Regenerate testdata and adapt tests for golang 1.24+ - #1434
Conversation
Add scripts to generate all the certs material under the various testdata directories, together with comments about how they are related with each other. The idea is to be able to programmatically control and regenerate the data when needed (certs expired, shaXXX deprecation, ..). The current issue is that most of the certs are expired or signed with SHA1, that is not allowed anymore by golang 1.24+. issue: cloudflare#1413
|
@mitch292 Hi! Do you think that the PR is viable to be reviewed for the cfssl repo? It should be a good addition, restoring tests would be of a good benefit for the whole community. Lemme know :) |
|
Hi @elukey - Yes I agree, getting these tests back in order on 1.24 and later would be great! I am just hesitant to commit to being able to have time to review in the short term. I will flag for my team as well to see if someone can take a look. |
|
@mitch292 ping :) |
ang-cloudflare
left a comment
There was a problem hiding this comment.
Scout review found eight low-severity correctness and test-coverage issues. None is individually blocking, but together they weaken the stated goal of reliable, reproducible Go 1.24+ fixtures.
|
@elukey I reviewed this PR and opened elukey#1 against your branch with fixes for the review findings. It preserves coverage with hermetic remote-bundling tests, restores SHA-1 behavior coverage where possible, and tightens the fixture generator invariants. If the direction looks good, you can merge that PR directly into this one. |
Preserve test coverage in Go 1.24 fixture refresh
|
@ang-cloudflare thank a lot for the review, I merged your changes! |
|
Thank you for the contribution @elukey and thank you @ang-cloudflare for helping out. |
golangci-lint v2 rejects the removed gosimple linter and refuses to run with zero linters. Enable govet, skip the scan/crypto fork that test.sh already skips, and exclude the pre-existing csr.Name.OID struct tag warning. Drop the stale cloudflare#1434 note from the CI matrix.
In golang 1.24+ sha1 signing is not allowed anymore, and a lot of certs in various testdata directories are SHA1 signed. There are also expired certs, that all together make the test suite fails in a lot of way.
I used various AI tools to do the following:
Given how old sha1 signing is, I would really vote to get rid of it as a special use case and focus on golang 1.24+ compatibility.
Fixes: #1413 1413