-
Notifications
You must be signed in to change notification settings - Fork 84
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
jar: support unconventional jar names #1467
base: main
Are you sure you want to change the base?
Conversation
2245436
to
f0d251e
Compare
f0d251e
to
5f47a26
Compare
552f32f
to
177a66d
Compare
f8e7fb8
to
7ff485d
Compare
Signed-off-by: RTann <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The changes look ok to me. Maybe get @crozzy to have another look.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The logic essentially looks good to me, just a few comments on the tests
}, | ||
} | ||
|
||
if !cmp.Equal(got, want) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if !cmp.Equal(got, want) { | |
if !cmp.Equal(got, want, cmpopts.IgnoreFields(Info{}, "SHA")) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This doesn't seem to render correctly as markdown.
@@ -185,7 +185,7 @@ func (s *Scanner) Scan(ctx context.Context, layer *claircore.Layer) ([]*claircor | |||
infos, err := jar.Parse(ctx, n, z) | |||
switch { | |||
case err == nil: | |||
case errors.Is(err, jar.ErrUnidentified) || errors.Is(err, jar.ErrNotAJar): | |||
case errors.Is(err, jar.ErrNotAJar): | |||
// If there's an error that's one of the "known" reasons (e.g. not a |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: This comment could probably be updated to be more specific to ErrNotAJar
now
Some JAR files just have bad names 🤷. Claircore should still continue to search for inner JARs in case the found JAR embeds valid JARs. Before this, we just stopped looking through any top-level JAR file with an unconventional name.
When testing, I realized we cannot really tell the difference between JARs and "inner" JARs. I'm wondering if I should also update the package name to be the full path instead of just the final portion. That is:
return
testdata/inner/inner.jar:BOOT-INF/lib/log4j-api-2.14.jar:META-INF/inner-jar/log4j-2.14.0.jar
instead ofMETA-INF/inner-jar/log4j-2.14.0.jar
.Also, I realized the packagescanner does not consider a JAR file a valid JAR unless it has a
META-INF
directory. According to the JAR spec from the last few LTS releases (11, 17, and 21) as well as the latest non-LTS release (23):So, the
META-INF
directory is not required, so we may want to consider dropping that constraint. Thoughts?