIApp{Fs: afero.NewMemMapFs()}
|
|
||||||
ctx := urfcli.NewContext(nil, set, nil)
|
|
||||||
|
|
||||||
// fetchManifestOperation logs to the process-global logger.
|
|
||||||
err := runLocked(func() error { return mfa.fetchManifestOperation(ctx) })
|
|
||||||
require.ErrorIs(t, err, errURLRequired)
|
|
||||||
assert.EqualError(t, err, "URL argument required")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSanitizePathMessages(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
t.Run("empty", func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
_, err := sanitizePath("")
|
|
||||||
require.ErrorIs(t, err, errEmptyPath)
|
|
||||||
assert.EqualError(t, err, "empty path")
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("absolute", func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
_, err := sanitizePath("/etc/passwd")
|
|
||||||
require.ErrorIs(t, err, errAbsolutePath)
|
|
||||||
assert.EqualError(t, err, "absolute path not allowed: /etc/passwd")
|
|
||||||
})
|
|
||||||
|
|
||||||
t.Run("traversal", func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
_, err := sanitizePath("../x")
|
|
||||||
require.ErrorIs(t, err, errPathTraversal)
|
|
||||||
assert.EqualError(t, err, "path traversal not allowed: ../x")
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestSizeMismatchMessage(t *testing.T) {
|
// TestFetchErrorMessagesVerbatim pins the fetch and manifest-loader
|
||||||
|
// messages; see TestErrorMessagesVerbatim for why.
|
||||||
|
func TestFetchErrorMessagesVerbatim(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
// finishDownload returns the size-mismatch error before it touches the
|
checkErrMsgCases(t, []errMsgCase{
|
||||||
// paths, digest, or entry, so those can be zero here.
|
{
|
||||||
err := finishDownload("", "", 9, 10, nil, nil, nil, nil)
|
name: "manifest_loader: http status",
|
||||||
require.ErrorIs(t, err, errSizeMismatch)
|
err: fmt.Errorf("failed to fetch %s: %w %d",
|
||||||
assert.EqualError(t, err, "size mismatch: expected 10 bytes, got 9")
|
"https://example.com/index.mf", errHTTPStatus, 404),
|
||||||
|
want: "failed to fetch https://example.com/index.mf: HTTP 404",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: manifest http status",
|
||||||
|
err: fmt.Errorf("failed to fetch manifest: %w %d",
|
||||||
|
errHTTPStatus, 404),
|
||||||
|
want: "failed to fetch manifest: HTTP 404",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: file http status",
|
||||||
|
err: fmt.Errorf("%w %d", errHTTPStatus, 500),
|
||||||
|
want: "HTTP 500",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: empty path",
|
||||||
|
err: errEmptyPath,
|
||||||
|
want: "empty path",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: absolute path",
|
||||||
|
err: fmt.Errorf("%w: %s", errAbsolutePath, "/etc/passwd"),
|
||||||
|
want: "absolute path not allowed: /etc/passwd",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: path traversal",
|
||||||
|
err: fmt.Errorf("%w: %s", errPathTraversal, "../x"),
|
||||||
|
want: "path traversal not allowed: ../x",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: size mismatch",
|
||||||
|
err: fmt.Errorf("%w: expected %d bytes, got %d",
|
||||||
|
errSizeMismatch, 10, 9),
|
||||||
|
want: "size mismatch: expected 10 bytes, got 9",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: url required",
|
||||||
|
err: errURLRequired,
|
||||||
|
want: "URL argument required",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "fetch: hash mismatch",
|
||||||
|
err: errHashMismatch,
|
||||||
|
want: "hash mismatch",
|
||||||
|
},
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestHashMismatchMessage(t *testing.T) {
|
// TestSentinelsAreMatchable checks that the wrapped forms of the
|
||||||
|
// messages above remain matchable with errors.Is, which is the reason
|
||||||
|
// the sentinels exist at all.
|
||||||
|
func TestSentinelsAreMatchable(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
// A 32-byte digest that matches none of the (empty) manifest hashes.
|
wrapped := fmt.Errorf("embedded signing key fingerprint %s %w %s",
|
||||||
err := verifyDownloadedHash(make([]byte, 32), &mfer.MFFilePath{})
|
"a", errSignerMismatch, "b")
|
||||||
require.ErrorIs(t, err, errHashMismatch)
|
require.ErrorIs(t, wrapped, errSignerMismatch)
|
||||||
require.NotErrorIs(t, err, errSizeMismatch)
|
|
||||||
assert.EqualError(t, err, "hash mismatch")
|
wrapped = fmt.Errorf("output file %s %w", "index.mf", errOutputExists)
|
||||||
|
require.ErrorIs(t, wrapped, errOutputExists)
|
||||||
|
|
||||||
|
wrapped = fmt.Errorf("failed to fetch manifest: %w %d", errHTTPStatus, 404)
|
||||||
|
require.ErrorIs(t, wrapped, errHTTPStatus)
|
||||||
|
|
||||||
|
assert.NotErrorIs(t, errHashMismatch, errSizeMismatch)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
package cli
|
package cli
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
@@ -304,7 +305,7 @@ func (h *freshenHasher) processEntry(e *freshenEntry) error {
|
|||||||
// writeFreshenedManifest writes the manifest atomically (write to a
|
// writeFreshenedManifest writes the manifest atomically (write to a
|
||||||
// temp file, then rename over the target).
|
// temp file, then rename over the target).
|
||||||
func writeFreshenedManifest(
|
func writeFreshenedManifest(
|
||||||
afs afero.Fs, builder *mfer.Builder, manifestPath string,
|
ctx context.Context, afs afero.Fs, builder *mfer.Builder, manifestPath string,
|
||||||
) error {
|
) error {
|
||||||
tmpPath := manifestPath + ".tmp"
|
tmpPath := manifestPath + ".tmp"
|
||||||
|
|
||||||
@@ -313,7 +314,7 @@ func writeFreshenedManifest(
|
|||||||
return fmt.Errorf("failed to create temp file: %w", err)
|
return fmt.Errorf("failed to create temp file: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
err = builder.Build(outFile)
|
err = builder.Build(ctx, outFile)
|
||||||
_ = outFile.Close()
|
_ = outFile.Close()
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -530,7 +531,7 @@ func (mfa *CLIApp) freshenManifestOperation(ctx *cli.Context) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Write updated manifest atomically (write to temp, then rename)
|
// Write updated manifest atomically (write to temp, then rename)
|
||||||
err = writeFreshenedManifest(mfa.Fs, hasher.builder, manifestPath)
|
err = writeFreshenedManifest(ctx.Context, mfa.Fs, hasher.builder, manifestPath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -110,10 +110,7 @@ func TestFreshenRecordEntryMtimePresence(t *testing.T) {
|
|||||||
|
|
||||||
const relPath = "file1.txt"
|
const relPath = "file1.txt"
|
||||||
|
|
||||||
// The scanned file's mtime is the Unix epoch. If recordEntry ever misreads
|
mtime := time.Unix(1_700_000_000, 0)
|
||||||
// an absent manifest mtime as the epoch, the "absent" case below would
|
|
||||||
// compare equal to this and be classified unchanged, so the test fails.
|
|
||||||
mtime := time.Unix(0, 0)
|
|
||||||
info := stubFileInfo{size: 8, mtime: mtime}
|
info := stubFileInfo{size: 8, mtime: mtime}
|
||||||
|
|
||||||
for _, tc := range []struct {
|
for _, tc := range []struct {
|
||||||
|
|||||||
+6
-4
@@ -3,6 +3,7 @@
|
|||||||
package mfer
|
package mfer
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
@@ -281,8 +282,9 @@ func (b *Builder) SetSigningOptions(opts *SigningOptions) {
|
|||||||
b.signingOptions = opts
|
b.signingOptions = opts
|
||||||
}
|
}
|
||||||
|
|
||||||
// Build finalizes the manifest and writes it to the writer.
|
// Build finalizes the manifest and writes it to the writer. ctx bounds the
|
||||||
func (b *Builder) Build(w io.Writer) error {
|
// gpg runs that sign the manifest when signing options are set.
|
||||||
|
func (b *Builder) Build(ctx context.Context, w io.Writer) error {
|
||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
|
|
||||||
@@ -308,13 +310,13 @@ func (b *Builder) Build(w io.Writer) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Generate outer wrapper
|
// Generate outer wrapper
|
||||||
err := m.generateOuter()
|
err := m.generateOuter(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("build: generate outer: %w", err)
|
return fmt.Errorf("build: generate outer: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Generate final output
|
// Generate final output
|
||||||
err = m.generate()
|
err = m.generate(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("build: generate: %w", err)
|
return fmt.Errorf("build: generate: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package mfer
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
|
"context"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
@@ -113,7 +114,7 @@ func TestBuilderBuild(t *testing.T) {
|
|||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err = b.Build(&buf)
|
err = b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Should have magic bytes
|
// Should have magic bytes
|
||||||
@@ -177,7 +178,7 @@ func TestBuilderDeterministicOutput(t *testing.T) {
|
|||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err := b.Build(&buf)
|
err := b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
return buf.Bytes()
|
return buf.Bytes()
|
||||||
@@ -325,7 +326,7 @@ func TestBuilderBuildRoundTrip(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, b.Build(&buf))
|
require.NoError(t, b.Build(context.Background(), &buf))
|
||||||
|
|
||||||
m, err := NewManifestFromReader(&buf)
|
m, err := NewManifestFromReader(&buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
@@ -383,7 +384,7 @@ func TestManifestString(t *testing.T) {
|
|||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, b.Build(&buf))
|
require.NoError(t, b.Build(context.Background(), &buf))
|
||||||
|
|
||||||
m, err := NewManifestFromReader(&buf)
|
m, err := NewManifestFromReader(&buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
@@ -397,7 +398,7 @@ func TestBuilderBuildEmpty(t *testing.T) {
|
|||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err := b.Build(&buf)
|
err := b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Should still produce valid manifest with 0 files
|
// Should still produce valid manifest with 0 files
|
||||||
@@ -416,7 +417,7 @@ func TestBuilderOmitsCreatedAtByDefault(t *testing.T) {
|
|||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, b.Build(&buf))
|
require.NoError(t, b.Build(context.Background(), &buf))
|
||||||
|
|
||||||
m, err := NewManifestFromReader(&buf)
|
m, err := NewManifestFromReader(&buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
@@ -438,7 +439,7 @@ func TestBuilderIncludesCreatedAtWhenRequested(t *testing.T) {
|
|||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, b.Build(&buf))
|
require.NoError(t, b.Build(context.Background(), &buf))
|
||||||
|
|
||||||
m, err := NewManifestFromReader(&buf)
|
m, err := NewManifestFromReader(&buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
@@ -464,7 +465,7 @@ func TestBuilderDeterministicFileOrder(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, b.Build(&buf))
|
require.NoError(t, b.Build(context.Background(), &buf))
|
||||||
m, err := NewManifestFromReader(&buf)
|
m, err := NewManifestFromReader(&buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -164,12 +164,12 @@ func (c *Checker) SigningPubKey() []byte {
|
|||||||
// ExtractEmbeddedSigningKeyFP imports the manifest's embedded public key into a
|
// ExtractEmbeddedSigningKeyFP imports the manifest's embedded public key into a
|
||||||
// temporary keyring and extracts its fingerprint. This validates the key and
|
// temporary keyring and extracts its fingerprint. This validates the key and
|
||||||
// returns its actual fingerprint from the key material itself.
|
// returns its actual fingerprint from the key material itself.
|
||||||
func (c *Checker) ExtractEmbeddedSigningKeyFP() (string, error) {
|
func (c *Checker) ExtractEmbeddedSigningKeyFP(ctx context.Context) (string, error) {
|
||||||
if len(c.signingPubKey) == 0 {
|
if len(c.signingPubKey) == 0 {
|
||||||
return "", errNoSigningPubKey
|
return "", errNoSigningPubKey
|
||||||
}
|
}
|
||||||
|
|
||||||
return gpgExtractPubKeyFingerprint(c.signingPubKey)
|
return gpgExtractPubKeyFingerprint(ctx, c.signingPubKey)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check verifies all files against the manifest.
|
// Check verifies all files against the manifest.
|
||||||
|
|||||||
@@ -61,7 +61,7 @@ func createTestManifest(
|
|||||||
}
|
}
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, builder.Build(&buf))
|
require.NoError(t, builder.Build(context.Background(), &buf))
|
||||||
require.NoError(t, afero.WriteFile(fs, manifestPath, buf.Bytes(), 0o644))
|
require.NoError(t, afero.WriteFile(fs, manifestPath, buf.Bytes(), 0o644))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package mfer
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
|
"context"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
@@ -92,7 +93,9 @@ func (m *manifest) verifyOuterIntegrity() error {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Loading a manifest takes no context; gpgTimeout still bounds gpg.
|
||||||
err = gpgVerify(
|
err = gpgVerify(
|
||||||
|
context.Background(),
|
||||||
[]byte(sigString),
|
[]byte(sigString),
|
||||||
m.pbOuter.GetSignature(),
|
m.pbOuter.GetSignature(),
|
||||||
m.pbOuter.GetSigningPubKey(),
|
m.pbOuter.GetSigningPubKey(),
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package mfer
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
|
"context"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"fmt"
|
"fmt"
|
||||||
"testing"
|
"testing"
|
||||||
@@ -122,7 +123,7 @@ func TestDeserializeValidManifestRoundTrips(t *testing.T) {
|
|||||||
require.NoError(t, b.AddFileWithHash("dir/file.txt", 123, ModTime{}, hash))
|
require.NoError(t, b.AddFileWithHash("dir/file.txt", 123, ModTime{}, hash))
|
||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
require.NoError(t, b.Build(&buf))
|
require.NoError(t, b.Build(context.Background(), &buf))
|
||||||
|
|
||||||
m, err := NewManifestFromReader(bytes.NewReader(buf.Bytes()))
|
m, err := NewManifestFromReader(bytes.NewReader(buf.Bytes()))
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|||||||
+4
-2
@@ -2,6 +2,7 @@
|
|||||||
package mfer
|
package mfer
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
@@ -80,6 +81,7 @@ func TestSerializeInternalErrorMessagesVerbatim(t *testing.T) {
|
|||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
m := &manifest{}
|
m := &manifest{}
|
||||||
require.EqualError(t, m.generate(), "internal error: pbInner not set")
|
require.EqualError(t, m.generate(context.Background()),
|
||||||
require.EqualError(t, m.generateOuter(), "internal error")
|
"internal error: pbInner not set")
|
||||||
|
require.EqualError(t, m.generateOuter(context.Background()), "internal error")
|
||||||
}
|
}
|
||||||
|
|||||||
+38
-15
@@ -10,9 +10,15 @@ import (
|
|||||||
"os/exec"
|
"os/exec"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
// gpgTimeout bounds every gpg run, which can otherwise wait forever on
|
||||||
|
// a passphrase prompt or a stalled gpg-agent. A minute leaves a person
|
||||||
|
// time to type a passphrase or touch a smartcard.
|
||||||
|
gpgTimeout = time.Minute
|
||||||
|
|
||||||
// privateDirPerms is the permission mode for temporary GPG home
|
// privateDirPerms is the permission mode for temporary GPG home
|
||||||
// directories.
|
// directories.
|
||||||
privateDirPerms os.FileMode = 0o700
|
privateDirPerms os.FileMode = 0o700
|
||||||
@@ -66,8 +72,17 @@ func gpgArgs(opts []string, positional ...string) []string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// runGPG runs the gpg binary in batch mode with the given arguments and
|
// runGPG runs the gpg binary in batch mode with the given arguments and
|
||||||
// optional stdin, returning captured stdout and stderr.
|
// optional stdin, returning captured stdout and stderr. gpg is killed when
|
||||||
func runGPG(stdin io.Reader, args ...string) (*bytes.Buffer, *bytes.Buffer, error) {
|
// ctx ends or gpgTimeout passes, whichever comes first.
|
||||||
|
func runGPG(
|
||||||
|
ctx context.Context, stdin io.Reader, args ...string,
|
||||||
|
) (*bytes.Buffer, *bytes.Buffer, error) {
|
||||||
|
// exec.CommandContext kills only gpg itself, and that is enough: a
|
||||||
|
// gpg-agent that gpg starts runs detached in its own session and does
|
||||||
|
// not hold gpg's output open, so Run returns as soon as gpg dies.
|
||||||
|
ctx, cancel := context.WithTimeout(ctx, gpgTimeout)
|
||||||
|
defer cancel()
|
||||||
|
|
||||||
fullArgs := append([]string{"--batch", "--no-tty"}, args...)
|
fullArgs := append([]string{"--batch", "--no-tty"}, args...)
|
||||||
|
|
||||||
// G204: the executable name is a compile-time constant. The arguments
|
// G204: the executable name is a compile-time constant. The arguments
|
||||||
@@ -76,7 +91,7 @@ func runGPG(stdin io.Reader, args ...string) (*bytes.Buffer, *bytes.Buffer, erro
|
|||||||
// option or after the "--" end-of-options marker inserted by gpgArgs,
|
// option or after the "--" end-of-options marker inserted by gpgArgs,
|
||||||
// and therefore cannot be reinterpreted by gpg as an option.
|
// and therefore cannot be reinterpreted by gpg as an option.
|
||||||
cmd := exec.CommandContext( //nolint:gosec // G204: see comment above
|
cmd := exec.CommandContext( //nolint:gosec // G204: see comment above
|
||||||
context.Background(), "gpg", fullArgs...)
|
ctx, "gpg", fullArgs...)
|
||||||
cmd.Stdin = stdin
|
cmd.Stdin = stdin
|
||||||
|
|
||||||
var stdout, stderr bytes.Buffer
|
var stdout, stderr bytes.Buffer
|
||||||
@@ -85,6 +100,14 @@ func runGPG(stdin io.Reader, args ...string) (*bytes.Buffer, *bytes.Buffer, erro
|
|||||||
cmd.Stderr = &stderr
|
cmd.Stderr = &stderr
|
||||||
|
|
||||||
err := cmd.Run()
|
err := cmd.Run()
|
||||||
|
if err != nil && ctx.Err() != nil {
|
||||||
|
// gpg was killed because ctx ended, which Run reports only as
|
||||||
|
// "signal: killed"; return the reason instead.
|
||||||
|
err = ctx.Err()
|
||||||
|
if errors.Is(err, context.DeadlineExceeded) {
|
||||||
|
err = fmt.Errorf("gpg timed out: %w", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
return &stdout, &stderr, err
|
return &stdout, &stderr, err
|
||||||
}
|
}
|
||||||
@@ -105,8 +128,8 @@ func parseFingerprint(colonOutput string) (string, bool) {
|
|||||||
|
|
||||||
// gpgSign creates a detached signature of the data using the specified key.
|
// gpgSign creates a detached signature of the data using the specified key.
|
||||||
// Returns the armored detached signature.
|
// Returns the armored detached signature.
|
||||||
func gpgSign(data []byte, keyID GPGKeyID) ([]byte, error) {
|
func gpgSign(ctx context.Context, data []byte, keyID GPGKeyID) ([]byte, error) {
|
||||||
stdout, stderr, err := runGPG(bytes.NewReader(data),
|
stdout, stderr, err := runGPG(ctx, bytes.NewReader(data),
|
||||||
"--detach-sign",
|
"--detach-sign",
|
||||||
gpgOptArmor,
|
gpgOptArmor,
|
||||||
"--local-user", string(keyID),
|
"--local-user", string(keyID),
|
||||||
@@ -120,8 +143,8 @@ func gpgSign(data []byte, keyID GPGKeyID) ([]byte, error) {
|
|||||||
|
|
||||||
// gpgExportPublicKey exports the public key for the specified key ID.
|
// gpgExportPublicKey exports the public key for the specified key ID.
|
||||||
// Returns the armored public key.
|
// Returns the armored public key.
|
||||||
func gpgExportPublicKey(keyID GPGKeyID) ([]byte, error) {
|
func gpgExportPublicKey(ctx context.Context, keyID GPGKeyID) ([]byte, error) {
|
||||||
stdout, stderr, err := runGPG(nil,
|
stdout, stderr, err := runGPG(ctx, nil,
|
||||||
gpgArgs([]string{"--export", gpgOptArmor}, string(keyID))...,
|
gpgArgs([]string{"--export", gpgOptArmor}, string(keyID))...,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -136,8 +159,8 @@ func gpgExportPublicKey(keyID GPGKeyID) ([]byte, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// gpgGetKeyFingerprint gets the full fingerprint for a key ID.
|
// gpgGetKeyFingerprint gets the full fingerprint for a key ID.
|
||||||
func gpgGetKeyFingerprint(keyID GPGKeyID) ([]byte, error) {
|
func gpgGetKeyFingerprint(ctx context.Context, keyID GPGKeyID) ([]byte, error) {
|
||||||
stdout, stderr, err := runGPG(nil,
|
stdout, stderr, err := runGPG(ctx, nil,
|
||||||
gpgArgs([]string{"--with-colons", "--fingerprint"}, string(keyID))...,
|
gpgArgs([]string{"--with-colons", "--fingerprint"}, string(keyID))...,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -157,7 +180,7 @@ func gpgGetKeyFingerprint(keyID GPGKeyID) ([]byte, error) {
|
|||||||
// gpgExtractPubKeyFingerprint imports a public key into a temporary keyring
|
// gpgExtractPubKeyFingerprint imports a public key into a temporary keyring
|
||||||
// and extracts its fingerprint. This verifies the key is valid and returns
|
// and extracts its fingerprint. This verifies the key is valid and returns
|
||||||
// the actual fingerprint from the key material.
|
// the actual fingerprint from the key material.
|
||||||
func gpgExtractPubKeyFingerprint(pubKey []byte) (string, error) {
|
func gpgExtractPubKeyFingerprint(ctx context.Context, pubKey []byte) (string, error) {
|
||||||
// Create temporary directory for GPG operations
|
// Create temporary directory for GPG operations
|
||||||
tmpDir, err := os.MkdirTemp("", "mfer-gpg-fingerprint-*")
|
tmpDir, err := os.MkdirTemp("", "mfer-gpg-fingerprint-*")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -181,7 +204,7 @@ func gpgExtractPubKeyFingerprint(pubKey []byte) (string, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Import the public key into the temporary keyring
|
// Import the public key into the temporary keyring
|
||||||
_, importStderr, err := runGPG(nil,
|
_, importStderr, err := runGPG(ctx, nil,
|
||||||
gpgArgs([]string{gpgOptHomedir, tmpDir, "--import"}, pubKeyFile)...,
|
gpgArgs([]string{gpgOptHomedir, tmpDir, "--import"}, pubKeyFile)...,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -191,7 +214,7 @@ func gpgExtractPubKeyFingerprint(pubKey []byte) (string, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// List keys to get fingerprint
|
// List keys to get fingerprint
|
||||||
listStdout, listStderr, err := runGPG(nil,
|
listStdout, listStderr, err := runGPG(ctx, nil,
|
||||||
"--homedir", tmpDir,
|
"--homedir", tmpDir,
|
||||||
"--with-colons",
|
"--with-colons",
|
||||||
"--fingerprint",
|
"--fingerprint",
|
||||||
@@ -212,7 +235,7 @@ func gpgExtractPubKeyFingerprint(pubKey []byte) (string, error) {
|
|||||||
|
|
||||||
// gpgVerify verifies a detached signature against data using the provided public key.
|
// gpgVerify verifies a detached signature against data using the provided public key.
|
||||||
// It creates a temporary keyring to import the public key for verification.
|
// It creates a temporary keyring to import the public key for verification.
|
||||||
func gpgVerify(data, signature, pubKey []byte) error {
|
func gpgVerify(ctx context.Context, data, signature, pubKey []byte) error {
|
||||||
// Create temporary directory for GPG operations
|
// Create temporary directory for GPG operations
|
||||||
tmpDir, err := os.MkdirTemp("", "mfer-gpg-verify-*")
|
tmpDir, err := os.MkdirTemp("", "mfer-gpg-verify-*")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -252,7 +275,7 @@ func gpgVerify(data, signature, pubKey []byte) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Import the public key into the temporary keyring
|
// Import the public key into the temporary keyring
|
||||||
_, importStderr, err := runGPG(nil,
|
_, importStderr, err := runGPG(ctx, nil,
|
||||||
gpgArgs([]string{gpgOptHomedir, tmpDir, "--import"}, pubKeyFile)...,
|
gpgArgs([]string{gpgOptHomedir, tmpDir, "--import"}, pubKeyFile)...,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -262,7 +285,7 @@ func gpgVerify(data, signature, pubKey []byte) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Verify the signature
|
// Verify the signature
|
||||||
_, verifyStderr, err := runGPG(nil,
|
_, verifyStderr, err := runGPG(ctx, nil,
|
||||||
gpgArgs([]string{gpgOptHomedir, tmpDir, gpgOptVerify},
|
gpgArgs([]string{gpgOptHomedir, tmpDir, gpgOptVerify},
|
||||||
sigFile, dataFile)...,
|
sigFile, dataFile)...,
|
||||||
)
|
)
|
||||||
|
|||||||
+58
-20
@@ -4,11 +4,13 @@ package mfer
|
|||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
"context"
|
"context"
|
||||||
|
"io"
|
||||||
"os"
|
"os"
|
||||||
"os/exec"
|
"os/exec"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
"github.com/spf13/afero"
|
"github.com/spf13/afero"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
@@ -43,8 +45,11 @@ Expire-Date: 0
|
|||||||
paramsFile := filepath.Join(gpgHome, "key-params")
|
paramsFile := filepath.Join(gpgHome, "key-params")
|
||||||
require.NoError(t, os.WriteFile(paramsFile, []byte(keyParams), 0o600))
|
require.NoError(t, os.WriteFile(paramsFile, []byte(keyParams), 0o600))
|
||||||
|
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), gpgTimeout)
|
||||||
|
defer cancel()
|
||||||
|
|
||||||
//nolint:gosec // paramsFile is a test-controlled path inside t.TempDir()
|
//nolint:gosec // paramsFile is a test-controlled path inside t.TempDir()
|
||||||
cmd := exec.CommandContext(context.Background(), "gpg",
|
cmd := exec.CommandContext(ctx, "gpg",
|
||||||
"--batch", "--gen-key", paramsFile)
|
"--batch", "--gen-key", paramsFile)
|
||||||
|
|
||||||
cmd.Env = append(os.Environ(), "GNUPGHOME="+gpgHome)
|
cmd.Env = append(os.Environ(), "GNUPGHOME="+gpgHome)
|
||||||
@@ -55,7 +60,7 @@ Expire-Date: 0
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Get the key fingerprint
|
// Get the key fingerprint
|
||||||
cmd = exec.CommandContext(context.Background(), "gpg",
|
cmd = exec.CommandContext(ctx, "gpg",
|
||||||
"--list-keys", "--with-colons", "test@mfer.test")
|
"--list-keys", "--with-colons", "test@mfer.test")
|
||||||
|
|
||||||
cmd.Env = append(os.Environ(), "GNUPGHOME="+gpgHome)
|
cmd.Env = append(os.Environ(), "GNUPGHOME="+gpgHome)
|
||||||
@@ -90,7 +95,7 @@ func TestGPGSign(t *testing.T) {
|
|||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
data := []byte("test data to sign")
|
data := []byte("test data to sign")
|
||||||
sig, err := gpgSign(data, keyID)
|
sig, err := gpgSign(context.Background(), data, keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
assert.NotEmpty(t, sig)
|
assert.NotEmpty(t, sig)
|
||||||
assert.Contains(t, string(sig), "-----BEGIN PGP SIGNATURE-----")
|
assert.Contains(t, string(sig), "-----BEGIN PGP SIGNATURE-----")
|
||||||
@@ -101,7 +106,7 @@ func TestGPGExportPublicKey(t *testing.T) {
|
|||||||
keyID, gpgHome := testGPGEnv(t)
|
keyID, gpgHome := testGPGEnv(t)
|
||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
pubKey, err := gpgExportPublicKey(keyID)
|
pubKey, err := gpgExportPublicKey(context.Background(), keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
assert.NotEmpty(t, pubKey)
|
assert.NotEmpty(t, pubKey)
|
||||||
assert.Contains(t, string(pubKey), "-----BEGIN PGP PUBLIC KEY BLOCK-----")
|
assert.Contains(t, string(pubKey), "-----BEGIN PGP PUBLIC KEY BLOCK-----")
|
||||||
@@ -112,7 +117,7 @@ func TestGPGGetKeyFingerprint(t *testing.T) {
|
|||||||
keyID, gpgHome := testGPGEnv(t)
|
keyID, gpgHome := testGPGEnv(t)
|
||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
fingerprint, err := gpgGetKeyFingerprint(keyID)
|
fingerprint, err := gpgGetKeyFingerprint(context.Background(), keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
assert.NotEmpty(t, fingerprint)
|
assert.NotEmpty(t, fingerprint)
|
||||||
// The fingerprint should be 40 hex chars
|
// The fingerprint should be 40 hex chars
|
||||||
@@ -146,12 +151,12 @@ func TestGPGOptionLikeKeyIDIsNotAnOption(t *testing.T) {
|
|||||||
_, gpgHome := testGPGEnv(t)
|
_, gpgHome := testGPGEnv(t)
|
||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
pubKey, err := gpgExportPublicKey(GPGKeyID("--version"))
|
pubKey, err := gpgExportPublicKey(context.Background(), GPGKeyID("--version"))
|
||||||
require.Error(t, err)
|
require.Error(t, err)
|
||||||
require.ErrorIs(t, err, errGPGKeyNotFound)
|
require.ErrorIs(t, err, errGPGKeyNotFound)
|
||||||
assert.NotContains(t, string(pubKey), "gpg (GnuPG)")
|
assert.NotContains(t, string(pubKey), "gpg (GnuPG)")
|
||||||
|
|
||||||
fpr, err := gpgGetKeyFingerprint(GPGKeyID("--version"))
|
fpr, err := gpgGetKeyFingerprint(context.Background(), GPGKeyID("--version"))
|
||||||
require.Error(t, err)
|
require.Error(t, err)
|
||||||
assert.NotContains(t, string(fpr), "gpg (GnuPG)")
|
assert.NotContains(t, string(fpr), "gpg (GnuPG)")
|
||||||
}
|
}
|
||||||
@@ -162,7 +167,8 @@ func TestGPGSignInvalidKey(t *testing.T) {
|
|||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
data := []byte("test data")
|
data := []byte("test data")
|
||||||
_, err := gpgSign(data, GPGKeyID("NONEXISTENT_KEY_ID_12345"))
|
_, err := gpgSign(context.Background(), data,
|
||||||
|
GPGKeyID("NONEXISTENT_KEY_ID_12345"))
|
||||||
assert.Error(t, err)
|
assert.Error(t, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -185,7 +191,7 @@ func TestBuilderWithSigning(t *testing.T) {
|
|||||||
// Build the manifest
|
// Build the manifest
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err = b.Build(&buf)
|
err = b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Parse the manifest and verify signature fields are populated
|
// Parse the manifest and verify signature fields are populated
|
||||||
@@ -251,14 +257,14 @@ func TestGPGVerify(t *testing.T) {
|
|||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
data := []byte("test data to sign and verify")
|
data := []byte("test data to sign and verify")
|
||||||
sig, err := gpgSign(data, keyID)
|
sig, err := gpgSign(context.Background(), data, keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
pubKey, err := gpgExportPublicKey(keyID)
|
pubKey, err := gpgExportPublicKey(context.Background(), keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Verify the signature
|
// Verify the signature
|
||||||
err = gpgVerify(data, sig, pubKey)
|
err = gpgVerify(context.Background(), data, sig, pubKey)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -267,15 +273,15 @@ func TestGPGVerifyInvalidSignature(t *testing.T) {
|
|||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
data := []byte("test data to sign")
|
data := []byte("test data to sign")
|
||||||
sig, err := gpgSign(data, keyID)
|
sig, err := gpgSign(context.Background(), data, keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
pubKey, err := gpgExportPublicKey(keyID)
|
pubKey, err := gpgExportPublicKey(context.Background(), keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Try to verify with different data - should fail
|
// Try to verify with different data - should fail
|
||||||
wrongData := []byte("different data")
|
wrongData := []byte("different data")
|
||||||
err = gpgVerify(wrongData, sig, pubKey)
|
err = gpgVerify(context.Background(), wrongData, sig, pubKey)
|
||||||
assert.Error(t, err)
|
assert.Error(t, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -284,12 +290,12 @@ func TestGPGVerifyBadPublicKey(t *testing.T) {
|
|||||||
t.Setenv("GNUPGHOME", gpgHome)
|
t.Setenv("GNUPGHOME", gpgHome)
|
||||||
|
|
||||||
data := []byte("test data")
|
data := []byte("test data")
|
||||||
sig, err := gpgSign(data, keyID)
|
sig, err := gpgSign(context.Background(), data, keyID)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Try to verify with invalid public key - should fail
|
// Try to verify with invalid public key - should fail
|
||||||
badPubKey := []byte("not a valid public key")
|
badPubKey := []byte("not a valid public key")
|
||||||
err = gpgVerify(data, sig, badPubKey)
|
err = gpgVerify(context.Background(), data, sig, badPubKey)
|
||||||
assert.Error(t, err)
|
assert.Error(t, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -312,7 +318,7 @@ func TestManifestSignatureVerification(t *testing.T) {
|
|||||||
// Build the manifest
|
// Build the manifest
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err = b.Build(&buf)
|
err = b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Parse the manifest - signature should be verified during load
|
// Parse the manifest - signature should be verified during load
|
||||||
@@ -341,7 +347,7 @@ func TestManifestTamperedSignatureFails(t *testing.T) {
|
|||||||
|
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err = b.Build(&buf)
|
err = b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Tamper with the signature by replacing some bytes
|
// Tamper with the signature by replacing some bytes
|
||||||
@@ -375,7 +381,7 @@ func TestBuilderWithoutSigning(t *testing.T) {
|
|||||||
// Build the manifest
|
// Build the manifest
|
||||||
var buf bytes.Buffer
|
var buf bytes.Buffer
|
||||||
|
|
||||||
err = b.Build(&buf)
|
err = b.Build(context.Background(), &buf)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// Parse the manifest and verify signature fields are empty
|
// Parse the manifest and verify signature fields are empty
|
||||||
@@ -390,3 +396,35 @@ func TestBuilderWithoutSigning(t *testing.T) {
|
|||||||
assert.Empty(t, manifest.pbOuter.GetSigningPubKey(),
|
assert.Empty(t, manifest.pbOuter.GetSigningPubKey(),
|
||||||
"signing public key should be empty when not signing")
|
"signing public key should be empty when not signing")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestGPGTimeoutKillsGPG puts a fake gpg that never finishes first on
|
||||||
|
// PATH and checks that a run past its deadline is killed and reported as
|
||||||
|
// a timeout of the named operation, instead of hanging.
|
||||||
|
func TestGPGTimeoutKillsGPG(t *testing.T) {
|
||||||
|
binDir := t.TempDir()
|
||||||
|
fakeGPG := []byte("#!/bin/sh\nexec sleep 10\n")
|
||||||
|
//nolint:gosec // G306: the fake gpg has to be executable
|
||||||
|
require.NoError(t, os.WriteFile(filepath.Join(binDir, "gpg"), fakeGPG, 0o700))
|
||||||
|
t.Setenv("PATH", binDir+string(os.PathListSeparator)+os.Getenv("PATH"))
|
||||||
|
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
||||||
|
defer cancel()
|
||||||
|
|
||||||
|
_, err := gpgSign(ctx, []byte("data"), GPGKeyID("any"))
|
||||||
|
require.ErrorIs(t, err, context.DeadlineExceeded)
|
||||||
|
assert.Contains(t, err.Error(), "gpg sign failed: gpg timed out")
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestBuildPassesContextToSigning checks that a caller can cancel the gpg
|
||||||
|
// runs that sign a manifest through the context given to Build.
|
||||||
|
func TestBuildPassesContextToSigning(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
b := NewBuilder()
|
||||||
|
b.SetSigningOptions(&SigningOptions{KeyID: "any"})
|
||||||
|
|
||||||
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
cancel()
|
||||||
|
|
||||||
|
require.ErrorIs(t, b.Build(ctx, io.Discard), context.Canceled)
|
||||||
|
}
|
||||||
|
|||||||
+1
-2
@@ -283,8 +283,7 @@ func (s *Scanner) ToManifest(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Build and write manifest
|
// Build and write manifest
|
||||||
//nolint:contextcheck // Build's GPG signing exec is not cancellable by design
|
return builder.Build(ctx, w)
|
||||||
return builder.Build(w)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// configureBuilder constructs a manifest builder configured from the
|
// configureBuilder constructs a manifest builder configured from the
|
||||||
|
|||||||
+9
-8
@@ -2,6 +2,7 @@ package mfer
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
|
"context"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
@@ -50,13 +51,13 @@ func newTimestampFromTime(t time.Time) *Timestamp {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (m *manifest) generate() error {
|
func (m *manifest) generate(ctx context.Context) error {
|
||||||
if m.pbInner == nil {
|
if m.pbInner == nil {
|
||||||
return errInnerNotSet
|
return errInnerNotSet
|
||||||
}
|
}
|
||||||
|
|
||||||
if m.pbOuter == nil {
|
if m.pbOuter == nil {
|
||||||
e := m.generateOuter()
|
e := m.generateOuter(ctx)
|
||||||
if e != nil {
|
if e != nil {
|
||||||
return e
|
return e
|
||||||
}
|
}
|
||||||
@@ -77,7 +78,7 @@ func (m *manifest) generate() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (m *manifest) generateOuter() error {
|
func (m *manifest) generateOuter(ctx context.Context) error {
|
||||||
if m.pbInner == nil {
|
if m.pbInner == nil {
|
||||||
return errInternal
|
return errInternal
|
||||||
}
|
}
|
||||||
@@ -135,7 +136,7 @@ func (m *manifest) generateOuter() error {
|
|||||||
|
|
||||||
// Sign the manifest if signing options are provided
|
// Sign the manifest if signing options are provided
|
||||||
if m.signingOptions != nil && m.signingOptions.KeyID != "" {
|
if m.signingOptions != nil && m.signingOptions.KeyID != "" {
|
||||||
return m.signOuter()
|
return m.signOuter(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
@@ -143,27 +144,27 @@ func (m *manifest) generateOuter() error {
|
|||||||
|
|
||||||
// signOuter signs the outer message with the configured GPG key and
|
// signOuter signs the outer message with the configured GPG key and
|
||||||
// embeds the signature, signer fingerprint, and public key.
|
// embeds the signature, signer fingerprint, and public key.
|
||||||
func (m *manifest) signOuter() error {
|
func (m *manifest) signOuter(ctx context.Context) error {
|
||||||
sigString, err := m.signatureString()
|
sigString, err := m.signatureString()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("failed to generate signature string: %w", err)
|
return fmt.Errorf("failed to generate signature string: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
sig, err := gpgSign([]byte(sigString), m.signingOptions.KeyID)
|
sig, err := gpgSign(ctx, []byte(sigString), m.signingOptions.KeyID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("failed to sign manifest: %w", err)
|
return fmt.Errorf("failed to sign manifest: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
m.pbOuter.Signature = sig
|
m.pbOuter.Signature = sig
|
||||||
|
|
||||||
fingerprint, err := gpgGetKeyFingerprint(m.signingOptions.KeyID)
|
fingerprint, err := gpgGetKeyFingerprint(ctx, m.signingOptions.KeyID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("failed to get key fingerprint: %w", err)
|
return fmt.Errorf("failed to get key fingerprint: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
m.pbOuter.Signer = fingerprint
|
m.pbOuter.Signer = fingerprint
|
||||||
|
|
||||||
pubKey, err := gpgExportPublicKey(m.signingOptions.KeyID)
|
pubKey, err := gpgExportPublicKey(ctx, m.signingOptions.KeyID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("failed to export public key: %w", err)
|
return fmt.Errorf("failed to export public key: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
+5
-15
@@ -1,24 +1,14 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# script/cibuild: run the CI build; the Gitea workflow runs this on push.
|
# script/cibuild: run the CI build. The Dockerfile runs script/check
|
||||||
# It builds the image with the same command as script/docker. --no-cache
|
# (via make check), so a successful build implies all checks pass.
|
||||||
# because the checks the final stage depends on are RUN steps, and a
|
# Generic: needs no adaptation. The Gitea workflow runs this on push.
|
||||||
# cached one is a check that did not run.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
# Own line: a failing command substitution inside an argument does
|
docker build .
|
||||||
# not trip `set -e`, so the inline form degrades silently to an
|
|
||||||
# empty constant. The VERSION build argument takes precedence over
|
|
||||||
# the version a build stage derives from the .git in the context.
|
|
||||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
|
||||||
[ -n "$version" ] || version="unknown"
|
|
||||||
docker build --no-cache \
|
|
||||||
--build-arg VERSION="$version" \
|
|
||||||
-t "$("$SCRIPT_DIR/projectname")" .
|
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user