Package workstation tools, reuse emulator sessions, and derive build versions
This commit is contained in:
@@ -33,7 +33,9 @@ def invoke(prefix, arguments, ok=True):
|
||||
def check_all(directory, key, ok=True):
|
||||
for label, command in commands:
|
||||
result = invoke(command, ['verify', directory, '--key', key], ok)
|
||||
if ok: assert 'VERIFIED FDS/OS 0.1.0' in result
|
||||
if ok:
|
||||
expected=json.loads((directory/'manifest.json').read_text())['version']
|
||||
assert f'VERIFIED FDS/OS {expected}' in result
|
||||
|
||||
key_prefix = work / 'test-key'
|
||||
invoke([str(host)], ['keygen', key_prefix])
|
||||
@@ -55,6 +57,13 @@ manifest = {'format': 1, 'version': '0.1.0', 'source_epoch': 1,
|
||||
invoke([str(host)], ['sign', release, '--key', private])
|
||||
check_all(release, public)
|
||||
invoke([str(host)], ['sign', release, '--key', private], False)
|
||||
# Keep the historical release fixture, and also sign the current Git-derived identity.
|
||||
current = work / 'current-version'; current.mkdir()
|
||||
shutil.copy2(release / 'image.img', current / 'image.img')
|
||||
current_manifest = dict(manifest, version=subprocess.check_output([str(project/'tools/version')], text=True).strip())
|
||||
(current / 'manifest.json').write_text(json.dumps(current_manifest))
|
||||
invoke([str(host)], ['sign', current, '--key', private])
|
||||
check_all(current, public)
|
||||
|
||||
# Independent standard Ed25519 verification/signing over the exact domain prefix
|
||||
# and raw manifest bytes. Test-only DER files are private and never printed.
|
||||
@@ -111,7 +120,7 @@ for name in ['traversal', 'duplicate', 'unknown', 'wrong-version', 'unbounded']:
|
||||
if name == 'traversal': value['files'][0]['name'] = '../image.img'
|
||||
elif name == 'duplicate': value['files'].append(copy.deepcopy(value['files'][0]))
|
||||
elif name == 'unknown': value['execute'] = 'sh'
|
||||
elif name == 'wrong-version': value['version'] = '999'
|
||||
elif name == 'wrong-version': value['version'] = '../invalid'
|
||||
(bad / 'manifest.json').write_text(json.dumps(value) + (' ' * (1024 * 1024) if name == 'unbounded' else ''))
|
||||
(bad / 'manifest.sig').write_bytes((release / 'manifest.sig').read_bytes())
|
||||
check_all(bad, public, False)
|
||||
|
||||
Reference in New Issue
Block a user