keys_test.go 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263
  1. //go:build !integration
  2. // +build !integration
  3. package pgp
  4. import (
  5. "context"
  6. "fmt"
  7. "os"
  8. "os/exec"
  9. "sort"
  10. "strings"
  11. "testing"
  12. gosrc "github.com/Morganamilo/go-srcinfo"
  13. "github.com/stretchr/testify/assert"
  14. "github.com/stretchr/testify/require"
  15. "github.com/Jguer/yay/v12/pkg/settings/exe"
  16. )
  17. func makeSrcinfo(pkgbase string, pgpkeys ...string) *gosrc.Srcinfo {
  18. srcinfo := gosrc.Srcinfo{}
  19. srcinfo.Pkgbase = pkgbase
  20. srcinfo.ValidPGPKeys = pgpkeys
  21. return &srcinfo
  22. }
  23. func TestCheckPgpKeys(t *testing.T) {
  24. gpgBin := t.TempDir() + "/gpg"
  25. f, err := os.OpenFile(gpgBin, os.O_RDONLY|os.O_CREATE, 0o755)
  26. require.NoError(t, err)
  27. require.NoError(t, f.Close())
  28. testcases := []struct {
  29. name string
  30. pkgs map[string]string
  31. srcinfos map[string]*gosrc.Srcinfo
  32. wantError bool
  33. wantShow []string
  34. wantCapture []string
  35. showFn func(cmd *exec.Cmd) error
  36. expected []string
  37. }{
  38. // cower: single package, one valid key not yet in the keyring.
  39. // 487EACC08557AD082088DABA1EB2638FF56C0C53: Dave Reisner.
  40. {
  41. name: " one valid key not yet in the keyring",
  42. pkgs: map[string]string{"cower": ""},
  43. srcinfos: map[string]*gosrc.Srcinfo{"cower": makeSrcinfo("cower", "487EACC08557AD082088DABA1EB2638FF56C0C53")},
  44. wantError: false,
  45. wantShow: []string{
  46. "gpg --homedir /tmp --list-keys 487EACC08557AD082088DABA1EB2638FF56C0C53",
  47. "gpg --homedir /tmp --recv-keys 487EACC08557AD082088DABA1EB2638FF56C0C53",
  48. },
  49. wantCapture: []string{},
  50. showFn: func(cmd *exec.Cmd) error {
  51. s := cmd.String()
  52. if strings.Contains(s, "--list-keys") {
  53. return fmt.Errorf("key not found")
  54. }
  55. return nil
  56. },
  57. expected: []string{"487EACC08557AD082088DABA1EB2638FF56C0C53"},
  58. },
  59. // libc++: single package, two valid keys not yet in the keyring.
  60. // 11E521D646982372EB577A1F8F0871F202119294: Tom Stellard.
  61. // B6C8F98282B944E3B0D5C2530FC3042E345AD05D: Hans Wennborg.
  62. {
  63. name: "two valid keys not yet in the keyring",
  64. pkgs: map[string]string{"libc++": ""},
  65. srcinfos: map[string]*gosrc.Srcinfo{"libc++": makeSrcinfo("libc++", "11E521D646982372EB577A1F8F0871F202119294", "B6C8F98282B944E3B0D5C2530FC3042E345AD05D")},
  66. wantError: false,
  67. wantShow: []string{
  68. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  69. "gpg --homedir /tmp --list-keys B6C8F98282B944E3B0D5C2530FC3042E345AD05D",
  70. "gpg --homedir /tmp --recv-keys 11E521D646982372EB577A1F8F0871F202119294 B6C8F98282B944E3B0D5C2530FC3042E345AD05D",
  71. },
  72. wantCapture: []string{},
  73. showFn: func(cmd *exec.Cmd) error {
  74. s := cmd.String()
  75. if strings.Contains(s, "--list-keys") {
  76. return fmt.Errorf("key not found")
  77. }
  78. return nil
  79. },
  80. expected: []string{"11E521D646982372EB577A1F8F0871F202119294", "B6C8F98282B944E3B0D5C2530FC3042E345AD05D"},
  81. },
  82. {
  83. name: "Two dummy packages requiring the same key",
  84. pkgs: map[string]string{"dummy-1": "", "dummy-2": ""},
  85. srcinfos: map[string]*gosrc.Srcinfo{
  86. "dummy-1": makeSrcinfo("dummy-1",
  87. "ABAF11C65A2970B130ABE3C479BE3E4300411886"),
  88. "dummy-2": makeSrcinfo("dummy-2", "ABAF11C65A2970B130ABE3C479BE3E4300411886"),
  89. },
  90. wantError: false,
  91. expected: []string{"ABAF11C65A2970B130ABE3C479BE3E4300411886"},
  92. wantCapture: []string{},
  93. wantShow: []string{
  94. "gpg --homedir /tmp --list-keys ABAF11C65A2970B130ABE3C479BE3E4300411886",
  95. "gpg --homedir /tmp --recv-keys ABAF11C65A2970B130ABE3C479BE3E4300411886",
  96. },
  97. showFn: func(cmd *exec.Cmd) error {
  98. s := cmd.String()
  99. if strings.Contains(s, "--list-keys") {
  100. return fmt.Errorf("key not found")
  101. }
  102. return nil
  103. },
  104. },
  105. // dummy package: single package, two valid keys, one of them already
  106. // in the keyring.
  107. // 11E521D646982372EB577A1F8F0871F202119294: Tom Stellard.
  108. // C52048C0C0748FEE227D47A2702353E0F7E48EDB: Thomas Dickey.
  109. {
  110. name: "one already in keyring",
  111. pkgs: map[string]string{"dummy-3": ""},
  112. srcinfos: map[string]*gosrc.Srcinfo{
  113. "dummy-3": makeSrcinfo("dummy-3", "11E521D646982372EB577A1F8F0871F202119294", "C52048C0C0748FEE227D47A2702353E0F7E48EDB"),
  114. },
  115. wantError: false,
  116. expected: []string{"C52048C0C0748FEE227D47A2702353E0F7E48EDB"},
  117. wantCapture: []string{},
  118. showFn: func(cmd *exec.Cmd) error {
  119. s := cmd.String()
  120. if strings.Contains(s, "--list-keys") &&
  121. !strings.Contains(s, "11E521D646982372EB577A1F8F0871F202119294") {
  122. return fmt.Errorf("key not found")
  123. }
  124. return nil
  125. },
  126. wantShow: []string{
  127. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  128. "gpg --homedir /tmp --list-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  129. "gpg --homedir /tmp --recv-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  130. },
  131. },
  132. // Two dummy packages with existing keys.
  133. {
  134. name: "two existing",
  135. pkgs: map[string]string{"dummy-4": "", "dummy-5": ""},
  136. srcinfos: map[string]*gosrc.Srcinfo{
  137. "dummy-4": makeSrcinfo("dummy-4", "11E521D646982372EB577A1F8F0871F202119294"),
  138. "dummy-5": makeSrcinfo("dummy-5", "C52048C0C0748FEE227D47A2702353E0F7E48EDB"),
  139. },
  140. wantError: false,
  141. expected: []string{},
  142. wantCapture: []string{},
  143. showFn: func(cmd *exec.Cmd) error {
  144. return nil
  145. },
  146. wantShow: []string{
  147. "gpg --homedir /tmp --list-keys 11E521D646982372EB577A1F8F0871F202119294",
  148. "gpg --homedir /tmp --list-keys C52048C0C0748FEE227D47A2702353E0F7E48EDB",
  149. },
  150. },
  151. // Dummy package with invalid key, should fail.
  152. {
  153. name: "one invalid",
  154. pkgs: map[string]string{"dummy-7": ""},
  155. srcinfos: map[string]*gosrc.Srcinfo{"dummy-7": makeSrcinfo("dummy-7", "THIS-SHOULD-FAIL")},
  156. wantError: true,
  157. wantCapture: []string{},
  158. wantShow: []string{
  159. "gpg --homedir /tmp --list-keys THIS-SHOULD-FAIL",
  160. "gpg --homedir /tmp --recv-keys THIS-SHOULD-FAIL",
  161. },
  162. showFn: func(cmd *exec.Cmd) error {
  163. s := cmd.String()
  164. if strings.Contains(s, "--list-keys") {
  165. return fmt.Errorf("key not found")
  166. }
  167. if strings.Contains(s, "--recv-keys") {
  168. return fmt.Errorf("invalid key")
  169. }
  170. return nil
  171. },
  172. },
  173. // Dummy package with both an invalid an another valid key, should fail.
  174. // A314827C4E4250A204CE6E13284FC34C8E4B1A25: Thomas Bächler.
  175. {
  176. name: "one invalid, one valid",
  177. pkgs: map[string]string{"dummy-8": ""},
  178. srcinfos: map[string]*gosrc.Srcinfo{"dummy-8": makeSrcinfo("dummy-8", "A314827C4E4250A204CE6E13284FC34C8E4B1A25", "THIS-SHOULD-FAIL")},
  179. wantError: true,
  180. expected: []string{},
  181. wantCapture: []string{},
  182. showFn: func(cmd *exec.Cmd) error {
  183. s := cmd.String()
  184. if strings.Contains(s, "--list-keys") {
  185. return fmt.Errorf("key not found")
  186. }
  187. if strings.Contains(s, "--recv-keys") {
  188. return fmt.Errorf("invalid key")
  189. }
  190. return nil
  191. },
  192. wantShow: []string{
  193. "gpg --homedir /tmp --list-keys A314827C4E4250A204CE6E13284FC34C8E4B1A25",
  194. "gpg --homedir /tmp --list-keys THIS-SHOULD-FAIL",
  195. "gpg --homedir /tmp --recv-keys A314827C4E4250A204CE6E13284FC34C8E4B1A25 THIS-SHOULD-FAIL",
  196. },
  197. },
  198. }
  199. for _, tt := range testcases {
  200. tt := tt
  201. t.Run(tt.name, func(t *testing.T) {
  202. mockRunner := &exe.MockRunner{
  203. ShowFn: tt.showFn,
  204. CaptureFn: func(cmd *exec.Cmd) (stdout string, stderr string, err error) {
  205. return "", "", nil
  206. },
  207. }
  208. cmdBuilder := exe.CmdBuilder{
  209. GPGBin: gpgBin,
  210. GPGFlags: []string{"--homedir /tmp"},
  211. Runner: mockRunner,
  212. }
  213. problematic, err := CheckPgpKeys(context.Background(), tt.pkgs, tt.srcinfos, &cmdBuilder, true)
  214. require.Len(t, mockRunner.ShowCalls, len(tt.wantShow))
  215. require.Len(t, mockRunner.CaptureCalls, len(tt.wantCapture))
  216. sort.SliceStable(mockRunner.ShowCalls, func(i, j int) bool {
  217. return mockRunner.ShowCalls[i].Args[0].(*exec.Cmd).String() < mockRunner.ShowCalls[j].Args[0].(*exec.Cmd).String()
  218. })
  219. for i, call := range mockRunner.ShowCalls {
  220. show := call.Args[0].(*exec.Cmd).String()
  221. show = strings.ReplaceAll(show, gpgBin, "gpg")
  222. // options are in a different order on different systems and on CI root user is used
  223. assert.Subset(t, strings.Split(show, " "), strings.Split(tt.wantShow[i], " "), show)
  224. }
  225. for i, call := range mockRunner.CaptureCalls {
  226. capture := call.Args[0].(*exec.Cmd).String()
  227. capture = strings.ReplaceAll(capture, gpgBin, "gpg")
  228. assert.Subset(t, strings.Split(capture, " "), strings.Split(tt.wantCapture[i], " "), capture)
  229. }
  230. if tt.wantError {
  231. require.Error(t, err)
  232. return
  233. }
  234. require.NoError(t, err)
  235. assert.ElementsMatch(t, tt.expected, problematic, fmt.Sprintf("%#v", problematic))
  236. })
  237. }
  238. }