|
|
|
|
#!/usr/bin/env bash
|
|
|
|
|
# Local gate: the same checks as .gitea/workflows/ci.yml, for any machine and
|
|
|
|
|
# for forges without runners. Run it before every push.
|
|
|
|
|
#
|
|
|
|
|
# scripts/check.sh # format, modules, vet, race tests, coverage,
|
Recovery check: open fixtures with the annex and no DateKeys code
scripts/recovery is a program that opens a capsule with only the Go
standard library, golang.org/x/crypto, filippo.io/age and the BLS12-381
library of drand/kyber-bls12381, as the informative annex of the draft
v0.15 describes it: the pinned Quicknet parameters, the release object,
the frame, the BLS verification of the release, the tlock stanza with H2,
H3 and H4, the age file of SEALED_CONTROL opened with its file key (HKDF,
header MAC and STREAM written out), the X25519 layers with age, and the
content of formats 1, 2 and 3. A test forbids importing this module, tlock
and drand. scripts/recovery_check.sh opens a time_only and a time_and_key
fixture of format 3 with it and compares what it recovers; scripts/check.sh
runs it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 day ago
|
|
|
# # govulncheck, the recovery check, vectors
|
|
|
|
|
# # and fixtures
|
|
|
|
|
# scripts/check.sh 20s # additionally fuzz every parser for 20 s
|
|
|
|
|
set -euo pipefail
|
|
|
|
|
cd "$(dirname "$0")/.."
|
|
|
|
|
|
|
|
|
|
fuzz="${1:-}"
|
|
|
|
|
|
|
|
|
|
echo "== gofmt"
|
|
|
|
|
bad=$(gofmt -l .)
|
|
|
|
|
if [ -n "$bad" ]; then
|
|
|
|
|
echo "not formatted:"; echo "$bad"; exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
echo "== go mod verify"
|
|
|
|
|
go mod verify
|
|
|
|
|
|
|
|
|
|
echo "== go mod tidy leaves go.mod and go.sum unchanged"
|
|
|
|
|
tmp=$(mktemp -d)
|
|
|
|
|
cp go.mod go.sum "$tmp"/
|
|
|
|
|
go mod tidy
|
|
|
|
|
if ! cmp -s go.mod "$tmp/go.mod" || ! cmp -s go.sum "$tmp/go.sum"; then
|
|
|
|
|
cp "$tmp"/go.mod "$tmp"/go.sum .
|
|
|
|
|
rm -rf "$tmp"
|
|
|
|
|
echo "go mod tidy would change go.mod or go.sum"; exit 1
|
|
|
|
|
fi
|
|
|
|
|
rm -rf "$tmp"
|
|
|
|
|
|
|
|
|
|
echo "== go vet"
|
|
|
|
|
go vet ./...
|
|
|
|
|
|
|
|
|
|
echo "== go test -race"
|
|
|
|
|
go test -race -count=1 ./...
|
|
|
|
|
|
|
|
|
|
echo "== coverage: at least 90 % in codec, capsule, accesskey, datekey and agewrap"
|
|
|
|
|
for pkg in codec capsule accesskey datekey agewrap; do
|
|
|
|
|
pct=$(go test -count=1 -cover "./$pkg" | sed -n 's/.*coverage: \([0-9.]*\)% of statements.*/\1/p')
|
|
|
|
|
echo "$pkg: $pct%"
|
|
|
|
|
awk -v p="$pct" 'BEGIN { exit !(p >= 90) }'
|
|
|
|
|
done
|
|
|
|
|
|
|
|
|
|
echo "== govulncheck"
|
|
|
|
|
go run golang.org/x/vuln/cmd/govulncheck@v1.8.0 ./...
|
|
|
|
|
|
Recovery check: open fixtures with the annex and no DateKeys code
scripts/recovery is a program that opens a capsule with only the Go
standard library, golang.org/x/crypto, filippo.io/age and the BLS12-381
library of drand/kyber-bls12381, as the informative annex of the draft
v0.15 describes it: the pinned Quicknet parameters, the release object,
the frame, the BLS verification of the release, the tlock stanza with H2,
H3 and H4, the age file of SEALED_CONTROL opened with its file key (HKDF,
header MAC and STREAM written out), the X25519 layers with age, and the
content of formats 1, 2 and 3. A test forbids importing this module, tlock
and drand. scripts/recovery_check.sh opens a time_only and a time_and_key
fixture of format 3 with it and compares what it recovers; scripts/check.sh
runs it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 day ago
|
|
|
echo "== the recovery annex opens fixtures without DateKeys code"
|
|
|
|
|
bash scripts/recovery_check.sh
|
|
|
|
|
|
|
|
|
|
echo "== vectors reproduce and fixtures are frozen"
|
|
|
|
|
go run ./internal/testkit/genfixtures -out testdata
|
|
|
|
|
git diff --exit-code -- testdata
|
|
|
|
|
|
|
|
|
|
if [ -n "$fuzz" ]; then
|
|
|
|
|
echo "== fuzz every parser for $fuzz"
|
|
|
|
|
./scripts/fuzz.sh "$fuzz"
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
echo "all checks passed"
|