Skip to content

Phase 12.L.E.5 — SHA256 mismatch on Linux (E12.u1-Linux)

Placeholder ppxd requested to merge phase12.L.E.5-linux-sha-mismatch into main

Summary

Linux analog of Windows E12.u1. Closes the SHA256 integrity-gate verification on the Linux side — the integrity gate against MITM-tampered downloads + corrupted air-gap mirror copies.

Without exercising the full curl → fetch → compare → exit chain, a regression in any layer could silently allow tampered binaries through.

Test mechanism

  • LocalReleaseMirror.StageSha256Override("0000...0000") — 64 zeros is a valid hex format the .sh regex (^[0-9a-fA-F]{64}$) accepts but real tarball's SHA can't possibly match
  • Real tarball served + downloaded + sha256sum'd locally
  • Compare fails → exit 7

Reverse-asserts (4 customMessages, each diagnosing a different regression)

Wrong exit Likely cause
exit 0 SHA verify SKIPPED entirely — SECURITY REGRESSION
exit 3 Extract missing binary — SHA verify passed when shouldn't
exit 6 Download not reachable — mirror config issue
exit 7 Correct (the documented mismatch path)

Plus: status MUST be FAILED (not silently succeed), detail MUST contain "SHA256 mismatch" (operator-actionable).

Local verification (macOS)

7/7 pass (3 cross-platform run, 4 Linux-only skip-guard). Linux runner verification on this PR.

Next (J.L.E.6+)

Linux full lifecycle E1.h analog — needs LinuxServiceFixture-installed unit + Phase B handoff via systemd-run --scope + systemctl restart. Largest single Linux PR ahead.

🤖 Generated with Claude Code

Merge request reports

Loading