mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-10 23:49:09 +02:00
[client] Drop go.step.sm/crypto and the repo-wide upgrades it imposed
The TSS2 parser was the only thing in the repository that used this module, and it brought 302 modules into the graph to do it — 35 of them linters, along with Google Cloud KMS and IAM, the AWS SDK and a terminal styling library. Those are the module's own development dependencies, which minimal version selection turns into floors in ours, and they are the whole reason gRPC, protobuf, the AWS SDK, OpenTelemetry, logrus and five x/ packages had moved. Management, signal, relay and proxy inherited every one of them for a feature none of them runs. Removing the import is not enough, because tidy never downgrades: the raised floors stay written in go.mod. Each one is pinned back to the version main had, then tidy is left to raise again whatever something still genuinely needs. It raised nothing: all 43 are back where they were, and go-tpm was already in the graph at the same version, so the certificate feature now costs no new module at all. The differential tests go with it. They existed to check the swap against the library while both were present, and there is nothing left to compare against.
This commit is contained in:
@@ -1,101 +0,0 @@
|
||||
package tpm
|
||||
|
||||
import (
|
||||
"crypto/ecdsa"
|
||||
"crypto/elliptic"
|
||||
"crypto/rand"
|
||||
"encoding/pem"
|
||||
"testing"
|
||||
|
||||
legacy "github.com/google/go-tpm/legacy/tpm2"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"go.step.sm/crypto/tpm/tss2"
|
||||
|
||||
"github.com/netbirdio/netbird/client/internal/tpm/tpmtest"
|
||||
)
|
||||
|
||||
// publicArea builds the public area of a P-256 signing key holding pub.
|
||||
func publicArea(t *testing.T, pub *ecdsa.PublicKey) []byte {
|
||||
t.Helper()
|
||||
area := tpmtest.SigningTemplate()
|
||||
area.ECCParameters.Point = legacy.ECPoint{
|
||||
XRaw: pub.X.FillBytes(make([]byte, 32)),
|
||||
YRaw: pub.Y.FillBytes(make([]byte, 32)),
|
||||
}
|
||||
encoded, err := area.Encode()
|
||||
require.NoError(t, err)
|
||||
return encoded
|
||||
}
|
||||
|
||||
// TestParseTSS2_AgreesWithStep is scaffolding for one commit: it holds the replacement
|
||||
// parser against the library it replaces, over bytes that library itself wrote, so the
|
||||
// swap is checked rather than asserted. It goes away with the dependency.
|
||||
func TestParseTSS2_AgreesWithStep(t *testing.T) {
|
||||
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
||||
require.NoError(t, err)
|
||||
public := publicArea(t, &key.PublicKey)
|
||||
|
||||
for _, tc := range []struct {
|
||||
name string
|
||||
opts []tss2.TPMOption
|
||||
}{
|
||||
{name: "owner hierarchy parent"},
|
||||
{name: "persistent parent", opts: []tss2.TPMOption{tss2.WithParent(0x81000001)}},
|
||||
} {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
encoded, err := tss2.New(public, []byte("placeholder"), tc.opts...).EncodeToMemory()
|
||||
require.NoError(t, err)
|
||||
block, _ := pem.Decode(encoded)
|
||||
require.NotNil(t, block)
|
||||
|
||||
want, err := tss2.ParsePrivateKey(block.Bytes)
|
||||
require.NoError(t, err)
|
||||
got, err := parseTSS2(block.Bytes)
|
||||
require.NoError(t, err, "the replacement must accept what the library writes")
|
||||
|
||||
assert.Equal(t, want.Type, got.Type, "key type")
|
||||
assert.Equal(t, want.EmptyAuth, got.EmptyAuth, "emptyAuth")
|
||||
assert.Equal(t, want.Parent, got.Parent, "parent handle")
|
||||
assert.Equal(t, want.PublicKey, got.PublicKey, "public area")
|
||||
assert.Equal(t, want.PrivateKey, got.PrivateKey, "private area")
|
||||
|
||||
wantPub, err := want.Public()
|
||||
require.NoError(t, err)
|
||||
signer, err := ParseKey(block.Bytes)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, wantPub, signer.Public(), "the decoded public key must be identical")
|
||||
assert.True(t, key.PublicKey.Equal(signer.Public()), "and must be the key the fixture was built from")
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestEncodeTSS2_ReadableByStep checks the other direction: the fixtures the tests are
|
||||
// built on are the shape the format calls for, not merely the shape this package reads.
|
||||
func TestEncodeTSS2_ReadableByStep(t *testing.T) {
|
||||
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
||||
require.NoError(t, err)
|
||||
|
||||
for _, tc := range []struct {
|
||||
name string
|
||||
opts []tpmtest.Option
|
||||
}{
|
||||
{name: "owner hierarchy parent"},
|
||||
{name: "persistent parent", opts: []tpmtest.Option{tpmtest.WithParent(0x81000001)}},
|
||||
{name: "needs authorization", opts: []tpmtest.Option{tpmtest.WithAuth()}},
|
||||
} {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
block, _ := pem.Decode([]byte(tpmtest.KeyPEM(t, &key.PublicKey, tc.opts...)))
|
||||
require.NotNil(t, block)
|
||||
|
||||
want, err := tss2.ParsePrivateKey(block.Bytes)
|
||||
require.NoError(t, err, "the library under replacement must accept our fixtures")
|
||||
got, err := parseTSS2(block.Bytes)
|
||||
require.NoError(t, err)
|
||||
|
||||
assert.Equal(t, want.EmptyAuth, got.EmptyAuth, "emptyAuth")
|
||||
assert.Equal(t, want.Parent, got.Parent, "parent handle")
|
||||
assert.Equal(t, want.PublicKey, got.PublicKey, "public area")
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user