3 ms·
By default, all go mod downloads go through the golang proxy (https://proxy.golang.org/ https://proxy.golang.org/). That is part of the verification process.
by JetSetIlly 9mo ago
By default, all go mod downloads go through the golang proxy (https://proxy.golang.org/ https://proxy.golang.org/). That is part of the verification process.
- zelphirkalt 9mo agoDoes this mean, that when you change the proxy, you lose all guarantees?
- arccy 9mo agoOnly if you change checksum servers https://sum.golang.org/ https://sum.golang.org/ Note that the default one uses data from https://proxy.golang.org/ https://proxy.golang.org/
- wereHamster 9mo agoLet's assume I publish a github repo with some go code, and tag a particular commit with tag v1.0.0. People start using it and put v1.0.0 into their go.mod file. They use the golang proxy to fetch the code (and that proxy does the "verification", according to your comment). Now I delete the v1.0.0 tag and re-create the tag to point to different (malicious) commit. Will the golang proxy notice? How does it verify that the people that expect the former commit under the v1.0.0 tag will actually get that and not the other (malicious) commit?
- compsciphd 9mo agoyes. From my understanding its stored forever in the proxy cache and your new tag will never be fetched by users who go through the language's centralized infrastructure (i.e. proxy). go can also validate the checksums (go.sum) against the languages central infrastructure that associates version->checksums. i.e. if you cut a release, realize you made a mistake and try to fix it quitely, no user will ever see it if even one user saw the previous version (and that one user is probably you, as you probably fetched it through the proxy to see the mistake)
- kibwen 9mo ago> its stored forever in the proxy cache This is mistaken. The Go module proxy doesn't make any guarantee that it will permanently store the checksum for any given module. From the outside, we would expect that their policy is to only ever delete checksums for modules that haven't been fetched in a long time. But in general, you should not base your security model on the notion that these checksums are stored permanently.
- agwa 9mo ago> The Go module proxy doesn't make any guarantee that it will permanently store the checksum for any given module Incorrect. Checksums are stored forever, in a Merkle Tree, meaning if the proxy were to ever delete a checksum, it would be detected (and yes, people like me are checking - https://sourcespotter.com/sumdb https://sourcespotter.com/sumdb). Like any code host, the proxy does not guarantee that the code for a module will be available forever, since code may have to be removed for legal reasons. But you absolutely can rely on the checksum being preserved and thus you can be sure you'll never be given different code for a particular version.
- kibwen 9mo agoAh, my mistake. I had read in the FAQ that it does not guarantee that data is stored forever, but overlooked the part about preserving checksums specifically.
- neild 9mo agoTo be very pedantic, there are two separate services: The module proxy (proxy.golang.org) serves cached modules and makes no guarantees about how long cache entries are kept. The sum database (sum.golang.org) serves module checksums, which are kept forever in a Merkle tree/transparency log.
- wereHamster 9mo agoOk. So to answer the question whether the code for v1.0.0 that I downloaded today is the same as I downloaded yesterday (or whether the code that I get is the same as the one my coworker is getting) you basically have to trust Google.