68 lines
1.6 KiB
Go
68 lines
1.6 KiB
Go
package main
|
|
|
|
import (
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"forge-mesh/internal/forge"
|
|
)
|
|
|
|
func TestSelfUpdateSignatureCheck(t *testing.T) {
|
|
dir := t.TempDir()
|
|
keyPath := filepath.Join(dir, "signing.key")
|
|
|
|
kp, err := forge.LoadOrCreateKey(keyPath)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
artifact := []byte("forge-mesh-agent-linux-amd64-test-artifact")
|
|
sig := kp.Sign(artifact)
|
|
|
|
if !verifyAgentUpdate(kp.PublicKeyHex(), artifact, sig) {
|
|
t.Fatal("valid artifact signature rejected")
|
|
}
|
|
|
|
tampered := append([]byte(nil), artifact...)
|
|
tampered[0] ^= 0xff
|
|
if verifyAgentUpdate(kp.PublicKeyHex(), tampered, sig) {
|
|
t.Fatal("tampered artifact should not verify")
|
|
}
|
|
|
|
if verifyAgentUpdate("not-a-valid-pubkey", artifact, sig) {
|
|
t.Fatal("invalid pubkey should not verify")
|
|
}
|
|
}
|
|
|
|
func TestSelfUpdateChecksumMatchesArtifact(t *testing.T) {
|
|
dir := t.TempDir()
|
|
artifactPath := filepath.Join(dir, "forge-mesh-agent-linux-amd64")
|
|
content := []byte("binary-payload-for-checksum-test")
|
|
if err := os.WriteFile(artifactPath, content, 0o755); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
sum := sha256.Sum256(content)
|
|
expected := hex.EncodeToString(sum[:])
|
|
|
|
data, err := os.ReadFile(artifactPath)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got := sha256.Sum256(data)
|
|
if hex.EncodeToString(got[:]) != expected {
|
|
t.Fatalf("checksum mismatch: got %s want %s", hex.EncodeToString(got[:]), expected)
|
|
}
|
|
|
|
kp, err := forge.LoadOrCreateKey(filepath.Join(dir, "signing.key"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !verifyAgentUpdate(kp.PublicKeyHex(), data, kp.Sign(data)) {
|
|
t.Fatal("checksum-stable artifact failed signature verification")
|
|
}
|
|
}
|