fix: require exact package manifest checksums

This commit is contained in:
Hermes Agent
2026-09-03 22:31:40 +00:00
parent a9237346fa
commit 0556a3610b
7 changed files with 22 additions and 3 deletions
+10
View File
@@ -104,6 +104,16 @@ def main():
fail(f"package doctor stale-lock diagnostic was unclear:\n{out}")
(work / "claro.lock").write_text(lock, encoding="utf-8")
checksum_line = next((line for line in manifest.splitlines() if line.startswith("checksum:")), "")
checksum = checksum_line.split(":", 1)[1].strip()
manifest_path.write_text(manifest.replace("checksum: " + checksum, "checksum: " + checksum + "-extra"), encoding="utf-8")
rc, out = run([str(EXE), "package", "doctor"], work)
if rc == 0:
fail("package doctor must reject a manifest checksum with trailing data")
if "BAD package checksum: math-tools" not in out:
fail(f"Package manifest checksum diagnostic was unclear:\n{out}")
manifest_path.write_text(manifest, encoding="utf-8")
rc, out = run([str(EXE), "package", "doctor"], work)
if rc != 0:
fail(out)