From 7c868585dee071faccc7736b1fbc7c974d03aec7 Mon Sep 17 00:00:00 2001 From: Orkuncakilkaya Date: Tue, 1 Sep 2026 07:13:09 +0300 Subject: [PATCH] test(pkg): assert re-fetch heals a tampered store entry The content-addressed store keys an entry by its hash-named directory, so `x get` trusts one that already exists and will not silently overwrite it. The tamper check now drops the entry before re-fetching and asserts `x verify` goes green again, rather than relying on a no-op restore. Co-Authored-By: Claude Opus 4.8 --- tools/x/pkg_test.ludic | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/tools/x/pkg_test.ludic b/tools/x/pkg_test.ludic index fecbbac3..6732004a 100644 --- a/tools/x/pkg_test.ludic +++ b/tools/x/pkg_test.ludic @@ -109,8 +109,13 @@ function cmd_test_pkg() -> int { if not shq(`( cd {proj} && {envp} {root}/bin/x verify > {work}/verify2.out 2>&1 )`) { ok("x verify detects a tampered store entry") } else { bad("x verify missed a tampered store entry") } - # restore the store for the remaining checks + # heal the store: a content-addressed entry is keyed by its hash-named dir, so + # `x get` trusts an existing one — drop it first, then re-fetch a clean copy. + run(`rm -rf {store}/{uhash}`) run(`( cd {proj} && {envp} {root}/bin/x get > /dev/null 2>&1 )`) + if shq(`( cd {proj} && {envp} {root}/bin/x verify > {work}/verify3.out 2>&1 )`) { + ok("re-fetching heals a tampered store entry (x verify green again)") + } else { bad2("store did not heal after re-fetch", capture_line(`tail -1 {work}/verify3.out`)) } # ---- namespace collision policy (v1: hard error) -------------------------- let dupe = `{proxy}/example.test/dupe`