-
Notifications
You must be signed in to change notification settings - Fork 25
/
verify.go
107 lines (86 loc) · 3 KB
/
verify.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
// SPDX-License-Identifier: Apache-2.0
package repository
import (
"context"
"errors"
"fmt"
"log/slog"
"github.com/gittuf/gittuf/internal/dev"
"github.com/gittuf/gittuf/internal/gitinterface"
"github.com/gittuf/gittuf/internal/policy"
"github.com/go-git/go-git/v5/plumbing"
)
// ErrRefStateDoesNotMatchRSL is returned when a Git reference being verified
// does not have the same tip as identified in the latest RSL entry for the
// reference. This can happen for a number of reasons such as incorrectly
// modifying reference state away from what's recorded in the RSL to not
// creating an RSL entry for some new changes. Depending on the context, one
// resolution is to update the reference state to match the RSL entry, while
// another is to create a new RSL entry for the current state.
var ErrRefStateDoesNotMatchRSL = errors.New("Git reference's current state does not match latest RSL entry") //nolint:stylecheck
func (r *Repository) VerifyRef(ctx context.Context, target string, latestOnly bool) error {
var (
expectedTip plumbing.Hash
err error
)
slog.Debug("Identifying absolute reference path...")
target, err = gitinterface.AbsoluteReference(r.r, target)
if err != nil {
return err
}
slog.Debug(fmt.Sprintf("Verifying gittuf policies for '%s'", target))
if latestOnly {
expectedTip, err = policy.VerifyRef(ctx, r.r, target)
} else {
expectedTip, err = policy.VerifyRefFull(ctx, r.r, target)
}
if err != nil {
return err
}
slog.Debug("Verifying if tip of reference matches expected value from RSL...")
if err := r.verifyRefTip(target, expectedTip); err != nil {
return err
}
slog.Debug("Verification successful!")
return nil
}
func (r *Repository) VerifyRefFromEntry(ctx context.Context, target, entryID string) error {
if !dev.InDevMode() {
return dev.ErrNotInDevMode
}
var err error
slog.Debug("Identifying absolute reference path...")
target, err = gitinterface.AbsoluteReference(r.r, target)
if err != nil {
return err
}
slog.Debug(fmt.Sprintf("Verifying gittuf policies for '%s' from entry '%s'", target, entryID))
expectedTip, err := policy.VerifyRefFromEntry(ctx, r.r, target, plumbing.NewHash(entryID))
if err != nil {
return err
}
slog.Debug("Verifying if tip of reference matches expected value from RSL...")
if err := r.verifyRefTip(target, expectedTip); err != nil {
return err
}
slog.Debug("Verification successful!")
return nil
}
func (r *Repository) VerifyCommit(ctx context.Context, ids ...string) map[string]string {
slog.Debug("Verifying commit signature...")
return policy.VerifyCommit(ctx, r.r, ids...)
}
func (r *Repository) VerifyTag(ctx context.Context, ids []string) map[string]string {
slog.Debug("Verifying tag signature...")
return policy.VerifyTag(ctx, r.r, ids)
}
func (r *Repository) verifyRefTip(target string, expectedTip plumbing.Hash) error {
ref, err := r.r.Reference(plumbing.ReferenceName(target), true)
if err != nil {
return err
}
if ref.Hash() != expectedTip {
return ErrRefStateDoesNotMatchRSL
}
return nil
}