TestSignerWorkflowSANMatchingPinnedRef covers a --signer-workflow value that pins a ref as well as a workflow. Such a value has to match the end of the SAN exactly, because a git ref may itself be named so that it begins with the pinned ref and is followed by something ref-shaped.
(t *testing.T)
| 436 | // because a git ref may itself be named so that it begins with the pinned ref and is |
| 437 | // followed by something ref-shaped. |
| 438 | func TestSignerWorkflowSANMatchingPinnedRef(t *testing.T) { |
| 439 | const pinnedWorkflow = "owner/builder/.github/workflows/release.yml@refs/heads/main" |
| 440 | const workflowURL = "https://github.com/owner/builder/.github/workflows/release.yml" |
| 441 | |
| 442 | testcases := []struct { |
| 443 | name string |
| 444 | san string |
| 445 | expectMatch bool |
| 446 | }{ |
| 447 | { |
| 448 | name: "the pinned ref", |
| 449 | san: workflowURL + "@refs/heads/main", |
| 450 | expectMatch: true, |
| 451 | }, |
| 452 | { |
| 453 | name: "a branch whose name extends the pinned ref", |
| 454 | san: workflowURL + "@refs/heads/mainattacker", |
| 455 | expectMatch: false, |
| 456 | }, |
| 457 | { |
| 458 | name: "a branch named so that a second ref follows the pinned ref", |
| 459 | san: workflowURL + "@refs/heads/main@refs/heads/attacker", |
| 460 | expectMatch: false, |
| 461 | }, |
| 462 | { |
| 463 | name: "a branch named so that an object ID follows the pinned ref", |
| 464 | san: workflowURL + "@refs/heads/main@09b495c3f12c7881b3cc17209a327792065c1a1d", |
| 465 | expectMatch: false, |
| 466 | }, |
| 467 | { |
| 468 | name: "a different ref", |
| 469 | san: workflowURL + "@refs/heads/attacker", |
| 470 | expectMatch: false, |
| 471 | }, |
| 472 | } |
| 473 | |
| 474 | sanRegex, err := validateSignerWorkflow("github.com", pinnedWorkflow) |
| 475 | require.NoError(t, err) |
| 476 | |
| 477 | matcher, err := verify.NewSANMatcher("", sanRegex) |
| 478 | require.NoError(t, err) |
| 479 | |
| 480 | for _, tc := range testcases { |
| 481 | t.Run(tc.name, func(t *testing.T) { |
| 482 | err := matcher.Verify(certificate.Summary{SubjectAlternativeName: tc.san}) |
| 483 | if tc.expectMatch { |
| 484 | require.NoError(t, err) |
| 485 | } else { |
| 486 | require.Error(t, err) |
| 487 | } |
| 488 | }) |
| 489 | } |
| 490 | } |
| 491 | |
| 492 | // TestSignerWorkflowSANMatchingObservedNestedRef uses the job_workflow_ref claim |
| 493 | // observed from a workflow run on a branch named "main@refs/heads/evil". Actions runs a |
nothing calls this directly
no test coverage detected