2017-09-26 14:43:52 -04:00
|
|
|
package trust
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"io/ioutil"
|
|
|
|
"os"
|
2017-10-25 13:45:10 -04:00
|
|
|
"path/filepath"
|
2018-02-27 10:54:36 -05:00
|
|
|
"runtime"
|
2017-09-26 14:43:52 -04:00
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/docker/cli/cli/config"
|
|
|
|
"github.com/docker/cli/internal/test"
|
2018-03-08 08:35:17 -05:00
|
|
|
notaryfake "github.com/docker/cli/internal/test/notary"
|
2017-10-30 12:21:41 -04:00
|
|
|
"github.com/theupdateframework/notary"
|
2020-02-22 12:12:14 -05:00
|
|
|
"gotest.tools/v3/assert"
|
|
|
|
is "gotest.tools/v3/assert/cmp"
|
2017-09-26 14:43:52 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestTrustSignerAddErrors(t *testing.T) {
|
|
|
|
testCases := []struct {
|
|
|
|
name string
|
|
|
|
args []string
|
|
|
|
expectedError string
|
|
|
|
}{
|
|
|
|
{
|
|
|
|
name: "not-enough-args",
|
|
|
|
expectedError: "requires at least 2 argument",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "no-key",
|
|
|
|
args: []string{"foo", "bar"},
|
2017-10-25 13:45:10 -04:00
|
|
|
expectedError: "path to a public key must be provided using the `--key` flag",
|
2017-09-26 14:43:52 -04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "reserved-releases-signer-add",
|
2017-10-25 13:45:10 -04:00
|
|
|
args: []string{"releases", "my-image", "--key", "/path/to/key"},
|
2017-09-26 14:43:52 -04:00
|
|
|
expectedError: "releases is a reserved keyword, please use a different signer name",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "disallowed-chars",
|
2017-10-25 13:45:10 -04:00
|
|
|
args: []string{"ali/ce", "my-image", "--key", "/path/to/key"},
|
|
|
|
expectedError: "signer name \"ali/ce\" must start with lowercase alphanumeric characters and can include \"-\" or \"_\" after the first character",
|
2017-09-26 14:43:52 -04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "no-upper-case",
|
2017-10-25 13:45:10 -04:00
|
|
|
args: []string{"Alice", "my-image", "--key", "/path/to/key"},
|
|
|
|
expectedError: "signer name \"Alice\" must start with lowercase alphanumeric characters and can include \"-\" or \"_\" after the first character",
|
2017-09-26 14:43:52 -04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "start-with-letter",
|
2017-10-25 13:45:10 -04:00
|
|
|
args: []string{"_alice", "my-image", "--key", "/path/to/key"},
|
|
|
|
expectedError: "signer name \"_alice\" must start with lowercase alphanumeric characters and can include \"-\" or \"_\" after the first character",
|
2017-09-26 14:43:52 -04:00
|
|
|
},
|
|
|
|
}
|
|
|
|
tmpDir, err := ioutil.TempDir("", "docker-sign-test-")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-09-26 14:43:52 -04:00
|
|
|
defer os.RemoveAll(tmpDir)
|
|
|
|
config.SetDir(tmpDir)
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
cli := test.NewFakeCli(&fakeClient{})
|
2018-03-08 08:35:17 -05:00
|
|
|
cli.SetNotaryClient(notaryfake.GetOfflineNotaryRepository)
|
2017-09-26 14:43:52 -04:00
|
|
|
cmd := newSignerAddCommand(cli)
|
|
|
|
cmd.SetArgs(tc.args)
|
|
|
|
cmd.SetOutput(ioutil.Discard)
|
2018-03-06 14:03:47 -05:00
|
|
|
assert.ErrorContains(t, cmd.Execute(), tc.expectedError)
|
2017-09-26 14:43:52 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestSignerAddCommandNoTargetsKey(t *testing.T) {
|
|
|
|
tmpDir, err := ioutil.TempDir("", "docker-sign-test-")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-09-26 14:43:52 -04:00
|
|
|
defer os.RemoveAll(tmpDir)
|
|
|
|
config.SetDir(tmpDir)
|
|
|
|
|
|
|
|
tmpfile, err := ioutil.TempFile("", "pemfile")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-09-26 14:43:52 -04:00
|
|
|
defer os.Remove(tmpfile.Name())
|
|
|
|
|
|
|
|
cli := test.NewFakeCli(&fakeClient{})
|
2018-03-08 08:35:17 -05:00
|
|
|
cli.SetNotaryClient(notaryfake.GetEmptyTargetsNotaryRepository)
|
2017-09-26 14:43:52 -04:00
|
|
|
cmd := newSignerAddCommand(cli)
|
|
|
|
cmd.SetArgs([]string{"--key", tmpfile.Name(), "alice", "alpine", "linuxkit/alpine"})
|
|
|
|
|
|
|
|
cmd.SetOutput(ioutil.Discard)
|
2018-03-06 15:54:24 -05:00
|
|
|
assert.Error(t, cmd.Execute(), fmt.Sprintf("could not parse public key from file: %s: no valid public key found", tmpfile.Name()))
|
2017-09-26 14:43:52 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
func TestSignerAddCommandBadKeyPath(t *testing.T) {
|
|
|
|
tmpDir, err := ioutil.TempDir("", "docker-sign-test-")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-09-26 14:43:52 -04:00
|
|
|
defer os.RemoveAll(tmpDir)
|
|
|
|
config.SetDir(tmpDir)
|
|
|
|
|
|
|
|
cli := test.NewFakeCli(&fakeClient{})
|
2018-03-08 08:35:17 -05:00
|
|
|
cli.SetNotaryClient(notaryfake.GetEmptyTargetsNotaryRepository)
|
2017-09-26 14:43:52 -04:00
|
|
|
cmd := newSignerAddCommand(cli)
|
|
|
|
cmd.SetArgs([]string{"--key", "/path/to/key.pem", "alice", "alpine"})
|
|
|
|
|
|
|
|
cmd.SetOutput(ioutil.Discard)
|
2018-02-27 10:54:36 -05:00
|
|
|
expectedError := "unable to read public key from file: open /path/to/key.pem: no such file or directory"
|
|
|
|
if runtime.GOOS == "windows" {
|
|
|
|
expectedError = "unable to read public key from file: open /path/to/key.pem: The system cannot find the path specified."
|
|
|
|
}
|
|
|
|
assert.Error(t, cmd.Execute(), expectedError)
|
2017-09-26 14:43:52 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
func TestSignerAddCommandInvalidRepoName(t *testing.T) {
|
|
|
|
tmpDir, err := ioutil.TempDir("", "docker-sign-test-")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-09-26 14:43:52 -04:00
|
|
|
defer os.RemoveAll(tmpDir)
|
|
|
|
config.SetDir(tmpDir)
|
|
|
|
|
2017-10-25 13:45:10 -04:00
|
|
|
pubKeyDir, err := ioutil.TempDir("", "key-load-test-pubkey-")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-10-25 13:45:10 -04:00
|
|
|
defer os.RemoveAll(pubKeyDir)
|
|
|
|
pubKeyFilepath := filepath.Join(pubKeyDir, "pubkey.pem")
|
2018-03-06 15:13:00 -05:00
|
|
|
assert.NilError(t, ioutil.WriteFile(pubKeyFilepath, pubKeyFixture, notary.PrivNoExecPerms))
|
2017-10-25 13:45:10 -04:00
|
|
|
|
2017-09-26 14:43:52 -04:00
|
|
|
cli := test.NewFakeCli(&fakeClient{})
|
2018-03-08 08:35:17 -05:00
|
|
|
cli.SetNotaryClient(notaryfake.GetUninitializedNotaryRepository)
|
2017-09-26 14:43:52 -04:00
|
|
|
cmd := newSignerAddCommand(cli)
|
|
|
|
imageName := "870d292919d01a0af7e7f056271dc78792c05f55f49b9b9012b6d89725bd9abd"
|
2017-10-25 13:45:10 -04:00
|
|
|
cmd.SetArgs([]string{"--key", pubKeyFilepath, "alice", imageName})
|
2017-09-26 14:43:52 -04:00
|
|
|
|
|
|
|
cmd.SetOutput(ioutil.Discard)
|
2018-03-06 15:54:24 -05:00
|
|
|
assert.Error(t, cmd.Execute(), "Failed to add signer to: 870d292919d01a0af7e7f056271dc78792c05f55f49b9b9012b6d89725bd9abd")
|
2017-10-25 13:45:10 -04:00
|
|
|
expectedErr := fmt.Sprintf("invalid repository name (%s), cannot specify 64-byte hexadecimal strings\n\n", imageName)
|
2017-09-26 14:43:52 -04:00
|
|
|
|
2018-03-05 18:53:52 -05:00
|
|
|
assert.Check(t, is.Equal(expectedErr, cli.ErrBuffer().String()))
|
2017-09-26 14:43:52 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
func TestIngestPublicKeys(t *testing.T) {
|
|
|
|
// Call with a bad path
|
|
|
|
_, err := ingestPublicKeys([]string{"foo", "bar"})
|
2018-02-27 10:54:36 -05:00
|
|
|
expectedError := "unable to read public key from file: open foo: no such file or directory"
|
|
|
|
if runtime.GOOS == "windows" {
|
|
|
|
expectedError = "unable to read public key from file: open foo: The system cannot find the file specified."
|
|
|
|
}
|
|
|
|
assert.Error(t, err, expectedError)
|
2017-09-26 14:43:52 -04:00
|
|
|
// Call with real file path
|
|
|
|
tmpfile, err := ioutil.TempFile("", "pemfile")
|
2018-03-06 14:44:13 -05:00
|
|
|
assert.NilError(t, err)
|
2017-09-26 14:43:52 -04:00
|
|
|
defer os.Remove(tmpfile.Name())
|
|
|
|
_, err = ingestPublicKeys([]string{tmpfile.Name()})
|
2018-03-06 15:54:24 -05:00
|
|
|
assert.Error(t, err, fmt.Sprintf("could not parse public key from file: %s: no valid public key found", tmpfile.Name()))
|
2017-09-26 14:43:52 -04:00
|
|
|
}
|