From e24aa2b95c867038f7f8012ce43504f0ba149651 Mon Sep 17 00:00:00 2001 From: Mikhail Swift Date: Thu, 21 Sep 2023 17:12:14 -0400 Subject: [PATCH] feat: add support for postgresql This allows users to connect to a postgresql backend for our ent library. The ent client creation was broken into it's own function so we can use the enttest library to pass in the test client for unit testing in the future. --- cmd/archivista/main.go | 9 ++- compose.psql.yml | 26 +++++++ go.mod | 1 + go.sum | 2 + internal/config/config.go | 1 + internal/metadatastorage/sqlstore/client.go | 72 +++++++++++++++++++ .../mysql.go => sqlstore/store.go} | 34 +-------- test/build.attestation.json | 1 + test/fail.attestation.json | 1 + test/package.attestation.json | 1 + test/test.sh | 52 ++++++++++++++ 11 files changed, 166 insertions(+), 34 deletions(-) create mode 100644 compose.psql.yml create mode 100644 internal/metadatastorage/sqlstore/client.go rename internal/metadatastorage/{mysqlstore/mysql.go => sqlstore/store.go} (88%) create mode 100644 test/build.attestation.json create mode 100644 test/fail.attestation.json create mode 100644 test/package.attestation.json create mode 100755 test/test.sh diff --git a/cmd/archivista/main.go b/cmd/archivista/main.go index 0c13cd98..e6aed61b 100644 --- a/cmd/archivista/main.go +++ b/cmd/archivista/main.go @@ -39,7 +39,7 @@ import ( "github.com/sirupsen/logrus" "github.com/testifysec/archivista" "github.com/testifysec/archivista/internal/config" - "github.com/testifysec/archivista/internal/metadatastorage/mysqlstore" + "github.com/testifysec/archivista/internal/metadatastorage/sqlstore" "github.com/testifysec/archivista/internal/objectstorage/blobstore" "github.com/testifysec/archivista/internal/objectstorage/filestore" "github.com/testifysec/archivista/internal/server" @@ -86,7 +86,12 @@ func main() { logrus.Fatalf("error initializing storage clients: %+v", err) } - mysqlStore, mysqlStoreCh, err := mysqlstore.New(ctx, cfg.SQLStoreConnectionString) + entClient, err := sqlstore.NewEntClient(cfg.SQLStoreBackend, cfg.SQLStoreConnectionString) + if err != nil { + logrus.Fatalf("could not create ent client: %+v", err) + } + + mysqlStore, mysqlStoreCh, err := sqlstore.New(ctx, entClient) if err != nil { logrus.Fatalf("error initializing mysql client: %+v", err) } diff --git a/compose.psql.yml b/compose.psql.yml new file mode 100644 index 00000000..1fa5121e --- /dev/null +++ b/compose.psql.yml @@ -0,0 +1,26 @@ +# Copyright 2023 The Archivista Contributors +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +services: + psql: + image: postgres:16 + restart: always + environment: + POSTGRES_USER: testify + POSTGRES_PASSWORD: example + + archivista: + environment: + ARCHIVISTA_SQL_STORE_BACKEND: PSQL + ARCHIVISTA_SQL_STORE_CONNECTION_STRING: postgresql://testify:example@psql?sslmode=disable diff --git a/go.mod b/go.mod index bc53a589..03a354e8 100644 --- a/go.mod +++ b/go.mod @@ -15,6 +15,7 @@ require ( github.com/gorilla/mux v1.8.0 github.com/hashicorp/go-multierror v1.1.1 github.com/kelseyhightower/envconfig v1.4.0 + github.com/lib/pq v1.10.7 github.com/minio/minio-go v6.0.14+incompatible github.com/sirupsen/logrus v1.9.0 github.com/spf13/cobra v1.5.0 diff --git a/go.sum b/go.sum index af4e97d5..d19794c1 100644 --- a/go.sum +++ b/go.sum @@ -116,6 +116,8 @@ github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= github.com/kylelemons/godebug v1.1.0 h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc= github.com/kylelemons/godebug v1.1.0/go.mod h1:9/0rRGxNHcop5bhtWyNeEfOS8JIWk580+fNqagV/RAw= +github.com/lib/pq v1.10.7 h1:p7ZhMD+KsSRozJr34udlUrhboJwWAgCg34+/ZZNvZZw= +github.com/lib/pq v1.10.7/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o= github.com/logrusorgru/aurora/v3 v3.0.0/go.mod h1:vsR12bk5grlLvLXAYrBsb5Oc/N+LxAlxggSjiwMnCUc= github.com/matryer/moq v0.2.7/go.mod h1:kITsx543GOENm48TUAQyJ9+SAvFSr7iGQXPoth/VUBk= github.com/mattn/go-colorable v0.1.12/go.mod h1:u5H1YNBxpqRaxsYJYSkiCWKzEfiAb1Gb520KVy5xxl4= diff --git a/internal/config/config.go b/internal/config/config.go index 7e0763d9..92d29892 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -32,6 +32,7 @@ type Config struct { SPIFFEAddress string `default:"unix:///tmp/spire-agent/public/api.sock" desc:"SPIFFE server address" split_words:"true"` SPIFFETrustedServerId string `default:"" desc:"Trusted SPIFFE server ID; defaults to any" split_words:"true"` SQLStoreConnectionString string `default:"root:example@tcp(db)/testify" desc:"SQL store connection string" split_words:"true"` + SQLStoreBackend string `default:"MYSQL" desc:"SQL backend to use. Options are MYSQL, PSQL" split_words:"true"` StorageBackend string `default:"" desc:"Backend to use for attestation storage. Options are FILE, BLOB, or empty string for disabled." split_words:"true"` FileServeOn string `default:"" desc:"What address to serve files on. Only valid when using FILE storage backend." split_words:"true"` diff --git a/internal/metadatastorage/sqlstore/client.go b/internal/metadatastorage/sqlstore/client.go new file mode 100644 index 00000000..45a81d91 --- /dev/null +++ b/internal/metadatastorage/sqlstore/client.go @@ -0,0 +1,72 @@ +// Copyright 2023 The Archivista Contributors +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package sqlstore + +import ( + "fmt" + "strings" + "time" + + "ariga.io/sqlcomment" + "entgo.io/ent/dialect" + "entgo.io/ent/dialect/sql" + "github.com/go-sql-driver/mysql" + "github.com/testifysec/archivista/ent" + + _ "github.com/lib/pq" +) + +// NewEntClient creates an ent client for use in the sqlmetadata store. +// Valid backends are MYSQL and PSQL. +func NewEntClient(sqlBackend string, connectionString string) (*ent.Client, error) { + var entDialect string + switch strings.ToUpper(sqlBackend) { + case "MYSQL": + dbConfig, err := mysql.ParseDSN(connectionString) + if err != nil { + return nil, fmt.Errorf("could not parse mysql connection string: %w", err) + } + + // this tells the go-sql-driver to parse times from mysql to go's time.Time + // see https://github.com/go-sql-driver/mysql#timetime-support for details + dbConfig.ParseTime = true + entDialect = dialect.MySQL + connectionString = dbConfig.FormatDSN() + case "PSQL": + entDialect = dialect.Postgres + default: + return nil, fmt.Errorf("unknown sql backend: %s", sqlBackend) + } + + drv, err := sql.Open(entDialect, connectionString) + if err != nil { + return nil, fmt.Errorf("could not open sql connection: %w", err) + } + + db := drv.DB() + db.SetMaxIdleConns(10) + db.SetMaxOpenConns(100) + db.SetConnMaxLifetime(3 * time.Minute) + sqlcommentDrv := sqlcomment.NewDriver(drv, + sqlcomment.WithDriverVerTag(), + sqlcomment.WithTags(sqlcomment.Tags{ + sqlcomment.KeyApplication: "archivista", + sqlcomment.KeyFramework: "net/http", + }), + ) + + client := ent.NewClient(ent.Driver(sqlcommentDrv)) + return client, nil +} diff --git a/internal/metadatastorage/mysqlstore/mysql.go b/internal/metadatastorage/sqlstore/store.go similarity index 88% rename from internal/metadatastorage/mysqlstore/mysql.go rename to internal/metadatastorage/sqlstore/store.go index bb52cb8e..3fc0d34c 100644 --- a/internal/metadatastorage/mysqlstore/mysql.go +++ b/internal/metadatastorage/sqlstore/store.go @@ -12,7 +12,7 @@ // See the License for the specific language governing permissions and // limitations under the License. -package mysqlstore +package sqlstore import ( "context" @@ -22,10 +22,7 @@ import ( "fmt" "time" - "ariga.io/sqlcomment" - "entgo.io/ent/dialect/sql" "github.com/digitorus/timestamp" - "github.com/go-sql-driver/mysql" "github.com/sirupsen/logrus" "github.com/testifysec/archivista/ent" "github.com/testifysec/archivista/internal/metadatastorage" @@ -47,34 +44,7 @@ type Store struct { client *ent.Client } -func New(ctx context.Context, connectionstring string) (*Store, <-chan error, error) { - dbConfig, err := mysql.ParseDSN(connectionstring) - if err != nil { - return nil, nil, err - } - - dbConfig.ParseTime = true - connectionstring = dbConfig.FormatDSN() - drv, err := sql.Open("mysql", connectionstring) - if err != nil { - return nil, nil, err - } - sqlcommentDrv := sqlcomment.NewDriver(drv, - sqlcomment.WithDriverVerTag(), - sqlcomment.WithTags(sqlcomment.Tags{ - sqlcomment.KeyApplication: "archivista", - sqlcomment.KeyFramework: "net/http", - }), - ) - - // TODO make sure these take affect in sqlcommentDrv - db := drv.DB() - db.SetMaxIdleConns(10) - db.SetMaxOpenConns(100) - db.SetConnMaxLifetime(3 * time.Minute) - - client := ent.NewClient(ent.Driver(sqlcommentDrv)) - +func New(ctx context.Context, client *ent.Client) (*Store, <-chan error, error) { errCh := make(chan error) go func() { diff --git a/test/build.attestation.json b/test/build.attestation.json new file mode 100644 index 00000000..77657655 --- /dev/null +++ b/test/build.attestation.json @@ -0,0 +1 @@ +{"payload":"{"_type":"https://in-toto.io/Statement/v0.1","subject":[{"name":"https://witness.dev/attestations/product/v0.1/file:testapp","digest":{"gitoid:sha1":"gitoid:blob:sha1:85e3a023c97c8aadace2d8c959535abffbf4e175","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"423da4cff198bbffbe3220ed9510d32ba96698e4b1f654552521d1f541abb6dc"}},{"name":"https://witness.dev/attestations/git/v0.1/commithash:be20100af602c780deeef50c54f5338662ce917c","digest":{"sha1":"be20100af602c780deeef50c54f5338662ce917c"}},{"name":"https://witness.dev/attestations/git/v0.1/authoremail:snyk-bot@snyk.io","digest":{"sha256":"ee48369be6072c1a49ba519b2eef9272235b0d925a6e7a338f7ffc12a2ca538e"}},{"name":"https://witness.dev/attestations/git/v0.1/committeremail:mswift@mswift.dev","digest":{"sha256":"408404e7a66b471e5630e801c93af66fb9cb01771982ae90b6f755e104281887"}},{"name":"https://witness.dev/attestations/git/v0.1/parenthash:aa35c1f4b1d41c87e139c2d333f09117fd0daf4f","digest":{"sha256":"0bc136f5509e96fc8aa290f175428d643a0e65d8e6b61586ad60e9ec983a3370"}}],"predicateType":"https://witness.testifysec.com/attestation-collection/v0.1","predicate":{"name":"build","attestations":[{"type":"https://witness.dev/attestations/environment/v0.1","attestation":{"os":"darwin","hostname":"Mikhails-MacBook-Pro-2.local","username":"mswift","variables":{"COLORTERM":"truecolor","COMMAND_MODE":"unix2003","GIT_ASKPASS":"/Applications/Visual Studio Code.app/Contents/Resources/app/extensions/git/dist/askpass.sh","GPG_TTY":"/dev/ttys008","HOME":"/Users/mswift","HOMEBREW_CELLAR":"/opt/homebrew/Cellar","HOMEBREW_PREFIX":"/opt/homebrew","HOMEBREW_REPOSITORY":"/opt/homebrew","INFOPATH":"/opt/homebrew/share/info:/opt/homebrew/share/info:","LANG":"en_US.UTF-8","LOGNAME":"mswift","LaunchInstanceID":"EB2A7A08-FF30-4AFC-93BC-F3B427CF1814","MANPATH":"/opt/homebrew/share/man:/usr/share/man:/usr/local/share/man:/opt/homebrew/share/man::","MallocNanoZone":"0","ORIGINAL_XDG_CURRENT_DESKTOP":"undefined","P9K_SSH":"0","P9K_TTY":"old","PATH":"/Users/mswift/google-cloud-sdk/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/local/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/appleinternal/bin:/Users/mswift/google-cloud-sdk/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/Users/mswift/go/bin:/Users/mswift/go/bin","PWD":"/Users/mswift/Workspaces/witness/test","SECURITYSESSIONID":"186c9","SHELL":"/bin/zsh","SHLVL":"2","SSH_AUTH_SOCK":"/Users/mswift/.gnupg/S.gpg-agent.ssh","TERM":"xterm-256color","TERM_PROGRAM":"vscode","TERM_PROGRAM_VERSION":"1.82.0","TMPDIR":"/var/folders/6k/frqls27n2zv4z51j55nnkxfw0000gn/T/","USER":"mswift","USER_ZDOTDIR":"/Users/mswift","USE_GKE_GCLOUD_AUTH_PLUGIN":"True","VSCODE_GIT_ASKPASS_EXTRA_ARGS":"--ms-enable-electron-run-as-node","VSCODE_GIT_ASKPASS_MAIN":"/Applications/Visual Studio Code.app/Contents/Resources/app/extensions/git/dist/askpass-main.js","VSCODE_GIT_ASKPASS_NODE":"/Applications/Visual Studio Code.app/Contents/Frameworks/Code Helper (Plugin).app/Contents/MacOS/Code Helper (Plugin)","VSCODE_GIT_IPC_HANDLE":"/var/folders/6k/frqls27n2zv4z51j55nnkxfw0000gn/T/vscode-git-118950d723.sock","VSCODE_INJECTION":"1","XPC_FLAGS":"0x0","XPC_SERVICE_NAME":"0","ZDOTDIR":"/Users/mswift","_":"../bin/witness","_P9K_TTY":"/dev/ttys008","__CFBundleIdentifier":"com.microsoft.VSCode","__CF_USER_TEXT_ENCODING":"0x1F5:0x0:0x0"}},"starttime":"2023-09-26T17:23:47.32625-05:00","endtime":"2023-09-26T17:23:47.327541-05:00"},{"type":"https://witness.dev/attestations/git/v0.1","attestation":{"commithash":"be20100af602c780deeef50c54f5338662ce917c","author":"snyk-bot","authoremail":"snyk-bot@snyk.io","committername":"Mikhail Swift","committeremail":"mswift@mswift.dev","commitdate":"2023-07-18 16:10:06 +0000 +0000","commitmessage":"fix: dev/Dockerfile.go-builder to reduce vulnerabilities\n\nThe following vulnerabilities are fixed with an upgrade:\n- https://snyk.io/vuln/SNYK-DEBIAN11-APR-3261105\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-3368735\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5291773\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5291777\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5661566","status":{".vscode/launch.json":{"staging":"untracked","worktree":"untracked"},"test/test.yaml":{"staging":"unmodified","worktree":"modified"}},"commitdigest":{"sha1":"be20100af602c780deeef50c54f5338662ce917c"},"parenthashes":["aa35c1f4b1d41c87e139c2d333f09117fd0daf4f"],"treehash":"9e0765b6579ac7c14a4060abdbcc1d09ba50804d","refs":["refs/heads/main","refs/remotes/origin/main"]},"starttime":"2023-09-26T17:23:47.327554-05:00","endtime":"2023-09-26T17:23:47.876433-05:00"},{"type":"https://witness.dev/attestations/material/v0.1","attestation":{".gitignore":{"gitoid:sha1":"gitoid:blob:sha1:ea126d8b94cf1a6dea5d952a1580b9f141cdab7e","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"ebf3a73a42ed2012db0be2b9e77f9e53d73a0a0ae22081a5fc5df2326f9afbab"},"build.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"},"common.sh":{"gitoid:sha1":"gitoid:blob:sha1:3c328fb7f31d1c4343ef79755619205a15697a60","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"68f49b475e708f51fd7f2768711fee2e6c858e94a44fdf8a6c5bf33b6a976162"},"failkey.pem":{"gitoid:sha1":"gitoid:blob:sha1:7c5ec43b78a38828d69a3a577c5ee638fe7a4375","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"093f0f8c5922a2f66cfb4737a5007b197b36f019a47d11a00a9577ad8fe288a9"},"main.go":{"gitoid:sha1":"gitoid:blob:sha1:de331f98992f9326b62e2bd72d7f4ef81df91b46","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"310e5ce267a64dd0ccc6341a6f043d5a7d59d57acb10f31fc11c2f54c94854d3"},"policy-signed.json":{"gitoid:sha1":"gitoid:blob:sha1:91b225e1cf0d28352aab3c8d5400ec4635a17b8e","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"cafb483fe3588b9e73c32fd382fb46793af902190b6e9c82286214d2cc6acb84"},"policy.json":{"gitoid:sha1":"gitoid:blob:sha1:2433442201041f466f921f5ba742851f5d0daca4","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"cc7d55c83d46a66c9d6b612fdd61516c9e2dbd1330119412fad41f9ceea7e84f"},"test-oci.sh":{"gitoid:sha1":"gitoid:blob:sha1:f8493882c5074e7db81eb062e4f8ad77c5ab96c4","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"1fb06f2fdf6378fc19c73a6d06d3caae790b32bc8231bc69e3853db4f27bf503"},"test.sh":{"gitoid:sha1":"gitoid:blob:sha1:8aafcdeed8c27684a36e4beb63a20d0943c0ec72","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"934f36f3a9b39a9a13686435c35c1090cd2db9bbd0fc96348815292305910fe3"},"test.yaml":{"gitoid:sha1":"gitoid:blob:sha1:83b769fcc7055af6eead843243a6b11a1a765fd5","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"48c7492a48c7b8ec8f1aec50810713e2437131da93b29f91c7ae1ab98c5d5a40"},"testkey.pem":{"gitoid:sha1":"gitoid:blob:sha1:facedcd782f8065343fd97bcc1df9daba0f90cca","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"17902d2925a9e944415af737ea0cdfd96a3efbbecc31f59bdb8535724a1256fc"},"testkey2.pem":{"gitoid:sha1":"gitoid:blob:sha1:d2c919f43ccaceab77e5dbc71c1b85794c862c90","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"3a6f39d761fd0e9aa4417c50a07f9f4d7b29b1ac430a01687b68400c2b968803"},"testpub.pem":{"gitoid:sha1":"gitoid:blob:sha1:9b4bea908cd7fc231c49ec8db4e5bddbc814031f","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"b97f0fb40bb749f5e6a55e588e800ffea3f1ec63665af8199aeba4472ab45327"},"testpub2.pem":{"gitoid:sha1":"gitoid:blob:sha1:1dc3f8c8624d98a69ba477c79fa2eb5c87408cb7","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"5e8c57df8ae58fe9a29b29f9993e2fc3b25bd75eb2754f353880bad4b9ebfdb3"}},"starttime":"2023-09-26T17:23:47.876455-05:00","endtime":"2023-09-26T17:23:47.876903-05:00"},{"type":"https://witness.dev/attestations/command-run/v0.1","attestation":{"cmd":["go","build","-o=testapp","."],"exitcode":0},"starttime":"2023-09-26T17:23:47.876912-05:00","endtime":"2023-09-26T17:23:48.073917-05:00"},{"type":"https://witness.dev/attestations/product/v0.1","attestation":{"testapp":{"mime_type":"application/octet-stream","digest":{"gitoid:sha1":"gitoid:blob:sha1:85e3a023c97c8aadace2d8c959535abffbf4e175","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"423da4cff198bbffbe3220ed9510d32ba96698e4b1f654552521d1f541abb6dc"}}},"starttime":"2023-09-26T17:23:48.074014-05:00","endtime":"2023-09-26T17:23:48.078433-05:00"}]}}","payloadType":"application/vnd.in-toto+json","signatures":[{"keyid":"ae2dcc989ea9c109a36e8eba5c4bc16d8fafcfe8e1a614164670d50aedacd647","sig":"ahsjnNBEVNqo5/umfwQzWiVAvLx4yk3z6Xh+fsaWyxhmGD1syhOhMOkXapmVvEuscm6la9a/edQKNXXg02ghCw=="}]} \ No newline at end of file diff --git a/test/fail.attestation.json b/test/fail.attestation.json new file mode 100644 index 00000000..1e0adb78 --- /dev/null +++ b/test/fail.attestation.json @@ -0,0 +1 @@ +{"payload":"{"_type":"https://in-toto.io/Statement/v0.1","subject":[{"name":"https://witness.dev/attestations/git/v0.1/parenthash:aa35c1f4b1d41c87e139c2d333f09117fd0daf4f","digest":{"sha256":"0bc136f5509e96fc8aa290f175428d643a0e65d8e6b61586ad60e9ec983a3370"}},{"name":"https://witness.dev/attestations/git/v0.1/commithash:be20100af602c780deeef50c54f5338662ce917c","digest":{"sha1":"be20100af602c780deeef50c54f5338662ce917c"}},{"name":"https://witness.dev/attestations/git/v0.1/authoremail:snyk-bot@snyk.io","digest":{"sha256":"ee48369be6072c1a49ba519b2eef9272235b0d925a6e7a338f7ffc12a2ca538e"}},{"name":"https://witness.dev/attestations/git/v0.1/committeremail:mswift@mswift.dev","digest":{"sha256":"408404e7a66b471e5630e801c93af66fb9cb01771982ae90b6f755e104281887"}}],"predicateType":"https://witness.testifysec.com/attestation-collection/v0.1","predicate":{"name":"build","attestations":[{"type":"https://witness.dev/attestations/environment/v0.1","attestation":{"os":"darwin","hostname":"Mikhails-MacBook-Pro-2.local","username":"mswift","variables":{"COLORTERM":"truecolor","COMMAND_MODE":"unix2003","GIT_ASKPASS":"/Applications/Visual Studio Code.app/Contents/Resources/app/extensions/git/dist/askpass.sh","GPG_TTY":"/dev/ttys008","HOME":"/Users/mswift","HOMEBREW_CELLAR":"/opt/homebrew/Cellar","HOMEBREW_PREFIX":"/opt/homebrew","HOMEBREW_REPOSITORY":"/opt/homebrew","INFOPATH":"/opt/homebrew/share/info:/opt/homebrew/share/info:","LANG":"en_US.UTF-8","LOGNAME":"mswift","LaunchInstanceID":"EB2A7A08-FF30-4AFC-93BC-F3B427CF1814","MANPATH":"/opt/homebrew/share/man:/usr/share/man:/usr/local/share/man:/opt/homebrew/share/man::","MallocNanoZone":"0","ORIGINAL_XDG_CURRENT_DESKTOP":"undefined","P9K_SSH":"0","P9K_TTY":"old","PATH":"/Users/mswift/google-cloud-sdk/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/local/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/appleinternal/bin:/Users/mswift/google-cloud-sdk/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/Users/mswift/go/bin:/Users/mswift/go/bin","PWD":"/Users/mswift/Workspaces/witness/test","SECURITYSESSIONID":"186c9","SHELL":"/bin/zsh","SHLVL":"2","SSH_AUTH_SOCK":"/Users/mswift/.gnupg/S.gpg-agent.ssh","TERM":"xterm-256color","TERM_PROGRAM":"vscode","TERM_PROGRAM_VERSION":"1.82.0","TMPDIR":"/var/folders/6k/frqls27n2zv4z51j55nnkxfw0000gn/T/","USER":"mswift","USER_ZDOTDIR":"/Users/mswift","USE_GKE_GCLOUD_AUTH_PLUGIN":"True","VSCODE_GIT_ASKPASS_EXTRA_ARGS":"--ms-enable-electron-run-as-node","VSCODE_GIT_ASKPASS_MAIN":"/Applications/Visual Studio Code.app/Contents/Resources/app/extensions/git/dist/askpass-main.js","VSCODE_GIT_ASKPASS_NODE":"/Applications/Visual Studio Code.app/Contents/Frameworks/Code Helper (Plugin).app/Contents/MacOS/Code Helper (Plugin)","VSCODE_GIT_IPC_HANDLE":"/var/folders/6k/frqls27n2zv4z51j55nnkxfw0000gn/T/vscode-git-118950d723.sock","VSCODE_INJECTION":"1","XPC_FLAGS":"0x0","XPC_SERVICE_NAME":"0","ZDOTDIR":"/Users/mswift","_":"../bin/witness","_P9K_TTY":"/dev/ttys008","__CFBundleIdentifier":"com.microsoft.VSCode","__CF_USER_TEXT_ENCODING":"0x1F5:0x0:0x0"}},"starttime":"2023-09-26T17:23:48.785941-05:00","endtime":"2023-09-26T17:23:48.787342-05:00"},{"type":"https://witness.dev/attestations/git/v0.1","attestation":{"commithash":"be20100af602c780deeef50c54f5338662ce917c","author":"snyk-bot","authoremail":"snyk-bot@snyk.io","committername":"Mikhail Swift","committeremail":"mswift@mswift.dev","commitdate":"2023-07-18 16:10:06 +0000 +0000","commitmessage":"fix: dev/Dockerfile.go-builder to reduce vulnerabilities\n\nThe following vulnerabilities are fixed with an upgrade:\n- https://snyk.io/vuln/SNYK-DEBIAN11-APR-3261105\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-3368735\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5291773\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5291777\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5661566","status":{".vscode/launch.json":{"staging":"untracked","worktree":"untracked"},"test/test.yaml":{"staging":"unmodified","worktree":"modified"}},"commitdigest":{"sha1":"be20100af602c780deeef50c54f5338662ce917c"},"parenthashes":["aa35c1f4b1d41c87e139c2d333f09117fd0daf4f"],"treehash":"9e0765b6579ac7c14a4060abdbcc1d09ba50804d","refs":["refs/heads/main","refs/remotes/origin/main"]},"starttime":"2023-09-26T17:23:48.787357-05:00","endtime":"2023-09-26T17:23:49.382796-05:00"},{"type":"https://witness.dev/attestations/material/v0.1","attestation":{".gitignore":{"gitoid:sha1":"gitoid:blob:sha1:ea126d8b94cf1a6dea5d952a1580b9f141cdab7e","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"ebf3a73a42ed2012db0be2b9e77f9e53d73a0a0ae22081a5fc5df2326f9afbab"},"build.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:77657655a4eaa135c09f92f723e12436b63781d1","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"ec0cbfc118b915dd61dc8a94d9b487acd9596d61e872d6ef37705cf67c1a0e82"},"common.sh":{"gitoid:sha1":"gitoid:blob:sha1:3c328fb7f31d1c4343ef79755619205a15697a60","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"68f49b475e708f51fd7f2768711fee2e6c858e94a44fdf8a6c5bf33b6a976162"},"fail.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"},"failkey.pem":{"gitoid:sha1":"gitoid:blob:sha1:7c5ec43b78a38828d69a3a577c5ee638fe7a4375","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"093f0f8c5922a2f66cfb4737a5007b197b36f019a47d11a00a9577ad8fe288a9"},"main.go":{"gitoid:sha1":"gitoid:blob:sha1:de331f98992f9326b62e2bd72d7f4ef81df91b46","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"310e5ce267a64dd0ccc6341a6f043d5a7d59d57acb10f31fc11c2f54c94854d3"},"package.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:cb2b274fa7a8179a18718959c471a14030c92ef1","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"6300d031dee3844923188ea729f139dddb45738577743c9bbca892c4377911f6"},"policy-signed.json":{"gitoid:sha1":"gitoid:blob:sha1:91b225e1cf0d28352aab3c8d5400ec4635a17b8e","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"cafb483fe3588b9e73c32fd382fb46793af902190b6e9c82286214d2cc6acb84"},"policy.json":{"gitoid:sha1":"gitoid:blob:sha1:2433442201041f466f921f5ba742851f5d0daca4","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"cc7d55c83d46a66c9d6b612fdd61516c9e2dbd1330119412fad41f9ceea7e84f"},"test-oci.sh":{"gitoid:sha1":"gitoid:blob:sha1:f8493882c5074e7db81eb062e4f8ad77c5ab96c4","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"1fb06f2fdf6378fc19c73a6d06d3caae790b32bc8231bc69e3853db4f27bf503"},"test.sh":{"gitoid:sha1":"gitoid:blob:sha1:8aafcdeed8c27684a36e4beb63a20d0943c0ec72","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"934f36f3a9b39a9a13686435c35c1090cd2db9bbd0fc96348815292305910fe3"},"test.yaml":{"gitoid:sha1":"gitoid:blob:sha1:83b769fcc7055af6eead843243a6b11a1a765fd5","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"48c7492a48c7b8ec8f1aec50810713e2437131da93b29f91c7ae1ab98c5d5a40"},"testapp":{"gitoid:sha1":"gitoid:blob:sha1:85e3a023c97c8aadace2d8c959535abffbf4e175","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"423da4cff198bbffbe3220ed9510d32ba96698e4b1f654552521d1f541abb6dc"},"testapp.tar.tgz":{"gitoid:sha1":"gitoid:blob:sha1:0266c1243f1b1d46cecfa671da2a4e8d1e4f97e5","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"d03dd827d71dfab7578faf049294c55ad140a596bece5e68bc406ac9265be1ee"},"testkey.pem":{"gitoid:sha1":"gitoid:blob:sha1:facedcd782f8065343fd97bcc1df9daba0f90cca","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"17902d2925a9e944415af737ea0cdfd96a3efbbecc31f59bdb8535724a1256fc"},"testkey2.pem":{"gitoid:sha1":"gitoid:blob:sha1:d2c919f43ccaceab77e5dbc71c1b85794c862c90","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"3a6f39d761fd0e9aa4417c50a07f9f4d7b29b1ac430a01687b68400c2b968803"},"testpub.pem":{"gitoid:sha1":"gitoid:blob:sha1:9b4bea908cd7fc231c49ec8db4e5bddbc814031f","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"b97f0fb40bb749f5e6a55e588e800ffea3f1ec63665af8199aeba4472ab45327"},"testpub2.pem":{"gitoid:sha1":"gitoid:blob:sha1:1dc3f8c8624d98a69ba477c79fa2eb5c87408cb7","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"5e8c57df8ae58fe9a29b29f9993e2fc3b25bd75eb2754f353880bad4b9ebfdb3"}},"starttime":"2023-09-26T17:23:49.382821-05:00","endtime":"2023-09-26T17:23:49.38827-05:00"},{"type":"https://witness.dev/attestations/command-run/v0.1","attestation":{"cmd":["go","build","-o=testapp","."],"exitcode":0},"starttime":"2023-09-26T17:23:49.388293-05:00","endtime":"2023-09-26T17:23:49.452797-05:00"},{"type":"https://witness.dev/attestations/product/v0.1","attestation":{},"starttime":"2023-09-26T17:23:49.452902-05:00","endtime":"2023-09-26T17:23:49.459203-05:00"}]}}","payloadType":"application/vnd.in-toto+json","signatures":[{"keyid":"6316cb923d1b8412880e49fb0245c0e5f5536674d1c2cc3e948476fdc9830453","sig":"MEUCIQDk6DSWysKt6vYZi66xoxNWJmJG+9M+t9mLGzjoVEp0xAIgSRjEKFaJzqYqVOq6TZE07gyobZVJH4RB8nqVdS8sQBU="}]} \ No newline at end of file diff --git a/test/package.attestation.json b/test/package.attestation.json new file mode 100644 index 00000000..3c60f6b9 --- /dev/null +++ b/test/package.attestation.json @@ -0,0 +1 @@ +{"payload":"{"_type":"https://in-toto.io/Statement/v0.1","subject":[{"name":"https://witness.dev/attestations/git/v0.1/committeremail:mswift@mswift.dev","digest":{"sha256":"408404e7a66b471e5630e801c93af66fb9cb01771982ae90b6f755e104281887"}},{"name":"https://witness.dev/attestations/git/v0.1/parenthash:aa35c1f4b1d41c87e139c2d333f09117fd0daf4f","digest":{"sha256":"0bc136f5509e96fc8aa290f175428d643a0e65d8e6b61586ad60e9ec983a3370"}},{"name":"https://witness.dev/attestations/product/v0.1/file:testapp.tar.tgz","digest":{"gitoid:sha1":"gitoid:blob:sha1:3994f66f37e15ce81ec11df852d5ee9d55f08c01","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"10cbf0f3d870934921276f669ab707983113f929784d877f1192f43c581f2070"}},{"name":"https://witness.dev/attestations/git/v0.1/commithash:be20100af602c780deeef50c54f5338662ce917c","digest":{"sha1":"be20100af602c780deeef50c54f5338662ce917c"}},{"name":"https://witness.dev/attestations/git/v0.1/authoremail:snyk-bot@snyk.io","digest":{"sha256":"ee48369be6072c1a49ba519b2eef9272235b0d925a6e7a338f7ffc12a2ca538e"}}],"predicateType":"https://witness.testifysec.com/attestation-collection/v0.1","predicate":{"name":"package","attestations":[{"type":"https://witness.dev/attestations/environment/v0.1","attestation":{"os":"darwin","hostname":"Mikhails-MacBook-Pro-2.local","username":"mswift","variables":{"COLORTERM":"truecolor","COMMAND_MODE":"unix2003","GIT_ASKPASS":"/Applications/Visual Studio Code.app/Contents/Resources/app/extensions/git/dist/askpass.sh","GPG_TTY":"/dev/ttys008","HOME":"/Users/mswift","HOMEBREW_CELLAR":"/opt/homebrew/Cellar","HOMEBREW_PREFIX":"/opt/homebrew","HOMEBREW_REPOSITORY":"/opt/homebrew","INFOPATH":"/opt/homebrew/share/info:/opt/homebrew/share/info:","LANG":"en_US.UTF-8","LOGNAME":"mswift","LaunchInstanceID":"EB2A7A08-FF30-4AFC-93BC-F3B427CF1814","MANPATH":"/opt/homebrew/share/man:/usr/share/man:/usr/local/share/man:/opt/homebrew/share/man::","MallocNanoZone":"0","ORIGINAL_XDG_CURRENT_DESKTOP":"undefined","P9K_SSH":"0","P9K_TTY":"old","PATH":"/Users/mswift/google-cloud-sdk/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/local/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/appleinternal/bin:/Users/mswift/google-cloud-sdk/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/Users/mswift/go/bin:/Users/mswift/go/bin","PWD":"/Users/mswift/Workspaces/witness/test","SECURITYSESSIONID":"186c9","SHELL":"/bin/zsh","SHLVL":"2","SSH_AUTH_SOCK":"/Users/mswift/.gnupg/S.gpg-agent.ssh","TERM":"xterm-256color","TERM_PROGRAM":"vscode","TERM_PROGRAM_VERSION":"1.82.0","TMPDIR":"/var/folders/6k/frqls27n2zv4z51j55nnkxfw0000gn/T/","USER":"mswift","USER_ZDOTDIR":"/Users/mswift","USE_GKE_GCLOUD_AUTH_PLUGIN":"True","VSCODE_GIT_ASKPASS_EXTRA_ARGS":"--ms-enable-electron-run-as-node","VSCODE_GIT_ASKPASS_MAIN":"/Applications/Visual Studio Code.app/Contents/Resources/app/extensions/git/dist/askpass-main.js","VSCODE_GIT_ASKPASS_NODE":"/Applications/Visual Studio Code.app/Contents/Frameworks/Code Helper (Plugin).app/Contents/MacOS/Code Helper (Plugin)","VSCODE_GIT_IPC_HANDLE":"/var/folders/6k/frqls27n2zv4z51j55nnkxfw0000gn/T/vscode-git-118950d723.sock","VSCODE_INJECTION":"1","XPC_FLAGS":"0x0","XPC_SERVICE_NAME":"0","ZDOTDIR":"/Users/mswift","_":"../bin/witness","_P9K_TTY":"/dev/ttys008","__CFBundleIdentifier":"com.microsoft.VSCode","__CF_USER_TEXT_ENCODING":"0x1F5:0x0:0x0"}},"starttime":"2023-09-26T17:23:49.471359-05:00","endtime":"2023-09-26T17:23:49.473583-05:00"},{"type":"https://witness.dev/attestations/git/v0.1","attestation":{"commithash":"be20100af602c780deeef50c54f5338662ce917c","author":"snyk-bot","authoremail":"snyk-bot@snyk.io","committername":"Mikhail Swift","committeremail":"mswift@mswift.dev","commitdate":"2023-07-18 16:10:06 +0000 +0000","commitmessage":"fix: dev/Dockerfile.go-builder to reduce vulnerabilities\n\nThe following vulnerabilities are fixed with an upgrade:\n- https://snyk.io/vuln/SNYK-DEBIAN11-APR-3261105\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-3368735\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5291773\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5291777\n- https://snyk.io/vuln/SNYK-DEBIAN11-OPENSSL-5661566","status":{".vscode/launch.json":{"staging":"untracked","worktree":"untracked"},"test/test.yaml":{"staging":"unmodified","worktree":"modified"}},"commitdigest":{"sha1":"be20100af602c780deeef50c54f5338662ce917c"},"parenthashes":["aa35c1f4b1d41c87e139c2d333f09117fd0daf4f"],"treehash":"9e0765b6579ac7c14a4060abdbcc1d09ba50804d","refs":["refs/heads/main","refs/remotes/origin/main"]},"starttime":"2023-09-26T17:23:49.473595-05:00","endtime":"2023-09-26T17:23:50.055535-05:00"},{"type":"https://witness.dev/attestations/material/v0.1","attestation":{".gitignore":{"gitoid:sha1":"gitoid:blob:sha1:ea126d8b94cf1a6dea5d952a1580b9f141cdab7e","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"ebf3a73a42ed2012db0be2b9e77f9e53d73a0a0ae22081a5fc5df2326f9afbab"},"build.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:77657655a4eaa135c09f92f723e12436b63781d1","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"ec0cbfc118b915dd61dc8a94d9b487acd9596d61e872d6ef37705cf67c1a0e82"},"common.sh":{"gitoid:sha1":"gitoid:blob:sha1:3c328fb7f31d1c4343ef79755619205a15697a60","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"68f49b475e708f51fd7f2768711fee2e6c858e94a44fdf8a6c5bf33b6a976162"},"fail.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:1e0adb7854027e9ce458b7a5aa77880c4668c11d","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"05d4c1b2da0a29eac0e374cec570da33dcf00e2592348f9e0e0e0c606d150960"},"failkey.pem":{"gitoid:sha1":"gitoid:blob:sha1:7c5ec43b78a38828d69a3a577c5ee638fe7a4375","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"093f0f8c5922a2f66cfb4737a5007b197b36f019a47d11a00a9577ad8fe288a9"},"main.go":{"gitoid:sha1":"gitoid:blob:sha1:de331f98992f9326b62e2bd72d7f4ef81df91b46","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"310e5ce267a64dd0ccc6341a6f043d5a7d59d57acb10f31fc11c2f54c94854d3"},"package.attestation.json":{"gitoid:sha1":"gitoid:blob:sha1:e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"},"policy-signed.json":{"gitoid:sha1":"gitoid:blob:sha1:91b225e1cf0d28352aab3c8d5400ec4635a17b8e","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"cafb483fe3588b9e73c32fd382fb46793af902190b6e9c82286214d2cc6acb84"},"policy.json":{"gitoid:sha1":"gitoid:blob:sha1:2433442201041f466f921f5ba742851f5d0daca4","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"cc7d55c83d46a66c9d6b612fdd61516c9e2dbd1330119412fad41f9ceea7e84f"},"test-oci.sh":{"gitoid:sha1":"gitoid:blob:sha1:f8493882c5074e7db81eb062e4f8ad77c5ab96c4","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"1fb06f2fdf6378fc19c73a6d06d3caae790b32bc8231bc69e3853db4f27bf503"},"test.sh":{"gitoid:sha1":"gitoid:blob:sha1:8aafcdeed8c27684a36e4beb63a20d0943c0ec72","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"934f36f3a9b39a9a13686435c35c1090cd2db9bbd0fc96348815292305910fe3"},"test.yaml":{"gitoid:sha1":"gitoid:blob:sha1:83b769fcc7055af6eead843243a6b11a1a765fd5","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"48c7492a48c7b8ec8f1aec50810713e2437131da93b29f91c7ae1ab98c5d5a40"},"testapp":{"gitoid:sha1":"gitoid:blob:sha1:85e3a023c97c8aadace2d8c959535abffbf4e175","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"423da4cff198bbffbe3220ed9510d32ba96698e4b1f654552521d1f541abb6dc"},"testapp.tar.tgz":{"gitoid:sha1":"gitoid:blob:sha1:0266c1243f1b1d46cecfa671da2a4e8d1e4f97e5","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"d03dd827d71dfab7578faf049294c55ad140a596bece5e68bc406ac9265be1ee"},"testkey.pem":{"gitoid:sha1":"gitoid:blob:sha1:facedcd782f8065343fd97bcc1df9daba0f90cca","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"17902d2925a9e944415af737ea0cdfd96a3efbbecc31f59bdb8535724a1256fc"},"testkey2.pem":{"gitoid:sha1":"gitoid:blob:sha1:d2c919f43ccaceab77e5dbc71c1b85794c862c90","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"3a6f39d761fd0e9aa4417c50a07f9f4d7b29b1ac430a01687b68400c2b968803"},"testpub.pem":{"gitoid:sha1":"gitoid:blob:sha1:9b4bea908cd7fc231c49ec8db4e5bddbc814031f","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"b97f0fb40bb749f5e6a55e588e800ffea3f1ec63665af8199aeba4472ab45327"},"testpub2.pem":{"gitoid:sha1":"gitoid:blob:sha1:1dc3f8c8624d98a69ba477c79fa2eb5c87408cb7","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"5e8c57df8ae58fe9a29b29f9993e2fc3b25bd75eb2754f353880bad4b9ebfdb3"}},"starttime":"2023-09-26T17:23:50.055564-05:00","endtime":"2023-09-26T17:23:50.06109-05:00"},{"type":"https://witness.dev/attestations/command-run/v0.1","attestation":{"cmd":["tar","czf","./testapp.tar.tgz","./testapp"],"exitcode":0},"starttime":"2023-09-26T17:23:50.061111-05:00","endtime":"2023-09-26T17:23:50.134363-05:00"},{"type":"https://witness.dev/attestations/product/v0.1","attestation":{"testapp.tar.tgz":{"mime_type":"application/x-gzip","digest":{"gitoid:sha1":"gitoid:blob:sha1:3994f66f37e15ce81ec11df852d5ee9d55f08c01","gitoid:sha256":"gitoid:blob:sha256:473a0f4c3be8a93681a267e3b1e9a7dcda1185436fe141f7749120a303721813","sha256":"10cbf0f3d870934921276f669ab707983113f929784d877f1192f43c581f2070"}}},"starttime":"2023-09-26T17:23:50.134438-05:00","endtime":"2023-09-26T17:23:50.14213-05:00"}]}}","payloadType":"application/vnd.in-toto+json","signatures":[{"keyid":"5e8c57df8ae58fe9a29b29f9993e2fc3b25bd75eb2754f353880bad4b9ebfdb3","sig":"G6gthh/6Z4pPpnz7CEgYNqCZh99LVYhQXgEdxk7bfvOaU14xXdv4zPmsCeufOwo1S+F/pxxptzTCN6d1sQwXhLNbhUXoa0Md/P+fUQ56i1WaqM57y7VQ2lOIaQBuLMaOnY07f52a/o8f40Rg29462+ccI+QFnf8/z63J/VgFu+DSlopDaa/3dPZ74oamENh34eWSThT+KjlU2v1XKYNDFVNt+S8hdINrkAFqeFdCNdpYH9hafaYutRH55Vx6ftm4o/aXTnnsjgS2moylzJN7CeIhaXoLS8oNHhYEss7UGSWlRrOZSgG/vepu4j6cdSXsoL7xoLPZB99RBNmRyfp/Fp1JfTFBeVQHBP5CaWIRgB1o/+aOYT32/Kt/FTlKetsr38Ft7Qx9P8pfXeUwn04+JcizjOoSMk1X/8TspUgHkcsa90FKx4Y+O0le9XR2AgtIo7qrgU4zKOjN0qm/PPfG0cudRdn5XA6RBvJRhJFa5uTrwpee54G2WvsrqZsuAI0hC/V8QMhZghDnpF9lYuxxEqenplJs/JfEcF/ih3n9S7N9gEter+g92DkaacV1VGqegHmmC9HIwelDoe/jVWv5byUghDPmzR7dRnAsCoK80d1gpmgcr/q0ELu/Wd/qlc7GFfbpNKeGFHL3WnqlF3nJgvx03574MIF5eCctIZNzF4o="}]} \ No newline at end of file diff --git a/test/test.sh b/test/test.sh new file mode 100755 index 00000000..ba9d6a27 --- /dev/null +++ b/test/test.sh @@ -0,0 +1,52 @@ +#!/usr/bin/env bash +set -e + +DIR="$( cd -- "$(dirname "$0")" >/dev/null 2>&1 ; pwd -P )" + +checkprograms() { + local result=0 + for prog in "$@" + do + if ! command -v $prog > /dev/null; then + printf "$prog is required to run this script. please ensure if is installed and in your PATH\n" + result=1 + fi + done + + return $result +} + +runtests() { + go run $DIR/../cmd/archivistactl/main.go store $DIR/*.attestation.json +} + +waitForArchivista() { + for attempt in $(seq 1 6); do + sleep 10 + archivistastate=$(docker compose -f "$DIR/../compose.yml" ps archivista --format json | jq -r '.State') + if [ "$archivistastate" == "running" ]; then + break + fi + + if [[ attempt -eq 6 ]]; then + echo "timed out waiting for archivista" + exit 1 + fi + done +} + +if ! checkprograms docker jq ; then + exit 1 +fi + +echo "Test mysql..." +docker compose -f "$DIR/../compose.yml" up --build -d +waitForArchivista +runtests +docker compose -f "$DIR/../compose.yml" down -v + +echo "Test psql..." +docker compose -f "$DIR/../compose.yml" -f "$DIR/../compose.psql.yml" up --build -d +waitForArchivista +runtests +docker compose -f "$DIR/../compose.yml" -f "$DIR/../compose.psql.yml" down -v \ No newline at end of file