use std::path::PathBuf;
use std::process::{Command, Stdio};
use crate::pushrefs::PushRef;
pub const FORMAT: &str = "amont-attest-v2";
pub const NOTES_REF: &str = "amont-attest";
pub const NOTES_FULL_REF: &str = "refs/notes/amont-attest";
pub const INPUTS_REF: &str = "amont-attest-inputs";
pub const INPUTS_FULL_REF: &str = "refs/notes/amont-attest-inputs";
const SPEC_PATHS: [&str; 2] = [".forgejo/attest-inputs", ".github/attest-inputs"];
pub const NAMESPACE: &str = "amont-attest";
pub const PUSH_GUARD: &str = "AMONT_ATTEST_PUSH";
const TOGGLE: &str = "amont.attest";
const KEY_CONFIG: &str = "amont.attestKey";
const KEY_DEFAULT: &str = ".ssh/amont-attest";
pub fn push_guard_active() -> bool {
std::env::var_os(PUSH_GUARD).is_some()
}
pub fn enabled(settings: &crate::config::Settings) -> bool {
crate::config::boolean_or(settings, TOGGLE, false)
}
fn key_path() -> Option<PathBuf> {
if let Some(k) = crate::git::stdout(&["config", "--get", KEY_CONFIG]) {
if !k.is_empty() {
return Some(PathBuf::from(k));
}
}
let home = std::env::var_os("HOME").or_else(|| std::env::var_os("USERPROFILE"))?;
Some(PathBuf::from(home).join(KEY_DEFAULT))
}
pub fn platform() -> String {
format!("{}-{}", std::env::consts::ARCH, std::env::consts::OS)
}
pub fn payload(tree: &str, gates: &[String], inputs: &[(String, String)]) -> String {
let mut p = format!(
"{FORMAT}\ntree {tree}\ngates {}\nplatform {}\n",
gates.join(" "),
platform()
);
for (gate, fp) in inputs {
p.push_str(&format!("input {gate} {fp}\n"));
}
p.push_str(&format!("amont {}\n", env!("CARGO_PKG_VERSION")));
p
}
const MAX_SPEC_BYTES: usize = 65536;
const MAX_SPEC_GATES: usize = 64;
const MAX_SPEC_PATHS: usize = 64;
fn valid_gate(name: &str) -> bool {
let mut chars = name.chars();
match chars.next() {
Some(c) if c.is_ascii_alphanumeric() => {}
_ => return false,
}
name.len() <= 64 && chars.all(|c| c.is_ascii_alphanumeric() || c == '.' || c == '_' || c == '-')
}
fn bad_path(tok: &str) -> bool {
tok.starts_with(':')
|| tok.starts_with('/')
|| tok.starts_with("./")
|| tok.starts_with("../")
|| tok.ends_with('/')
|| tok
.chars()
.any(|c| matches!(c, '*' | '?' | '[' | ']' | '\\'))
|| tok
.split('/')
.any(|c| c.is_empty() || c == "." || c == "..")
}
fn parse_spec(bytes: &[u8]) -> Option<Vec<(String, Vec<String>)>> {
if bytes.len() > MAX_SPEC_BYTES
|| bytes
.iter()
.any(|&b| !(b == b' ' || b == b'\t' || b == b'\n' || (0x21..=0x7e).contains(&b)))
{
return None;
}
let text = std::str::from_utf8(bytes).ok()?;
let mut gates: Vec<(String, Vec<String>)> = Vec::new();
for line in text.split('\n') {
let mut toks = line.split([' ', '\t']).filter(|t| !t.is_empty());
let Some(gate) = toks.next() else { continue };
if gate.starts_with('#') {
continue;
}
if !valid_gate(gate) || gates.iter().any(|(g, _)| g == gate) {
return None;
}
let paths: Vec<String> = toks.map(String::from).collect();
if paths.is_empty() || paths.len() > MAX_SPEC_PATHS || paths.iter().any(|p| bad_path(p)) {
return None;
}
gates.push((gate.to_string(), paths));
if gates.len() > MAX_SPEC_GATES {
return None;
}
}
Some(gates)
}
fn spec_at(tree: &str) -> Option<Vec<(String, Vec<String>)>> {
let present: Vec<&str> = SPEC_PATHS
.iter()
.copied()
.filter(|p| crate::git::succeeds(&["cat-file", "-e", &format!("{tree}:{p}")]))
.collect();
let [path] = present.as_slice() else {
return None;
};
let bytes = crate::git::stdout_raw(&["cat-file", "blob", &format!("{tree}:{path}")])?;
parse_spec(&bytes)
}
fn implicit_inputs(tokens: &[String]) -> Vec<String> {
let mut attrs: Vec<String> = vec![".gitattributes".to_string()];
for t in tokens {
let comps: Vec<&str> = t.split('/').collect();
let mut prefix = String::new();
for c in &comps[..comps.len().saturating_sub(1)] {
if !prefix.is_empty() {
prefix.push('/');
}
prefix.push_str(c);
attrs.push(format!("{prefix}/.gitattributes"));
}
}
attrs.sort();
attrs.dedup();
let mut out: Vec<String> = SPEC_PATHS.iter().map(|s| s.to_string()).collect();
out.push(".gitmodules".to_string());
out.extend(attrs);
out
}
fn is_oid(s: &str) -> bool {
(s.len() == 40 || s.len() == 64)
&& s.bytes()
.all(|b| b.is_ascii_hexdigit() && !b.is_ascii_uppercase())
}
fn fingerprint(tree: &str, paths: &[String]) -> Option<String> {
let names: String = paths.iter().map(|p| format!("{tree}:{p}\n")).collect();
let answers = crate::git::stdout_piped(&["cat-file", "--batch-check"], &names)?;
if answers.lines().count() != paths.len() || answers.lines().any(|l| l.ends_with(" missing")) {
return None;
}
let mut args: Vec<String> = vec![
"ls-tree".into(),
"-r".into(),
"-z".into(),
"--full-tree".into(),
tree.to_string(),
"--".into(),
];
args.extend(implicit_inputs(paths));
args.extend(paths.iter().cloned());
let argv: Vec<&str> = args.iter().map(String::as_str).collect();
let listing = crate::git::stdout_raw(&argv)?;
if listing.is_empty() {
return None;
}
crate::git::stdout_piped_in(
std::path::Path::new("."),
&["hash-object", "--stdin"],
&listing,
)
.filter(|s| is_oid(s))
}
fn inputs_for(tree: &str, gates: &[String]) -> Vec<(String, String)> {
let Some(spec) = spec_at(tree) else {
return Vec::new();
};
spec.iter()
.filter(|(g, _)| gates.iter().any(|x| x == g))
.filter_map(|(g, paths)| fingerprint(tree, paths).map(|fp| (g.clone(), fp)))
.collect()
}
fn input_key(gate: &str, fp: &str) -> Option<String> {
let pre = format!("amont-attest-input {gate} {fp}\n");
crate::git::stdout_piped_in(
std::path::Path::new("."),
&["hash-object", "--stdin"],
pre.as_bytes(),
)
.filter(|s| is_oid(s))
}
fn sign(payload: &str, key: &std::path::Path) -> Option<String> {
use std::io::Write;
let mut child = Command::new("ssh-keygen")
.args(["-Y", "sign", "-n", NAMESPACE, "-f"])
.arg(key)
.stdin(Stdio::piped())
.stdout(Stdio::piped())
.stderr(Stdio::null())
.spawn()
.ok()?;
child.stdin.take()?.write_all(payload.as_bytes()).ok()?;
let out = child.wait_with_output().ok()?;
if !out.status.success() {
return None;
}
let sig = String::from_utf8_lossy(&out.stdout).trim().to_string();
sig.starts_with("-----BEGIN SSH SIGNATURE-----")
.then_some(sig)
}
fn create_exclusive(path: &std::path::Path) -> Option<std::fs::File> {
std::fs::OpenOptions::new()
.write(true)
.create_new(true)
.open(path)
.ok()
}
pub fn verify(
payload: &str,
sig: &str,
allowed_signers: &std::path::Path,
principal: &str,
) -> bool {
use std::io::Write;
let nonce = std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.map(|d| d.subsec_nanos())
.unwrap_or(0);
let sig_file = std::env::temp_dir().join(format!(
"amont-attest-verify-{}-{:p}-{nonce}.sig",
std::process::id(),
&sig
));
let Some(mut f) = create_exclusive(&sig_file) else {
return false;
};
if f.write_all(format!("{sig}\n").as_bytes()).is_err() {
let _ = std::fs::remove_file(&sig_file);
return false;
}
drop(f);
let ok = (|| {
let mut child = Command::new("ssh-keygen")
.args(["-Y", "verify", "-n", NAMESPACE, "-I", principal, "-f"])
.arg(allowed_signers)
.arg("-s")
.arg(&sig_file)
.stdin(Stdio::piped())
.stdout(Stdio::null())
.stderr(Stdio::null())
.spawn()
.ok()?;
child.stdin.take()?.write_all(payload.as_bytes()).ok()?;
child.wait().ok().map(|s| s.success())
})()
.unwrap_or(false);
let _ = std::fs::remove_file(&sig_file);
ok
}
pub fn attest_push(
settings: &crate::config::Settings,
remote: &str,
refs: &[PushRef],
gates: &[String],
) {
if gates.is_empty() || remote.is_empty() || !enabled(settings) {
return;
}
let Some(key) = key_path() else { return };
if !key.exists() {
crate::config::complain(
TOGGLE,
&format!("signing key {} does not exist", key.display()),
"no attestation (CI will run the tests)",
);
return;
}
let mut blocks: Vec<(String, String)> = Vec::new();
let mut input_blocks: Vec<(String, String)> = Vec::new();
for r in refs {
if is_zero(&r.local_oid) {
continue; }
let spec = format!("{}^{{tree}}", r.local_oid);
let Some(tree) = crate::git::stdout(&["rev-parse", &spec]) else {
continue;
};
let inputs = inputs_for(&tree, gates);
let p = payload(&tree, gates, &inputs);
let body = match sign(&p, &key) {
Some(sig) => format!("{p}\n{sig}"),
None => continue,
};
for (gate, fp) in &inputs {
if let Some(k) = input_key(gate, fp) {
input_blocks.push((k, body.clone()));
}
}
blocks.push((tree, body.clone()));
blocks.push((r.local_oid.clone(), body));
}
if blocks.is_empty() {
return;
}
let main_ok = publish(remote, NOTES_FULL_REF, &blocks);
let inputs_ok = input_blocks.is_empty() || publish(remote, INPUTS_FULL_REF, &input_blocks);
if main_ok {
crate::say!(
"{} attested {} for CI ({}{})",
crate::ui::valid_sign(),
crate::ui::highlight(&gates.join(" ")),
NOTES_REF,
if input_blocks.is_empty() {
String::new()
} else if inputs_ok {
format!(", {} input fingerprints", input_blocks.len())
} else {
", input fingerprints not published".to_string()
},
);
}
}
const PUSH_ATTEMPTS: u32 = 4;
fn publish(remote: &str, notes_ref: &str, blocks: &[(String, String)]) -> bool {
let short = notes_ref.trim_start_matches("refs/notes/");
let tmp = format!("amont-attest-push-{}-{short}", std::process::id());
let tmp_full = format!("refs/notes/{tmp}");
let fetch_spec = format!("+{notes_ref}:{tmp_full}");
let push_spec = format!("{tmp_full}:{notes_ref}");
let mut published = false;
for _ in 0..PUSH_ATTEMPTS {
let _ = crate::git::succeeds(&["update-ref", "-d", &tmp_full]);
let _ = crate::git::succeeds(&["fetch", "--quiet", remote, &fetch_spec]);
let mut appended = false;
for (object, body) in blocks {
let existing =
crate::git::stdout(&["notes", "--ref", &tmp, "show", object]).unwrap_or_default();
if existing.contains(body.trim_end()) {
continue;
}
if crate::git::succeeds(&["notes", "--ref", &tmp, "append", "-m", body, object]) {
appended = true;
}
}
if !appended {
published = true;
break;
}
match push_notes(remote, &push_spec) {
Push::Done => {
published = true;
break;
}
Push::Raced => continue,
Push::Refused => break,
}
}
if published {
let _ = crate::git::succeeds(&["update-ref", notes_ref, &tmp_full]);
}
let _ = crate::git::succeeds(&["update-ref", "-d", &tmp_full]);
published
}
enum Push {
Done,
Raced,
Refused,
}
pub fn covered(
signers: &std::path::Path,
principal: &str,
require_platform: Option<&str>,
) -> Option<String> {
let refspec = format!("+{NOTES_FULL_REF}:{NOTES_FULL_REF}");
let _ = crate::git::succeeds(&["fetch", "origin", &refspec]);
let head_tree = crate::git::stdout(&["rev-parse", "HEAD^{tree}"])?;
for candidate in [head_tree.as_str(), "HEAD", "HEAD^2"] {
let Some(object) = crate::git::stdout(&["rev-parse", "--verify", candidate]) else {
continue;
};
let Some(body) = crate::git::stdout(&["notes", "--ref", NOTES_REF, "show", &object]) else {
continue;
};
let Some((payload, sig)) = split_note(&body) else {
continue;
};
let mut lines = payload.lines();
if lines.next() != Some(FORMAT) {
continue;
}
let field = |name: &str| {
payload
.lines()
.find_map(|l| l.strip_prefix(name).and_then(|r| r.strip_prefix(' ')))
.map(str::trim)
};
let (Some(tree), Some(gates), Some(ran_on)) =
(field("tree"), field("gates"), field("platform"))
else {
continue;
};
if tree != head_tree || gates.is_empty() {
continue; }
if require_platform.is_some_and(|want| want != ran_on) {
continue;
}
if verify(&payload, &sig, signers, principal) {
return Some(gates.to_string());
}
}
None
}
pub fn default_signers() -> Option<PathBuf> {
let root = crate::git::stdout(&["rev-parse", "--show-toplevel"]).map(PathBuf::from);
[".forgejo/allowed_signers", ".github/allowed_signers"]
.into_iter()
.map(|rel| match &root {
Some(root) => root.join(rel),
None => PathBuf::from(rel),
})
.find(|p| p.exists())
}
pub fn first_principal(signers: &std::path::Path) -> Option<String> {
let body = std::fs::read_to_string(signers).ok()?;
body.lines()
.map(str::trim)
.find(|l| !l.is_empty() && !l.starts_with('#'))
.and_then(|l| l.split_whitespace().next())
.map(str::to_string)
}
fn split_note(body: &str) -> Option<(String, String)> {
let (payload, sig) = body.split_once("\n\n")?;
if !sig.starts_with("-----BEGIN SSH SIGNATURE-----") {
return None;
}
Some((format!("{payload}\n"), sig.to_string()))
}
fn push_notes(remote: &str, refspec: &str) -> Push {
let out = Command::new("git")
.args(["push", "--quiet", remote, refspec])
.env(PUSH_GUARD, "1")
.stdin(Stdio::null())
.stdout(Stdio::null())
.output();
let Ok(out) = out else { return Push::Refused };
if out.status.success() {
return Push::Done;
}
let err = String::from_utf8_lossy(&out.stderr);
if [
"non-fast-forward",
"fetch first",
"stale info",
"cannot lock ref",
"failed to lock",
]
.iter()
.any(|m| err.contains(m))
{
Push::Raced
} else {
Push::Refused
}
}
fn is_zero(oid: &str) -> bool {
!oid.is_empty() && oid.bytes().all(|b| b == b'0')
}
pub fn forget() -> bool {
crate::git::succeeds(&["update-ref", "-d", NOTES_FULL_REF])
}
pub fn forget_in(repo: &std::path::Path) -> bool {
crate::git::succeeds_in(repo, &["update-ref", "-d", NOTES_FULL_REF])
}
#[cfg(test)]
mod tests {
use super::*;
fn test_settings() -> crate::config::Settings {
crate::config::Settings::default()
}
use std::path::Path;
fn dir(name: &str) -> PathBuf {
let d = std::env::temp_dir().join(format!("attest-{name}-{}", std::process::id()));
let _ = std::fs::remove_dir_all(&d);
std::fs::create_dir_all(&d).unwrap();
d
}
fn git(dir: &Path, args: &[&str]) -> String {
let out = std::process::Command::new("git")
.arg("-C")
.arg(dir)
.args(args)
.output()
.expect("git");
assert!(
out.status.success(),
"fixture: git {args:?} in {} exited {:?}: {}",
dir.display(),
out.status.code(),
String::from_utf8_lossy(&out.stderr).trim()
);
String::from_utf8_lossy(&out.stdout).trim().to_string()
}
fn repo(name: &str) -> PathBuf {
let d = dir(name);
git(&d, &["init", "-q", "--template=", "."]);
git(&d, &["config", "user.email", "t@t.test"]);
git(&d, &["config", "user.name", "t"]);
d
}
fn keypair(d: &Path) -> (PathBuf, PathBuf) {
let key = d.join("attest_key");
let ok = std::process::Command::new("ssh-keygen")
.args(["-q", "-t", "ed25519", "-N", "", "-C", "test", "-f"])
.arg(&key)
.status()
.expect("ssh-keygen must exist for these tests")
.success();
assert!(ok, "keygen failed");
let pubkey = std::fs::read_to_string(key.with_extension("pub")).unwrap();
let signers = d.join("allowed_signers");
std::fs::write(
&signers,
format!("t@t.test namespaces=\"{NAMESPACE}\" {pubkey}"),
)
.unwrap();
(key, signers)
}
fn in_repo<T>(dir: &Path, f: impl FnOnce() -> T) -> T {
let _guard = crate::TEST_CWD.lock().unwrap_or_else(|p| p.into_inner());
let prev = std::env::current_dir().unwrap();
std::env::set_current_dir(dir).unwrap();
let r = f();
std::env::set_current_dir(prev).unwrap();
r
}
#[test]
fn the_signature_file_refuses_to_follow_what_is_already_there() {
let dir = std::env::temp_dir().join(format!("amont-excl-{}", std::process::id()));
let _ = std::fs::remove_dir_all(&dir);
std::fs::create_dir_all(&dir).expect("temp dir");
let taken = dir.join("taken");
std::fs::write(&taken, "original").expect("seed");
assert!(create_exclusive(&taken).is_none());
assert_eq!(std::fs::read_to_string(&taken).unwrap(), "original");
#[cfg(unix)]
{
let victim = dir.join("victim");
std::fs::write(&victim, "precious").expect("seed");
let link = dir.join("link");
std::os::unix::fs::symlink(&victim, &link).expect("symlink");
assert!(
create_exclusive(&link).is_none(),
"a symlink must be refused, not followed"
);
assert_eq!(
std::fs::read_to_string(&victim).unwrap(),
"precious",
"the link target was written through"
);
}
let fresh = dir.join("fresh");
assert!(create_exclusive(&fresh).is_some());
let _ = std::fs::remove_dir_all(&dir);
}
#[test]
fn the_payload_is_the_documented_contract() {
let p = payload(
"abc123",
&["pre-push-pytest".into(), "pre-push-cargo-test".into()],
&[],
);
let lines: Vec<&str> = p.lines().collect();
assert_eq!(lines[0], FORMAT);
assert_eq!(lines[1], "tree abc123");
assert_eq!(lines[2], "gates pre-push-pytest pre-push-cargo-test");
assert_eq!(lines[3], format!("platform {}", platform()));
assert_eq!(lines[4], format!("amont {}", env!("CARGO_PKG_VERSION")));
assert!(
p.ends_with('\n'),
"CI reconstructs these bytes; the trailing newline is part of them"
);
}
#[test]
fn sign_verify_roundtrip_and_tamper_rejection() {
let d = dir("roundtrip");
let (key, signers) = keypair(&d);
let p = payload("deadbeef", &["pre-push-pytest".into()], &[]);
let sig = sign(&p, &key).expect("signing with a real key succeeds");
assert!(verify(&p, &sig, &signers, "t@t.test"));
let tampered = payload("deadbeee", &["pre-push-pytest".into()], &[]);
assert!(!verify(&tampered, &sig, &signers, "t@t.test"));
assert!(!verify(&p, &sig, &signers, "someone@else.test"));
let _ = std::fs::remove_dir_all(&d);
}
#[test]
fn a_missing_key_signs_nothing() {
assert!(sign("anything", Path::new("/nonexistent/key")).is_none());
}
#[test]
fn an_enabled_push_leaves_a_verifiable_note_on_the_remote() {
let d = dir("e2e");
let (key, signers) = keypair(&d);
let remote = d.join("remote.git");
std::fs::create_dir_all(&remote).unwrap();
git(&remote, &["init", "-q", "--bare", "--template=", "."]);
let work = repo("e2e-work");
git(
&work,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&work, &["config", "amont.attest", "true"]);
git(&work, &["config", "amont.attestKey", key.to_str().unwrap()]);
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "chore: a"]);
let head = git(&work, &["rev-parse", "HEAD"]);
let tree = git(&work, &["rev-parse", "HEAD^{tree}"]);
let push_ref = PushRef {
local_ref: "refs/heads/main".into(),
local_oid: head.clone(),
remote_ref: "refs/heads/main".into(),
remote_oid: "0".repeat(40),
};
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref],
&["pre-push-run-tests-js".into()],
);
});
let body = git(&remote, &["notes", "--ref", NOTES_REF, "show", &head]);
assert!(!body.is_empty(), "no note reached the remote");
let (p, sig) = body
.split_once("\n\n")
.expect("payload, blank line, signature");
let p = format!("{p}\n"); assert!(p.starts_with(FORMAT));
assert!(
p.contains(&format!("tree {tree}")),
"attests the pushed tree"
);
assert!(
verify(&p, sig, &signers, "t@t.test"),
"the remote copy verifies"
);
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
fn remote_and_work(name: &str) -> (PathBuf, PathBuf, PathBuf, PathBuf) {
let d = dir(name);
let (key, signers) = keypair(&d);
let remote = d.join("remote.git");
std::fs::create_dir_all(&remote).unwrap();
git(&remote, &["init", "-q", "--bare", "--template=", "."]);
let work = repo(&format!("{name}-work"));
git(
&work,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&work, &["config", "amont.attest", "true"]);
git(&work, &["config", "amont.attestKey", key.to_str().unwrap()]);
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "chore: a"]);
(d, work, remote, signers)
}
fn push_ref_for(work: &Path) -> PushRef {
PushRef {
local_ref: "refs/heads/main".into(),
local_oid: git(work, &["rev-parse", "HEAD"]),
remote_ref: "refs/heads/main".into(),
remote_oid: "0".repeat(40),
}
}
fn blocks_in(body: &str) -> usize {
body.matches("-----BEGIN SSH SIGNATURE-----").count()
}
#[test]
fn a_block_already_on_the_remote_survives_and_ours_is_appended() {
let (d, work, remote, _) = remote_and_work("append");
let tree = git(&work, &["rev-parse", "HEAD^{tree}"]);
let seed = repo("append-seed");
git(
&seed,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&seed, &["fetch", "-q", "origin"]);
std::fs::write(seed.join("a.ts"), "x").unwrap();
git(&seed, &["add", "a.ts"]);
git(&seed, &["commit", "-qm", "chore: a"]);
let foreign = "amont-attest-v2\ntree x\ngates ci-fmt\nplatform s390x-aix\namont other\n\n-----BEGIN SSH SIGNATURE-----\nnope\n-----END SSH SIGNATURE-----";
git(
&seed,
&["notes", "--ref", NOTES_REF, "add", "-m", foreign, &tree],
);
git(
&seed,
&[
"push",
"-q",
"origin",
&format!("{NOTES_FULL_REF}:{NOTES_FULL_REF}"),
],
);
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref_for(&work)],
&["pre-push-run-tests-js".into()],
);
});
let body = git(&remote, &["notes", "--ref", NOTES_REF, "show", &tree]);
assert_eq!(blocks_in(&body), 2, "both blocks on the remote:\n{body}");
assert!(body.contains("gates ci-fmt"), "the foreign block survives");
assert!(
body.contains("gates pre-push-run-tests-js"),
"ours was appended"
);
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
let _ = std::fs::remove_dir_all(&seed);
}
#[test]
fn a_stale_local_notes_ref_no_longer_loses_the_push() {
let (d, work, remote, _) = remote_and_work("stale");
let head = git(&work, &["rev-parse", "HEAD"]);
git(
&work,
&[
"notes",
"--ref",
NOTES_REF,
"add",
"-m",
"stale local",
&head,
],
);
let stale = git(&work, &["rev-parse", NOTES_FULL_REF]);
let seed = repo("stale-seed");
std::fs::write(seed.join("b.ts"), "y").unwrap();
git(&seed, &["add", "b.ts"]);
git(&seed, &["commit", "-qm", "chore: b"]);
git(
&seed,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(
&seed,
&[
"notes",
"--ref",
NOTES_REF,
"add",
"-m",
"remote first",
"HEAD",
],
);
git(&seed, &["push", "-q", "origin", "HEAD:refs/heads/other"]);
git(
&seed,
&[
"push",
"-q",
"origin",
&format!("{NOTES_FULL_REF}:{NOTES_FULL_REF}"),
],
);
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref_for(&work)],
&["pre-push-run-tests-js".into()],
);
});
let body = git(&remote, &["notes", "--ref", NOTES_REF, "show", &head]);
assert!(
body.contains("gates pre-push-run-tests-js"),
"the push landed:\n{body}"
);
assert_ne!(
git(&work, &["rev-parse", NOTES_FULL_REF]),
stale,
"the local ref followed the published state"
);
assert!(
git(&work, &["for-each-ref", "refs/notes/amont-attest-push-*"]).is_empty(),
"no temporary ref left behind"
);
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
let _ = std::fs::remove_dir_all(&seed);
}
#[test]
fn a_second_push_of_the_same_tree_appends_nothing() {
let (d, work, remote, _) = remote_and_work("twice");
let tree = git(&work, &["rev-parse", "HEAD^{tree}"]);
for _ in 0..2 {
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref_for(&work)],
&["pre-push-run-tests-js".into()],
);
});
}
let body = git(&remote, &["notes", "--ref", NOTES_REF, "show", &tree]);
assert_eq!(blocks_in(&body), 1, "one block, not two:\n{body}");
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn a_spec_yields_input_lines_and_fingerprint_keyed_notes() {
let (d, work, remote, _) = remote_and_work("inputs");
std::fs::create_dir_all(work.join(".github")).unwrap();
std::fs::write(
work.join(".github/attest-inputs"),
"# what each gate reads\npre-push-run-tests-js a.ts\nother nope\n",
)
.unwrap();
git(&work, &["add", ".github/attest-inputs"]);
git(&work, &["commit", "-qm", "chore: spec"]);
let tree = git(&work, &["rev-parse", "HEAD^{tree}"]);
let listing = std::process::Command::new("git")
.args([
"-C",
work.to_str().unwrap(),
"ls-tree",
"-r",
"-z",
"--full-tree",
&tree,
"--",
".forgejo/attest-inputs",
".github/attest-inputs",
".gitmodules",
".gitattributes",
"a.ts",
])
.output()
.unwrap()
.stdout;
let expected =
crate::git::stdout_piped_in(&work, &["hash-object", "--stdin"], &listing).unwrap();
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref_for(&work)],
&["pre-push-run-tests-js".into(), "other".into()],
);
});
let body = git(&remote, &["notes", "--ref", NOTES_REF, "show", &tree]);
assert!(
body.contains(&format!("input pre-push-run-tests-js {expected}\n")),
"the input line carries the reference fingerprint:\n{body}"
);
assert!(
!body.contains("input other "),
"a gate whose path does not exist gets no line"
);
let key = crate::git::stdout_piped_in(
&work,
&["hash-object", "--stdin"],
format!("amont-attest-input pre-push-run-tests-js {expected}\n").as_bytes(),
)
.unwrap();
let under_key = git(&remote, &["notes", "--ref", INPUTS_REF, "show", &key]);
assert_eq!(
under_key, body,
"the same block is filed under the fingerprint key"
);
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref_for(&work)],
&["pre-push-run-tests-js".into(), "other".into()],
);
});
assert_eq!(
git(&remote, &["notes", "--ref", INPUTS_REF, "show", &key])
.matches("BEGIN SSH SIGNATURE")
.count(),
1
);
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn without_a_valid_spec_the_block_is_tree_keyed_only() {
let (d, work, remote, _) = remote_and_work("nospec");
std::fs::create_dir_all(work.join(".github")).unwrap();
std::fs::write(
work.join(".github/attest-inputs"),
"pre-push-run-tests-js src/*.ts\n",
)
.unwrap();
git(&work, &["add", ".github/attest-inputs"]);
git(&work, &["commit", "-qm", "chore: bad spec"]);
let tree = git(&work, &["rev-parse", "HEAD^{tree}"]);
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref_for(&work)],
&["pre-push-run-tests-js".into()],
);
});
let body = git(&remote, &["notes", "--ref", NOTES_REF, "show", &tree]);
assert!(!body.contains("\ninput "), "no input line:\n{body}");
assert!(
!crate::git::succeeds_in(
&remote,
&["rev-parse", "--verify", "--quiet", INPUTS_FULL_REF]
),
"no inputs ref was created"
);
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn the_spec_grammar_is_attests() {
assert!(parse_spec(b"# c\ng src Cargo.toml\n").is_some());
for bad in [
b"g src/*.rs\n".as_slice(),
b"g :!x\n",
b"g\n",
b"g src\ng x\n",
b"g src\r\n",
b"g sr\xc3\xa9\n",
b"-g src\n",
b"g ./src\n",
b"g src/\n",
b"g a/../b\n",
] {
assert!(parse_spec(bad).is_none(), "{bad:?}");
}
assert_eq!(
implicit_inputs(&["crates/foo/src".into()]),
[
".forgejo/attest-inputs",
".github/attest-inputs",
".gitmodules",
".gitattributes",
"crates/.gitattributes",
"crates/foo/.gitattributes"
]
);
}
#[test]
fn no_opt_in_means_no_note() {
let d = dir("optout");
let (key, _) = keypair(&d);
let remote = d.join("remote.git");
std::fs::create_dir_all(&remote).unwrap();
git(&remote, &["init", "-q", "--bare", "--template=", "."]);
let work = repo("optout-work");
git(
&work,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&work, &["config", "amont.attestKey", key.to_str().unwrap()]);
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "chore: a"]);
let head = git(&work, &["rev-parse", "HEAD"]);
let push_ref = PushRef {
local_ref: "refs/heads/main".into(),
local_oid: head.clone(),
remote_ref: "refs/heads/main".into(),
remote_oid: "0".repeat(40),
};
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref],
&["pre-push-run-tests-js".into()],
);
});
assert!(
git(&remote, &["notes", "--ref", NOTES_REF, "list"]).is_empty(),
"an un-opted-in repo attested something"
);
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn deletions_and_empty_gates_attest_nothing() {
let d = dir("nothing");
let (key, _) = keypair(&d);
let remote = d.join("remote.git");
std::fs::create_dir_all(&remote).unwrap();
git(&remote, &["init", "-q", "--bare", "--template=", "."]);
let work = repo("nothing-work");
git(
&work,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&work, &["config", "amont.attest", "true"]);
git(&work, &["config", "amont.attestKey", key.to_str().unwrap()]);
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "chore: a"]);
let head = git(&work, &["rev-parse", "HEAD"]);
let deletion = PushRef {
local_ref: "(delete)".into(),
local_oid: "0".repeat(40),
remote_ref: "refs/heads/gone".into(),
remote_oid: head.clone(),
};
let real = PushRef {
local_ref: "refs/heads/main".into(),
local_oid: head,
remote_ref: "refs/heads/main".into(),
remote_oid: "0".repeat(40),
};
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[deletion],
&["pre-push-pytest".into()],
);
attest_push(&test_settings(), "origin", &[real], &[]);
});
assert!(git(&remote, &["notes", "--ref", NOTES_REF, "list"]).is_empty());
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn covered_answers_in_a_fresh_clone_and_rejects_drift_and_forgery() {
let d = dir("covered");
let (key, signers) = keypair(&d);
let remote = d.join("remote.git");
std::fs::create_dir_all(&remote).unwrap();
git(&remote, &["init", "-q", "--bare", "--template=", "."]);
git(&remote, &["symbolic-ref", "HEAD", "refs/heads/main"]);
let work = repo("covered-work");
git(
&work,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&work, &["config", "amont.attest", "true"]);
git(&work, &["config", "amont.attestKey", key.to_str().unwrap()]);
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "chore: a"]);
git(&work, &["push", "-q", "origin", "HEAD:main"]);
let head = git(&work, &["rev-parse", "HEAD"]);
let push_ref = PushRef {
local_ref: "refs/heads/main".into(),
local_oid: head.clone(),
remote_ref: "refs/heads/main".into(),
remote_oid: "0".repeat(40),
};
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref],
&["pre-push-pytest".into()],
);
});
let clone = d.join("ci-checkout");
git(
&d,
&[
"clone",
"-q",
"--template=",
remote.to_str().unwrap(),
clone.to_str().unwrap(),
],
);
in_repo(&clone, || {
assert_eq!(
covered(&signers, "t@t.test", Some(&platform())).as_deref(),
Some("pre-push-pytest"),
"a fresh clone verifies the attestation and reads the gates"
);
assert_eq!(
covered(&signers, "t@t.test", None).as_deref(),
Some("pre-push-pytest"),
"`any` covers a platform-independent suite"
);
assert_eq!(
covered(&signers, "t@t.test", Some("s390x-aix")),
None,
"a pass on one platform is not evidence about another"
);
assert_eq!(
covered(&signers, "someone@else.test", None),
None,
"an unlisted principal covers nothing"
);
});
std::fs::write(clone.join("b.ts"), "y").unwrap();
git(&clone, &["config", "user.email", "t@t.test"]);
git(&clone, &["config", "user.name", "t"]);
git(&clone, &["add", "b.ts"]);
git(&clone, &["commit", "-qm", "chore: b"]);
in_repo(&clone, || {
assert_eq!(covered(&signers, "t@t.test", None), None, "drifted tree");
});
let head_tree = git(&work, &["rev-parse", "HEAD^{tree}"]);
for object in [&head, &head_tree] {
git(
&work,
&[
"notes", "--ref", NOTES_REF, "add", "-f", "-m", "garbage", object,
],
);
}
git(
&work,
&[
"push",
"-q",
"origin",
&format!("+{NOTES_FULL_REF}:{NOTES_FULL_REF}"),
],
);
git(&clone, &["reset", "-q", "--hard", &head]);
in_repo(&clone, || {
assert_eq!(
covered(&signers, "t@t.test", None),
None,
"a foreign note is not a stamp"
);
});
let _ = std::fs::remove_dir_all(&d);
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn default_signers_is_found_from_a_subdirectory() {
let work = repo("signers-subdir");
std::fs::create_dir_all(work.join(".forgejo")).unwrap();
std::fs::write(work.join(".forgejo/allowed_signers"), "t@t.test x\n").unwrap();
let sub = work.join("packages").join("thing");
std::fs::create_dir_all(&sub).unwrap();
in_repo(&sub, || {
let found = default_signers().expect("resolved from the repo root, not the cwd");
assert!(found.ends_with(".forgejo/allowed_signers"));
assert!(found.exists(), "the path it returns must be usable as-is");
assert_eq!(
first_principal(&found).as_deref(),
Some("t@t.test"),
"and readable from there"
);
});
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn zero_oids_of_any_width_are_zero() {
assert!(is_zero(&"0".repeat(40)));
assert!(is_zero(&"0".repeat(64)));
assert!(!is_zero("0a0000"));
assert!(!is_zero(""));
}
#[test]
fn forget_removes_the_local_ref() {
let work = repo("forget");
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "chore: a"]);
git(
&work,
&["notes", "--ref", NOTES_REF, "add", "-m", "x", "HEAD"],
);
in_repo(&work, forget);
assert!(git(&work, &["notes", "--ref", NOTES_REF, "list"]).is_empty());
let _ = std::fs::remove_dir_all(&work);
}
#[test]
fn an_attestation_survives_a_rewrite_that_keeps_the_tree() {
let d = dir("rewritten");
let (key, signers) = keypair(&d);
let remote = d.join("remote.git");
std::fs::create_dir_all(&remote).unwrap();
git(&remote, &["init", "-q", "--bare", "--template=", "."]);
git(&remote, &["symbolic-ref", "HEAD", "refs/heads/main"]);
let work = repo("rewritten-work");
git(
&work,
&["remote", "add", "origin", remote.to_str().unwrap()],
);
git(&work, &["config", "amont.attest", "true"]);
git(&work, &["config", "amont.attestKey", key.to_str().unwrap()]);
std::fs::write(work.join("a.ts"), "x").unwrap();
git(&work, &["add", "a.ts"]);
git(&work, &["commit", "-qm", "feat: on a branch"]);
git(&work, &["push", "-q", "origin", "HEAD:main"]);
let branch_tip = git(&work, &["rev-parse", "HEAD"]);
let push_ref = PushRef {
local_ref: "refs/heads/main".into(),
local_oid: branch_tip.clone(),
remote_ref: "refs/heads/main".into(),
remote_oid: "0".repeat(40),
};
in_repo(&work, || {
attest_push(
&test_settings(),
"origin",
&[push_ref],
&["pre-push-pytest".into()],
);
});
git(
&work,
&[
"commit",
"-q",
"--amend",
"-m",
"feat: squashed by the forge",
],
);
let rewritten = git(&work, &["rev-parse", "HEAD"]);
assert_ne!(rewritten, branch_tip, "the fixture must rewrite the commit");
assert_eq!(
git(&work, &["rev-parse", "HEAD^{tree}"]),
git(&work, &["rev-parse", &format!("{branch_tip}^{{tree}}")]),
"…while preserving the tree, which is the premise"
);
git(&work, &["push", "-q", "-f", "origin", "HEAD:main"]);
let clone = d.join("ci-checkout");
git(
&d,
&[
"clone",
"-q",
"--template=",
remote.to_str().unwrap(),
clone.to_str().unwrap(),
],
);
in_repo(&clone, || {
assert_eq!(
covered(&signers, "t@t.test", None).as_deref(),
Some("pre-push-pytest"),
"the attestation must be found by the tree it signed"
);
});
let _ = std::fs::remove_dir_all(&d);
}
}