]> git.saurik.com Git - apt.git/blame_incremental - test/integration/test-ubuntu-bug-1098738-apt-get-source-md5sum
add --sha512 option + documentation for apt-ftparchive
[apt.git] / test / integration / test-ubuntu-bug-1098738-apt-get-source-md5sum
... / ...
CommitLineData
1#!/bin/sh
2set -e
3
4TESTDIR=$(readlink -f $(dirname $0))
5. $TESTDIR/framework
6
7setupenvironment
8configarchitecture 'native'
9
10cat > aptarchive/Sources <<EOF
11Package: pkg-md5-ok
12Binary: pkg-md5-ok
13Version: 1.0
14Maintainer: Joe Sixpack <joe@example.org>
15Architecture: all
16Files:
17 9604ba9427a280db542279d9ed78400b 3 pkg-md5-ok_1.0.dsc
18 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-md5-ok_1.0.tar.gz
19
20Package: pkg-sha256-ok
21Binary: pkg-sha256-ok
22Version: 1.0
23Maintainer: Joe Sixpack <joe@example.org>
24Architecture: all
25Files:
26 9604ba9427a280db542279d9ed78400b 3 pkg-sha256-ok_1.0.dsc
27 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-sha256-ok_1.0.tar.gz
28Checksums-Sha1:
29 324f464e6151a92cf57b26ef95dcfcf2059a8c44 3 pkg-sha256-ok_1.0.dsc
30 680254bad1d7ca0d65ec46aaa315d363abf6a50a 3 pkg-sha256-ok_1.0.tar.gz
31Checksums-Sha256:
32 943d3bf22ac661fb0f59bc4ff68cc12b04ff17a838dfcc2537008eb9c7f3770a 3 pkg-sha256-ok_1.0.dsc
33 90aebae315675cbf04612de4f7d5874850f48e0b8dd82becbeaa47ca93f5ebfb 3 pkg-sha256-ok_1.0.tar.gz
34
35Package: pkg-sha256-bad
36Binary: pkg-sha256-bad
37Version: 1.0
38Maintainer: Joe Sixpack <joe@example.org>
39Architecture: all
40Files:
41 9604ba9427a280db542279d9ed78400b 3 pkg-sha256-bad_1.0.dsc
42 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-sha256-bad_1.0.tar.gz
43Checksums-Sha1:
44 324f464e6151a92cf57b26ef95dcfcf2059a8c44 3 pkg-sha256-bad_1.0.dsc
45 680254bad1d7ca0d65ec46aaa315d363abf6a50a 3 pkg-sha256-bad_1.0.tar.gz
46Checksums-Sha256:
47 aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 3 pkg-sha256-bad_1.0.dsc
48 bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb 3 pkg-sha256-bad_1.0.tar.gz
49
50Package: pkg-md5-bad
51Binary: pkg-md5-bad
52Version: 1.0
53Maintainer: Joe Sixpack <joe@example.org>
54Architecture: all
55Files:
56 aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 3 pkg-md5-bad_1.0.dsc
57 bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb 3 pkg-md5-bad_1.0.tar.gz
58
59Package: pkg-no-md5
60Binary: pkg-no-md5
61Version: 1.0
62Maintainer: Joe Sixpack <joe@example.org>
63Architecture: all
64Checksums-Sha1:
65 324f464e6151a92cf57b26ef95dcfcf2059a8c44 3 pkg-no-md5_1.0.dsc
66 680254bad1d7ca0d65ec46aaa315d363abf6a50a 3 pkg-no-md5_1.0.tar.gz
67Checksums-Sha256:
68 943d3bf22ac661fb0f59bc4ff68cc12b04ff17a838dfcc2537008eb9c7f3770a 3 pkg-no-md5_1.0.dsc
69 90aebae315675cbf04612de4f7d5874850f48e0b8dd82becbeaa47ca93f5ebfb 3 pkg-no-md5_1.0.tar.gz
70
71Package: pkg-mixed-ok
72Binary: pkg-mixed-ok
73Version: 1.0
74Maintainer: Joe Sixpack <joe@example.org>
75Architecture: all
76Checksums-Sha1:
77 680254bad1d7ca0d65ec46aaa315d363abf6a50a 3 pkg-mixed-ok_1.0.tar.gz
78Checksums-Sha256:
79 943d3bf22ac661fb0f59bc4ff68cc12b04ff17a838dfcc2537008eb9c7f3770a 3 pkg-mixed-ok_1.0.dsc
80
81Package: pkg-mixed-sha1-bad
82Binary: pkg-mixed-sha1-bad
83Version: 1.0
84Maintainer: Joe Sixpack <joe@example.org>
85Architecture: all
86Checksums-Sha1:
87 aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 3 pkg-mixed-sha1-bad_1.0.dsc
88Checksums-Sha256:
89 90aebae315675cbf04612de4f7d5874850f48e0b8dd82becbeaa47ca93f5ebfb 3 pkg-mixed-sha1-bad_1.0.tar.gz
90
91Package: pkg-mixed-sha2-bad
92Binary: pkg-mixed-sha2-bad
93Version: 1.0
94Maintainer: Joe Sixpack <joe@example.org>
95Architecture: all
96Checksums-Sha1:
97 324f464e6151a92cf57b26ef95dcfcf2059a8c44 3 pkg-mixed-sha2-bad_1.0.dsc
98Checksums-Sha256:
99 bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb 3 pkg-mixed-sha2-bad_1.0.tar.gz
100
101Package: pkg-md5-disagree
102Binary: pkg-md5-disagree
103Version: 1.0
104Maintainer: Joe Sixpack <joe@example.org>
105Architecture: all
106Files:
107 9604ba9427a280db542279d9ed78400b 3 pkg-md5-disagree_1.0.dsc
108 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-md5-disagree_1.0.tar.gz
109 aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 3 pkg-md5-disagree_1.0.dsc
110 bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb 3 pkg-md5-disagree_1.0.tar.gz
111
112Package: pkg-md5-agree
113Binary: pkg-md5-agree
114Version: 1.0
115Maintainer: Joe Sixpack <joe@example.org>
116Architecture: all
117Files:
118 9604ba9427a280db542279d9ed78400b 3 pkg-md5-agree_1.0.dsc
119 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-md5-agree_1.0.tar.gz
120 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-md5-agree_1.0.tar.gz
121 9604ba9427a280db542279d9ed78400b 3 pkg-md5-agree_1.0.dsc
122
123Package: pkg-sha256-disagree
124Binary: pkg-sha256-disagree
125Version: 1.0
126Maintainer: Joe Sixpack <joe@example.org>
127Architecture: all
128Files:
129 9604ba9427a280db542279d9ed78400b 3 pkg-sha256-disagree_1.0.dsc
130 db5570bf61464b46e2bde31ed61a7dc6 3 pkg-sha256-disagree_1.0.tar.gz
131Checksums-Sha1:
132 324f464e6151a92cf57b26ef95dcfcf2059a8c44 3 pkg-sha256-disagree_1.0.dsc
133 680254bad1d7ca0d65ec46aaa315d363abf6a50a 3 pkg-sha256-disagree_1.0.tar.gz
134Checksums-Sha256:
135 943d3bf22ac661fb0f59bc4ff68cc12b04ff17a838dfcc2537008eb9c7f3770a 3 pkg-sha256-disagree_1.0.dsc
136 90aebae315675cbf04612de4f7d5874850f48e0b8dd82becbeaa47ca93f5ebfb 3 pkg-sha256-disagree_1.0.tar.gz
137 aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 3 pkg-sha256-disagree_1.0.dsc
138 bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb 3 pkg-sha256-disagree_1.0.tar.gz
139EOF
140
141# create fetchable files
142for x in 'pkg-md5-ok' 'pkg-sha256-ok' 'pkg-sha256-bad' 'pkg-no-md5' \
143 'pkg-mixed-ok' 'pkg-mixed-sha1-bad' 'pkg-mixed-sha2-bad' \
144 'pkg-md5-agree' 'pkg-md5-disagree' 'pkg-sha256-disagree' \
145 'pkg-md5-bad'; do
146 echo -n 'dsc' > aptarchive/${x}_1.0.dsc
147 echo -n 'tar' > aptarchive/${x}_1.0.tar.gz
148done
149
150setupaptarchive --no-update
151changetowebserver
152testsuccess aptget update
153
154cd downloaded
155
156testok() {
157 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
158 testsuccessequal "Reading package lists...
159Building dependency tree...
160Need to get 6 B of source archives.
161Get:1 http://localhost:8080 $1 1.0 (dsc) [3 B]
162Get:2 http://localhost:8080 $1 1.0 (tar) [3 B]
163Download complete and in download only mode" aptget source -d "$@"
164 msgtest 'Files were successfully downloaded for' "$1"
165 testsuccess --nomsg test -e ${1}_1.0.dsc -a -e ${1}_1.0.tar.gz
166 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
167}
168
169testkeep() {
170 echo -n 'dsc' > ${1}_1.0.dsc
171 echo -n 'tar' > ${1}_1.0.tar.gz
172 testsuccessequal "Reading package lists...
173Building dependency tree...
174Skipping already downloaded file '${1}_1.0.dsc'
175Skipping already downloaded file '${1}_1.0.tar.gz'
176Need to get 0 B of source archives.
177Download complete and in download only mode" aptget source -d "$@"
178 msgtest 'Files already downloaded are kept for' "$1"
179 testsuccess --nomsg test -e ${1}_1.0.dsc -a -e ${1}_1.0.tar.gz
180 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
181}
182
183testnohash() {
184 #FIXME: Maybe we should fail in this case instead of skipping
185 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
186 testsuccessequal "Reading package lists...
187Building dependency tree...
188Skipping download of file '${1}_1.0.dsc' as requested hashsum is not available for authentication
189Skipping download of file '${1}_1.0.tar.gz' as requested hashsum is not available for authentication
190Need to get 0 B of source archives.
191Download complete and in download only mode" aptget source -d "$@"
192 msgtest 'Files are not downloaded for' "$1"
193 testfailure --nomsg test -e ${1}_1.0.dsc -o -e ${1}_1.0.tar.gz
194}
195
196testmismatch() {
197 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
198 testfailureequal "Reading package lists...
199Building dependency tree...
200Need to get 6 B of source archives.
201Get:1 http://localhost:8080 $1 1.0 (dsc) [3 B]
202Err:1 http://localhost:8080 $1 1.0 (dsc)
203 Hash Sum mismatch
204Get:2 http://localhost:8080 $1 1.0 (tar) [3 B]
205Err:2 http://localhost:8080 $1 1.0 (tar)
206 Hash Sum mismatch
207E: Failed to fetch http://localhost:8080/${1}_1.0.dsc Hash Sum mismatch
208
209E: Failed to fetch http://localhost:8080/${1}_1.0.tar.gz Hash Sum mismatch
210
211E: Failed to fetch some archives." aptget source -d "$@"
212 msgtest 'Files were not download as they have hashsum mismatches for' "$1"
213 testfailure --nomsg test -e ${1}_1.0.dsc -a -e ${1}_1.0.tar.gz
214
215 if [ "$2" != '--allow-unauthenticated' ]; then
216 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
217 testsuccessequal "Reading package lists...
218Building dependency tree...
219Skipping download of file '${1}_1.0.dsc' as requested hashsum is not available for authentication
220Skipping download of file '${1}_1.0.tar.gz' as requested hashsum is not available for authentication
221Need to get 0 B of source archives.
222Download complete and in download only mode" aptget source -d "$@" -o Acquire::ForceHash=ROT26
223 msgtest 'Files were not download as hash is unavailable for' "$1"
224 testfailure --nomsg test -e ${1}_1.0.dsc -a -e ${1}_1.0.tar.gz
225 fi
226
227 rm -f ${1}_1.0.dsc ${1}_1.0.tar.gz
228 testsuccessequal "Reading package lists...
229Building dependency tree...
230Need to get 6 B of source archives.
231Get:1 http://localhost:8080 $1 1.0 (dsc) [3 B]
232Get:2 http://localhost:8080 $1 1.0 (tar) [3 B]
233Download complete and in download only mode" aptget source --allow-unauthenticated -d "$@" -o Acquire::ForceHash=ROT26
234 msgtest 'Files were downloaded unauthenticated as user allowed it' "$1"
235 testsuccess --nomsg test -e ${1}_1.0.dsc -a -e ${1}_1.0.tar.gz
236}
237
238testnohash pkg-md5-ok
239testok pkg-sha256-ok
240testkeep pkg-sha256-ok
241
242# pkg-sha256-bad has a bad SHA sum, but good MD5 sum. If apt is
243# checking the best available hash (as it should), this will trigger
244# a hash mismatch.
245testmismatch pkg-sha256-bad
246testok pkg-sha256-bad -o Acquire::ForceHash=MD5Sum
247
248testnohash pkg-md5-bad
249testmismatch pkg-md5-bad --allow-unauthenticated
250
251# not having MD5 sum doesn't mean the file doesn't exist at all …
252testok pkg-no-md5
253testok pkg-no-md5 -o Acquire::ForceHash=SHA256
254testsuccessequal "Reading package lists...
255Building dependency tree...
256Skipping download of file 'pkg-no-md5_1.0.dsc' as requested hashsum is not available for authentication
257Skipping download of file 'pkg-no-md5_1.0.tar.gz' as requested hashsum is not available for authentication
258Need to get 0 B of source archives.
259Download complete and in download only mode" aptget source -d pkg-no-md5 -o Acquire::ForceHash=MD5Sum
260msgtest 'Files were not download as MD5 is not available for this package' 'pkg-no-md5'
261testfailure --nomsg test -e pkg-no-md5_1.0.dsc -a -e pkg-no-md5_1.0.tar.gz
262
263# deal with cases in which we haven't for all files the same checksum type
264# mostly pathologic as this shouldn't happen, but just to be sure
265testok pkg-mixed-ok
266testfailureequal 'Reading package lists...
267Building dependency tree...
268Need to get 6 B of source archives.
269Get:1 http://localhost:8080 pkg-mixed-sha1-bad 1.0 (tar) [3 B]
270Get:2 http://localhost:8080 pkg-mixed-sha1-bad 1.0 (dsc) [3 B]
271Err:2 http://localhost:8080 pkg-mixed-sha1-bad 1.0 (dsc)
272 Hash Sum mismatch
273E: Failed to fetch http://localhost:8080/pkg-mixed-sha1-bad_1.0.dsc Hash Sum mismatch
274
275E: Failed to fetch some archives.' aptget source -d pkg-mixed-sha1-bad
276msgtest 'Only tar file is downloaded as the dsc has hashsum mismatch' 'pkg-mixed-sha1-bad'
277testsuccess --nomsg test ! -e pkg-mixed-sha1-bad_1.0.dsc -a -e pkg-mixed-sha1-bad_1.0.tar.gz
278testfailureequal 'Reading package lists...
279Building dependency tree...
280Need to get 6 B of source archives.
281Get:1 http://localhost:8080 pkg-mixed-sha2-bad 1.0 (tar) [3 B]
282Err:1 http://localhost:8080 pkg-mixed-sha2-bad 1.0 (tar)
283 Hash Sum mismatch
284Get:2 http://localhost:8080 pkg-mixed-sha2-bad 1.0 (dsc) [3 B]
285E: Failed to fetch http://localhost:8080/pkg-mixed-sha2-bad_1.0.tar.gz Hash Sum mismatch
286
287E: Failed to fetch some archives.' aptget source -d pkg-mixed-sha2-bad
288msgtest 'Only dsc file is downloaded as the tar has hashsum mismatch' 'pkg-mixed-sha2-bad'
289testsuccess --nomsg test -e pkg-mixed-sha2-bad_1.0.dsc -a ! -e pkg-mixed-sha2-bad_1.0.tar.gz
290
291# it gets even more pathologic: multiple entries for one file, some even disagreeing!
292testnohash pkg-md5-agree
293testfailureequal 'Reading package lists...
294Building dependency tree...
295E: Error parsing checksum in Files of source package pkg-md5-disagree' aptget source -d pkg-md5-disagree
296testfailureequal 'Reading package lists...
297Building dependency tree...
298E: Error parsing checksum in Checksums-SHA256 of source package pkg-sha256-disagree' aptget source -d pkg-sha256-disagree