keys_test.go 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260
  1. package pgp
  2. import (
  3. "context"
  4. "fmt"
  5. "os"
  6. "os/exec"
  7. "sort"
  8. "strings"
  9. "testing"
  10. gosrc "github.com/Morganamilo/go-srcinfo"
  11. "github.com/stretchr/testify/assert"
  12. "github.com/stretchr/testify/require"
  13. "github.com/Jguer/yay/v12/pkg/settings/exe"
  14. )
  15. func makeSrcinfo(pkgbase string, pgpkeys ...string) *gosrc.Srcinfo {
  16. srcinfo := gosrc.Srcinfo{}
  17. srcinfo.Pkgbase = pkgbase
  18. srcinfo.ValidPGPKeys = pgpkeys
  19. return &srcinfo
  20. }
  21. func TestCheckPgpKeys(t *testing.T) {
  22. gpgBin := t.TempDir() + "/gpg"
  23. f, err := os.OpenFile(gpgBin, os.O_RDONLY|os.O_CREATE, 0o755)
  24. require.NoError(t, err)
  25. require.NoError(t, f.Close())
  26. testcases := []struct {
  27. name string
  28. pkgs map[string]string
  29. srcinfos map[string]*gosrc.Srcinfo
  30. wantError bool
  31. wantShow []string
  32. wantCapture []string
  33. showFn func(cmd *exec.Cmd) error
  34. expected []string
  35. }{
  36. // cower: single package, one valid key not yet in the keyring.
  37. // 487EACC08557AD082088DABA1EB2638FF56C0C53: Dave Reisner.
  38. {
  39. name: " one valid key not yet in the keyring",
  40. pkgs: map[string]string{"cower": ""},
  41. srcinfos: map[string]*gosrc.Srcinfo{"cower": makeSrcinfo("cower", "487EACC08557AD082088DABA1EB2638FF56C0C53")},
  42. wantError: false,
  43. wantShow: []string{
  44. "gpg --homedir /tmp --list-keys 487EACC08557AD082088DABA1EB2638FF56C0C53",
  45. "gpg --homedir /tmp --recv-keys 487EACC08557AD082088DABA1EB2638FF56C0C53",
  46. },
  47. wantCapture: []string{},
  48. showFn: func(cmd *exec.Cmd) error {
  49. s := cmd.String()
  50. if strings.Contains(s, "--list-keys") {
  51. return fmt.Errorf("key not found")
  52. }
  53. return nil
  54. },
  55. expected: []string{"487EACC08557AD082088DABA1EB2638FF56C0C53"},
  56. },
  57. // libc++: single package, two valid keys not yet in the keyring.
  58. // 11E521D646982372EB577A1F8F0871F202119294: Tom Stellard.
  59. // B6C8F98282B944E3B0D5C2530FC3042E345AD05D: Hans Wennborg.
  60. {
  61. name: "two valid keys not yet in the keyring",
  62. pkgs: map[string]string{"libc++": ""},
  63. srcinfos: map[string]*gosrc.Srcinfo{"libc++": makeSrcinfo("libc++", "11E521D646982372EB577A1F8F0871F202119294", "B6C8F98282B944E3B0D5C2530FC3042E345AD05D")},
  64. wantError: false,
  65. wantShow: []string{
  66. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  67. "gpg --homedir /tmp --list-keys B6C8F98282B944E3B0D5C2530FC3042E345AD05D",
  68. "gpg --homedir /tmp --recv-keys 11E521D646982372EB577A1F8F0871F202119294 B6C8F98282B944E3B0D5C2530FC3042E345AD05D",
  69. },
  70. wantCapture: []string{},
  71. showFn: func(cmd *exec.Cmd) error {
  72. s := cmd.String()
  73. if strings.Contains(s, "--list-keys") {
  74. return fmt.Errorf("key not found")
  75. }
  76. return nil
  77. },
  78. expected: []string{"11E521D646982372EB577A1F8F0871F202119294", "B6C8F98282B944E3B0D5C2530FC3042E345AD05D"},
  79. },
  80. {
  81. name: "Two dummy packages requiring the same key",
  82. pkgs: map[string]string{"dummy-1": "", "dummy-2": ""},
  83. srcinfos: map[string]*gosrc.Srcinfo{
  84. "dummy-1": makeSrcinfo("dummy-1",
  85. "ABAF11C65A2970B130ABE3C479BE3E4300411886"),
  86. "dummy-2": makeSrcinfo("dummy-2", "ABAF11C65A2970B130ABE3C479BE3E4300411886"),
  87. },
  88. wantError: false,
  89. expected: []string{"ABAF11C65A2970B130ABE3C479BE3E4300411886"},
  90. wantCapture: []string{},
  91. wantShow: []string{
  92. "gpg --homedir /tmp --list-keys ABAF11C65A2970B130ABE3C479BE3E4300411886",
  93. "gpg --homedir /tmp --recv-keys ABAF11C65A2970B130ABE3C479BE3E4300411886",
  94. },
  95. showFn: func(cmd *exec.Cmd) error {
  96. s := cmd.String()
  97. if strings.Contains(s, "--list-keys") {
  98. return fmt.Errorf("key not found")
  99. }
  100. return nil
  101. },
  102. },
  103. // dummy package: single package, two valid keys, one of them already
  104. // in the keyring.
  105. // 11E521D646982372EB577A1F8F0871F202119294: Tom Stellard.
  106. // C52048C0C0748FEE227D47A2702353E0F7E48EDB: Thomas Dickey.
  107. {
  108. name: "one already in keyring",
  109. pkgs: map[string]string{"dummy-3": ""},
  110. srcinfos: map[string]*gosrc.Srcinfo{
  111. "dummy-3": makeSrcinfo("dummy-3", "11E521D646982372EB577A1F8F0871F202119294", "C52048C0C0748FEE227D47A2702353E0F7E48EDB"),
  112. },
  113. wantError: false,
  114. expected: []string{"C52048C0C0748FEE227D47A2702353E0F7E48EDB"},
  115. wantCapture: []string{},
  116. showFn: func(cmd *exec.Cmd) error {
  117. s := cmd.String()
  118. if strings.Contains(s, "--list-keys") &&
  119. !strings.Contains(s, "11E521D646982372EB577A1F8F0871F202119294") {
  120. return fmt.Errorf("key not found")
  121. }
  122. return nil
  123. },
  124. wantShow: []string{
  125. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  126. "gpg --homedir /tmp --list-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  127. "gpg --homedir /tmp --recv-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  128. },
  129. },
  130. // Two dummy packages with existing keys.
  131. {
  132. name: "two existing",
  133. pkgs: map[string]string{"dummy-4": "", "dummy-5": ""},
  134. srcinfos: map[string]*gosrc.Srcinfo{
  135. "dummy-4": makeSrcinfo("dummy-4", "11E521D646982372EB577A1F8F0871F202119294"),
  136. "dummy-5": makeSrcinfo("dummy-5", "C52048C0C0748FEE227D47A2702353E0F7E48EDB"),
  137. },
  138. wantError: false,
  139. expected: []string{},
  140. wantCapture: []string{},
  141. showFn: func(cmd *exec.Cmd) error {
  142. return nil
  143. },
  144. wantShow: []string{
  145. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  146. "gpg --homedir /tmp --list-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  147. },
  148. },
  149. // Dummy package with invalid key, should fail.
  150. {
  151. name: "one invalid",
  152. pkgs: map[string]string{"dummy-7": ""},
  153. srcinfos: map[string]*gosrc.Srcinfo{"dummy-7": makeSrcinfo("dummy-7", "THIS-SHOULD-FAIL")},
  154. wantError: true,
  155. wantCapture: []string{},
  156. wantShow: []string{
  157. "gpg --homedir /tmp --list-keys THIS-SHOULD-FAIL",
  158. "gpg --homedir /tmp --recv-keys THIS-SHOULD-FAIL",
  159. },
  160. showFn: func(cmd *exec.Cmd) error {
  161. s := cmd.String()
  162. if strings.Contains(s, "--list-keys") {
  163. return fmt.Errorf("key not found")
  164. }
  165. if strings.Contains(s, "--recv-keys") {
  166. return fmt.Errorf("invalid key")
  167. }
  168. return nil
  169. },
  170. },
  171. // Dummy package with both an invalid an another valid key, should fail.
  172. // A314827C4E4250A204CE6E13284FC34C8E4B1A25: Thomas Bächler.
  173. {
  174. name: "one invalid, one valid",
  175. pkgs: map[string]string{"dummy-8": ""},
  176. srcinfos: map[string]*gosrc.Srcinfo{"dummy-8": makeSrcinfo("dummy-8", "A314827C4E4250A204CE6E13284FC34C8E4B1A25", "THIS-SHOULD-FAIL")},
  177. wantError: true,
  178. expected: []string{},
  179. wantCapture: []string{},
  180. showFn: func(cmd *exec.Cmd) error {
  181. s := cmd.String()
  182. if strings.Contains(s, "--list-keys") {
  183. return fmt.Errorf("key not found")
  184. }
  185. if strings.Contains(s, "--recv-keys") {
  186. return fmt.Errorf("invalid key")
  187. }
  188. return nil
  189. },
  190. wantShow: []string{
  191. "gpg --homedir /tmp --list-keys A314827C4E4250A204CE6E13284FC34C8E4B1A25",
  192. "gpg --homedir /tmp --list-keys THIS-SHOULD-FAIL",
  193. "gpg --homedir /tmp --recv-keys A314827C4E4250A204CE6E13284FC34C8E4B1A25 THIS-SHOULD-FAIL",
  194. },
  195. },
  196. }
  197. for _, tt := range testcases {
  198. tt := tt
  199. t.Run(tt.name, func(t *testing.T) {
  200. mockRunner := &exe.MockRunner{
  201. ShowFn: tt.showFn,
  202. CaptureFn: func(cmd *exec.Cmd) (stdout string, stderr string, err error) {
  203. return "", "", nil
  204. },
  205. }
  206. cmdBuilder := exe.CmdBuilder{
  207. GPGBin: gpgBin,
  208. GPGFlags: []string{"--homedir /tmp"},
  209. Runner: mockRunner,
  210. }
  211. problematic, err := CheckPgpKeys(context.Background(), tt.pkgs, tt.srcinfos, &cmdBuilder, true)
  212. require.Len(t, mockRunner.ShowCalls, len(tt.wantShow))
  213. require.Len(t, mockRunner.CaptureCalls, len(tt.wantCapture))
  214. sort.SliceStable(mockRunner.ShowCalls, func(i, j int) bool {
  215. return mockRunner.ShowCalls[i].Args[0].(*exec.Cmd).String() < mockRunner.ShowCalls[j].Args[0].(*exec.Cmd).String()
  216. })
  217. for i, call := range mockRunner.ShowCalls {
  218. show := call.Args[0].(*exec.Cmd).String()
  219. show = strings.ReplaceAll(show, gpgBin, "gpg")
  220. // options are in a different order on different systems and on CI root user is used
  221. assert.Subset(t, strings.Split(show, " "), strings.Split(tt.wantShow[i], " "), show)
  222. }
  223. for i, call := range mockRunner.CaptureCalls {
  224. capture := call.Args[0].(*exec.Cmd).String()
  225. capture = strings.ReplaceAll(capture, gpgBin, "gpg")
  226. assert.Subset(t, strings.Split(capture, " "), strings.Split(tt.wantCapture[i], " "), capture)
  227. }
  228. if tt.wantError {
  229. require.Error(t, err)
  230. return
  231. }
  232. require.NoError(t, err)
  233. assert.ElementsMatch(t, tt.expected, problematic, fmt.Sprintf("%#v", problematic))
  234. })
  235. }
  236. }