keys_test.go 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269
  1. //go:build !integration
  2. // +build !integration
  3. package pgp
  4. import (
  5. "context"
  6. "fmt"
  7. "io"
  8. "os"
  9. "os/exec"
  10. "sort"
  11. "strings"
  12. "testing"
  13. gosrc "github.com/Morganamilo/go-srcinfo"
  14. "github.com/stretchr/testify/assert"
  15. "github.com/stretchr/testify/require"
  16. "github.com/Jguer/yay/v12/pkg/settings/exe"
  17. "github.com/Jguer/yay/v12/pkg/text"
  18. )
  19. func newTestLogger() *text.Logger {
  20. return text.NewLogger(io.Discard, io.Discard, strings.NewReader(""), true, "test")
  21. }
  22. func makeSrcinfo(pkgbase string, pgpkeys ...string) *gosrc.Srcinfo {
  23. srcinfo := gosrc.Srcinfo{}
  24. srcinfo.Pkgbase = pkgbase
  25. srcinfo.ValidPGPKeys = pgpkeys
  26. return &srcinfo
  27. }
  28. func TestCheckPgpKeys(t *testing.T) {
  29. gpgBin := t.TempDir() + "/gpg"
  30. f, err := os.OpenFile(gpgBin, os.O_RDONLY|os.O_CREATE, 0o755)
  31. require.NoError(t, err)
  32. require.NoError(t, f.Close())
  33. testcases := []struct {
  34. name string
  35. pkgs map[string]string
  36. srcinfos map[string]*gosrc.Srcinfo
  37. wantError bool
  38. wantShow []string
  39. wantCapture []string
  40. showFn func(cmd *exec.Cmd) error
  41. expected []string
  42. }{
  43. // cower: single package, one valid key not yet in the keyring.
  44. // 487EACC08557AD082088DABA1EB2638FF56C0C53: Dave Reisner.
  45. {
  46. name: " one valid key not yet in the keyring",
  47. pkgs: map[string]string{"cower": ""},
  48. srcinfos: map[string]*gosrc.Srcinfo{"cower": makeSrcinfo("cower", "487EACC08557AD082088DABA1EB2638FF56C0C53")},
  49. wantError: false,
  50. wantShow: []string{
  51. "gpg --homedir /tmp --list-keys 487EACC08557AD082088DABA1EB2638FF56C0C53",
  52. "gpg --homedir /tmp --recv-keys 487EACC08557AD082088DABA1EB2638FF56C0C53",
  53. },
  54. wantCapture: []string{},
  55. showFn: func(cmd *exec.Cmd) error {
  56. s := cmd.String()
  57. if strings.Contains(s, "--list-keys") {
  58. return fmt.Errorf("key not found")
  59. }
  60. return nil
  61. },
  62. expected: []string{"487EACC08557AD082088DABA1EB2638FF56C0C53"},
  63. },
  64. // libc++: single package, two valid keys not yet in the keyring.
  65. // 11E521D646982372EB577A1F8F0871F202119294: Tom Stellard.
  66. // B6C8F98282B944E3B0D5C2530FC3042E345AD05D: Hans Wennborg.
  67. {
  68. name: "two valid keys not yet in the keyring",
  69. pkgs: map[string]string{"libc++": ""},
  70. srcinfos: map[string]*gosrc.Srcinfo{"libc++": makeSrcinfo("libc++", "11E521D646982372EB577A1F8F0871F202119294", "B6C8F98282B944E3B0D5C2530FC3042E345AD05D")},
  71. wantError: false,
  72. wantShow: []string{
  73. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  74. "gpg --homedir /tmp --list-keys B6C8F98282B944E3B0D5C2530FC3042E345AD05D",
  75. "gpg --homedir /tmp --recv-keys 11E521D646982372EB577A1F8F0871F202119294 B6C8F98282B944E3B0D5C2530FC3042E345AD05D",
  76. },
  77. wantCapture: []string{},
  78. showFn: func(cmd *exec.Cmd) error {
  79. s := cmd.String()
  80. if strings.Contains(s, "--list-keys") {
  81. return fmt.Errorf("key not found")
  82. }
  83. return nil
  84. },
  85. expected: []string{"11E521D646982372EB577A1F8F0871F202119294", "B6C8F98282B944E3B0D5C2530FC3042E345AD05D"},
  86. },
  87. {
  88. name: "Two dummy packages requiring the same key",
  89. pkgs: map[string]string{"dummy-1": "", "dummy-2": ""},
  90. srcinfos: map[string]*gosrc.Srcinfo{
  91. "dummy-1": makeSrcinfo("dummy-1",
  92. "ABAF11C65A2970B130ABE3C479BE3E4300411886"),
  93. "dummy-2": makeSrcinfo("dummy-2", "ABAF11C65A2970B130ABE3C479BE3E4300411886"),
  94. },
  95. wantError: false,
  96. expected: []string{"ABAF11C65A2970B130ABE3C479BE3E4300411886"},
  97. wantCapture: []string{},
  98. wantShow: []string{
  99. "gpg --homedir /tmp --list-keys ABAF11C65A2970B130ABE3C479BE3E4300411886",
  100. "gpg --homedir /tmp --recv-keys ABAF11C65A2970B130ABE3C479BE3E4300411886",
  101. },
  102. showFn: func(cmd *exec.Cmd) error {
  103. s := cmd.String()
  104. if strings.Contains(s, "--list-keys") {
  105. return fmt.Errorf("key not found")
  106. }
  107. return nil
  108. },
  109. },
  110. // dummy package: single package, two valid keys, one of them already
  111. // in the keyring.
  112. // 11E521D646982372EB577A1F8F0871F202119294: Tom Stellard.
  113. // C52048C0C0748FEE227D47A2702353E0F7E48EDB: Thomas Dickey.
  114. {
  115. name: "one already in keyring",
  116. pkgs: map[string]string{"dummy-3": ""},
  117. srcinfos: map[string]*gosrc.Srcinfo{
  118. "dummy-3": makeSrcinfo("dummy-3", "11E521D646982372EB577A1F8F0871F202119294", "C52048C0C0748FEE227D47A2702353E0F7E48EDB"),
  119. },
  120. wantError: false,
  121. expected: []string{"C52048C0C0748FEE227D47A2702353E0F7E48EDB"},
  122. wantCapture: []string{},
  123. showFn: func(cmd *exec.Cmd) error {
  124. s := cmd.String()
  125. if strings.Contains(s, "--list-keys") &&
  126. !strings.Contains(s, "11E521D646982372EB577A1F8F0871F202119294") {
  127. return fmt.Errorf("key not found")
  128. }
  129. return nil
  130. },
  131. wantShow: []string{
  132. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  133. "gpg --homedir /tmp --list-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  134. "gpg --homedir /tmp --recv-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  135. },
  136. },
  137. // Two dummy packages with existing keys.
  138. {
  139. name: "two existing",
  140. pkgs: map[string]string{"dummy-4": "", "dummy-5": ""},
  141. srcinfos: map[string]*gosrc.Srcinfo{
  142. "dummy-4": makeSrcinfo("dummy-4", "11E521D646982372EB577A1F8F0871F202119294"),
  143. "dummy-5": makeSrcinfo("dummy-5", "C52048C0C0748FEE227D47A2702353E0F7E48EDB"),
  144. },
  145. wantError: false,
  146. expected: []string{},
  147. wantCapture: []string{},
  148. showFn: func(cmd *exec.Cmd) error {
  149. return nil
  150. },
  151. wantShow: []string{
  152. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  153. "gpg --homedir /tmp --list-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  154. },
  155. },
  156. // Dummy package with invalid key, should fail.
  157. {
  158. name: "one invalid",
  159. pkgs: map[string]string{"dummy-7": ""},
  160. srcinfos: map[string]*gosrc.Srcinfo{"dummy-7": makeSrcinfo("dummy-7", "THIS-SHOULD-FAIL")},
  161. wantError: true,
  162. wantCapture: []string{},
  163. wantShow: []string{
  164. "gpg --homedir /tmp --list-keys THIS-SHOULD-FAIL",
  165. "gpg --homedir /tmp --recv-keys THIS-SHOULD-FAIL",
  166. },
  167. showFn: func(cmd *exec.Cmd) error {
  168. s := cmd.String()
  169. if strings.Contains(s, "--list-keys") {
  170. return fmt.Errorf("key not found")
  171. }
  172. if strings.Contains(s, "--recv-keys") {
  173. return fmt.Errorf("invalid key")
  174. }
  175. return nil
  176. },
  177. },
  178. // Dummy package with both an invalid an another valid key, should fail.
  179. // A314827C4E4250A204CE6E13284FC34C8E4B1A25: Thomas Bächler.
  180. {
  181. name: "one invalid, one valid",
  182. pkgs: map[string]string{"dummy-8": ""},
  183. srcinfos: map[string]*gosrc.Srcinfo{"dummy-8": makeSrcinfo("dummy-8", "A314827C4E4250A204CE6E13284FC34C8E4B1A25", "THIS-SHOULD-FAIL")},
  184. wantError: true,
  185. expected: []string{},
  186. wantCapture: []string{},
  187. showFn: func(cmd *exec.Cmd) error {
  188. s := cmd.String()
  189. if strings.Contains(s, "--list-keys") {
  190. return fmt.Errorf("key not found")
  191. }
  192. if strings.Contains(s, "--recv-keys") {
  193. return fmt.Errorf("invalid key")
  194. }
  195. return nil
  196. },
  197. wantShow: []string{
  198. "gpg --homedir /tmp --list-keys A314827C4E4250A204CE6E13284FC34C8E4B1A25",
  199. "gpg --homedir /tmp --list-keys THIS-SHOULD-FAIL",
  200. "gpg --homedir /tmp --recv-keys A314827C4E4250A204CE6E13284FC34C8E4B1A25 THIS-SHOULD-FAIL",
  201. },
  202. },
  203. }
  204. for _, tt := range testcases {
  205. tt := tt
  206. t.Run(tt.name, func(t *testing.T) {
  207. mockRunner := &exe.MockRunner{
  208. ShowFn: tt.showFn,
  209. CaptureFn: func(cmd *exec.Cmd) (stdout string, stderr string, err error) {
  210. return "", "", nil
  211. },
  212. }
  213. cmdBuilder := exe.CmdBuilder{
  214. GPGBin: gpgBin,
  215. GPGFlags: []string{"--homedir /tmp"},
  216. Runner: mockRunner,
  217. }
  218. problematic, err := CheckPgpKeys(context.Background(), newTestLogger(), tt.pkgs, tt.srcinfos, &cmdBuilder, true)
  219. require.Len(t, mockRunner.ShowCalls, len(tt.wantShow))
  220. require.Len(t, mockRunner.CaptureCalls, len(tt.wantCapture))
  221. sort.SliceStable(mockRunner.ShowCalls, func(i, j int) bool {
  222. return mockRunner.ShowCalls[i].Args[0].(*exec.Cmd).String() < mockRunner.ShowCalls[j].Args[0].(*exec.Cmd).String()
  223. })
  224. for i, call := range mockRunner.ShowCalls {
  225. show := call.Args[0].(*exec.Cmd).String()
  226. show = strings.ReplaceAll(show, gpgBin, "gpg")
  227. // options are in a different order on different systems and on CI root user is used
  228. assert.Subset(t, strings.Split(show, " "), strings.Split(tt.wantShow[i], " "), show)
  229. }
  230. for i, call := range mockRunner.CaptureCalls {
  231. capture := call.Args[0].(*exec.Cmd).String()
  232. capture = strings.ReplaceAll(capture, gpgBin, "gpg")
  233. assert.Subset(t, strings.Split(capture, " "), strings.Split(tt.wantCapture[i], " "), capture)
  234. }
  235. if tt.wantError {
  236. require.Error(t, err)
  237. return
  238. }
  239. require.NoError(t, err)
  240. assert.ElementsMatch(t, tt.expected, problematic, fmt.Sprintf("%#v", problematic))
  241. })
  242. }
  243. }