Phase 12.L.E.5 — SHA256 mismatch on Linux (E12.u1-Linux)
Summary
Linux analog of Windows E12.u1. Closes the SHA256 integrity-gate verification on the Linux side — the integrity gate against MITM-tampered downloads + corrupted air-gap mirror copies.
Without exercising the full curl → fetch → compare → exit chain, a regression in any layer could silently allow tampered binaries through.
Test mechanism
-
LocalReleaseMirror.StageSha256Override("0000...0000")— 64 zeros is a valid hex format the.shregex (^[0-9a-fA-F]{64}$) accepts but real tarball's SHA can't possibly match - Real tarball served + downloaded +
sha256sum'd locally - Compare fails → exit 7
Reverse-asserts (4 customMessages, each diagnosing a different regression)
| Wrong exit | Likely cause |
|---|---|
| exit 0 | SHA verify SKIPPED entirely — SECURITY REGRESSION |
| exit 3 | Extract missing binary — SHA verify passed when shouldn't |
| exit 6 | Download not reachable — mirror config issue |
| exit 7 | Correct (the documented mismatch path) |
Plus: status MUST be FAILED (not silently succeed), detail MUST contain "SHA256 mismatch" (operator-actionable).
Local verification (macOS)
7/7 pass (3 cross-platform run, 4 Linux-only skip-guard). Linux runner verification on this PR.
Next (J.L.E.6+)
Linux full lifecycle E1.h analog — needs LinuxServiceFixture-installed unit + Phase B handoff via systemd-run --scope + systemctl restart. Largest single Linux PR ahead.