Skip to content

Regenerate testdata and adapt tests for golang 1.24+ - #1434

Merged
mitch292 merged 7 commits into
cloudflare:masterfrom
elukey:master
Sep 23, 2026
Merged

mitch292 merged 7 commits into
cloudflare:masterfrom
elukey:master

Conversation

@elukey

@elukey elukey commented Mar 11, 2026 •

Copy link
Copy Markdown
Contributor

In golang 1.24+ sha1 signing is not allowed anymore, and a lot of certs in various testdata directories are SHA1 signed. There are also expired certs, that all together make the test suite fails in a lot of way.

I used various AI tools to do the following:

  1. Create reliable build_certs.sh scripts able to regenerate the certs data, documenting how they are related to each other and what are the constraints that tests expect.
  2. Regenerate all the testdata dirs to make the test suite completely pass on golang 1.24+.

Given how old sha1 signing is, I would really vote to get rid of it as a special use case and focus on golang 1.24+ compatibility.

Fixes: #1413 1413

elukey added 5 commits March 11, 2026 14:33
Add scripts to generate all the certs material under the various
testdata directories, together with comments about how they are related
with each other. The idea is to be able to programmatically control and
regenerate the data when needed (certs expired, shaXXX deprecation, ..).

The current issue is that most of the certs are expired or signed
with SHA1, that is not allowed anymore by golang 1.24+.

issue: cloudflare#1413
@elukey

elukey commented Mar 20, 2026

Copy link
Copy Markdown
Contributor Author

@mitch292 Hi! Do you think that the PR is viable to be reviewed for the cfssl repo? It should be a good addition, restoring tests would be of a good benefit for the whole community. Lemme know :)

@mitch292

Copy link
Copy Markdown
Contributor

Hi @elukey - Yes I agree, getting these tests back in order on 1.24 and later would be great! I am just hesitant to commit to being able to have time to review in the short term. I will flag for my team as well to see if someone can take a look.

@elukey

elukey commented May 5, 2026

Copy link
Copy Markdown
Contributor Author

@mitch292 ping :)

@ang-cloudflare ang-cloudflare left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scout review found eight low-severity correctness and test-coverage issues. None is individually blocking, but together they weaken the stated goal of reliable, reproducible Go 1.24+ fixtures.

Comment thread bundler/bundle_from_remote_test.go Outdated
Comment thread bundler/bundler_sha1_deprecation_test.go Outdated
Comment thread bundler/bundler_test.go Outdated
Comment thread bundler/testdata/build_certs.sh
Comment thread bundler/bundler_test.go
Comment thread bundler/testdata/build_certs.sh Outdated
Comment thread bundler/testdata/build_certs.sh Outdated
Comment thread api/testdata/build_certs.sh Outdated
@ang-cloudflare

Copy link
Copy Markdown
Contributor

@elukey I reviewed this PR and opened elukey#1 against your branch with fixes for the review findings. It preserves coverage with hermetic remote-bundling tests, restores SHA-1 behavior coverage where possible, and tightens the fixture generator invariants. If the direction looks good, you can merge that PR directly into this one.

Preserve test coverage in Go 1.24 fixture refresh
@elukey

elukey commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

@ang-cloudflare thank a lot for the review, I merged your changes!

@mitch292

Copy link
Copy Markdown
Contributor

Thank you for the contribution @elukey and thank you @ang-cloudflare for helping out.

@mitch292
mitch292 merged commit 82408a1 into cloudflare:master Sep 23, 2026
6 checks passed
ang-cloudflare added a commit to ang-cloudflare/cfssl that referenced this pull request Sep 25, 2026
golangci-lint v2 rejects the removed gosimple linter and refuses to run
with zero linters. Enable govet, skip the scan/crypto fork that test.sh
already skips, and exclude the pre-existing csr.Name.OID struct tag
warning. Drop the stale cloudflare#1434 note from the CI matrix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The x509sha1 GODEBUG setting has been removed with go1.24, tests relying on sha1 certificates will fail when running with >= go1.24

3 participants