test(pkg): assert re-fetch heals a tampered store entry
All checks were successful
bootstrap / cfree-fixpoint (push) Successful in 17s
ci / build-and-test (push) Successful in 1m33s
commit-lint / conventional-commits (push) Successful in 2s
docs / build-and-deploy (push) Successful in 26s

The content-addressed store keys an entry by its hash-named directory, so
`x get` trusts one that already exists and will not silently overwrite it.
The tamper check now drops the entry before re-fetching and asserts `x verify`
goes green again, rather than relying on a no-op restore.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Orkun ÇAKILKAYA 2026-09-01 07:13:09 +03:00
parent 2c44bae496
commit 7c868585de

View file

@ -109,8 +109,13 @@ function cmd_test_pkg() -> int {
if not shq(`( cd {proj} && {envp} {root}/bin/x verify > {work}/verify2.out 2>&1 )`) {
ok("x verify detects a tampered store entry")
} else { bad("x verify missed a tampered store entry") }
# restore the store for the remaining checks
# heal the store: a content-addressed entry is keyed by its hash-named dir, so
# `x get` trusts an existing one — drop it first, then re-fetch a clean copy.
run(`rm -rf {store}/{uhash}`)
run(`( cd {proj} && {envp} {root}/bin/x get > /dev/null 2>&1 )`)
if shq(`( cd {proj} && {envp} {root}/bin/x verify > {work}/verify3.out 2>&1 )`) {
ok("re-fetching heals a tampered store entry (x verify green again)")
} else { bad2("store did not heal after re-fetch", capture_line(`tail -1 {work}/verify3.out`)) }
# ---- namespace collision policy (v1: hard error) --------------------------
let dupe = `{proxy}/example.test/dupe`