# A matching line in go.sum must not bypass checksum database verification
# for a downloaded toolchain, since useSumDB requires the checksum database
# for golang.org/toolchain even when GOSUMDB=off.

env GOTOOLCHAIN=local
env sumdb=$GOSUMDB
env proxy=$GOPROXY
env dbname=localhost.localdev/sumdb

go get golang.org/toolchain@v0.0.1-go1.999testmod.$GOOS-$GOARCH
grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]* h1:' go.sum
grep '^golang.org/toolchain v0.0.1-go1.999testmod.[a-z0-9\-]*/go.mod h1:' go.sum

# With the checksum database disabled, the matching go.sum entry
# must not be accepted on its own.
env GOSUMDB=off
! go mod download golang.org/toolchain
stderr 'checksum database disabled by GOSUMDB=off'

# With a checksum database that disagrees with go.sum, the download
# must be rejected even though go.sum matches the downloaded bits.
# Clear cached lookups and the cached tree head so the server is consulted.
go clean -modcache
rm $GOPATH/pkg/sumdb/$dbname/latest
env GOSUMDB=$sumdb' '$proxy/sumdb-wrong
! go mod download golang.org/toolchain
stderr 'verifying (module|go.mod): checksum mismatch'
stderr 'localhost.localdev/sumdb: h1:wrong'
stderr 'SECURITY ERROR'

-- go.mod --
module example.com/m

go 1.21
