MCPcopy Create free account
hub / github.com/cli/cli / TestSignerWorkflowSANMatchingPinnedRef

Function TestSignerWorkflowSANMatchingPinnedRef

pkg/cmd/attestation/verify/policy_test.go:438–490  ·  view source on GitHub ↗

TestSignerWorkflowSANMatchingPinnedRef covers a --signer-workflow value that pins a ref as well as a workflow. Such a value has to match the end of the SAN exactly, because a git ref may itself be named so that it begins with the pinned ref and is followed by something ref-shaped.

(t *testing.T)

Source from the content-addressed store, hash-verified

436// because a git ref may itself be named so that it begins with the pinned ref and is
437// followed by something ref-shaped.
438func TestSignerWorkflowSANMatchingPinnedRef(t *testing.T) {
439 const pinnedWorkflow = "owner/builder/.github/workflows/release.yml@refs/heads/main"
440 const workflowURL = "https://github.com/owner/builder/.github/workflows/release.yml"
441
442 testcases := []struct {
443 name string
444 san string
445 expectMatch bool
446 }{
447 {
448 name: "the pinned ref",
449 san: workflowURL + "@refs/heads/main",
450 expectMatch: true,
451 },
452 {
453 name: "a branch whose name extends the pinned ref",
454 san: workflowURL + "@refs/heads/mainattacker",
455 expectMatch: false,
456 },
457 {
458 name: "a branch named so that a second ref follows the pinned ref",
459 san: workflowURL + "@refs/heads/main@refs/heads/attacker",
460 expectMatch: false,
461 },
462 {
463 name: "a branch named so that an object ID follows the pinned ref",
464 san: workflowURL + "@refs/heads/main@09b495c3f12c7881b3cc17209a327792065c1a1d",
465 expectMatch: false,
466 },
467 {
468 name: "a different ref",
469 san: workflowURL + "@refs/heads/attacker",
470 expectMatch: false,
471 },
472 }
473
474 sanRegex, err := validateSignerWorkflow("github.com", pinnedWorkflow)
475 require.NoError(t, err)
476
477 matcher, err := verify.NewSANMatcher("", sanRegex)
478 require.NoError(t, err)
479
480 for _, tc := range testcases {
481 t.Run(tc.name, func(t *testing.T) {
482 err := matcher.Verify(certificate.Summary{SubjectAlternativeName: tc.san})
483 if tc.expectMatch {
484 require.NoError(t, err)
485 } else {
486 require.Error(t, err)
487 }
488 })
489 }
490}
491
492// TestSignerWorkflowSANMatchingObservedNestedRef uses the job_workflow_ref claim
493// observed from a workflow run on a branch named "main@refs/heads/evil". Actions runs a

Callers

nothing calls this directly

Calls 4

validateSignerWorkflowFunction · 0.85
RunMethod · 0.65
VerifyMethod · 0.65
ErrorMethod · 0.45

Tested by

no test coverage detected