Skip to content

test(golang): make the UPX fixture exercise loader padding - #5354

Merged
willmurphyscode merged 1 commit into
anchore:mainfrom
willmurphyscode:test/upx-loader-padding-coverage
Sep 29, 2026
Merged

willmurphyscode merged 1 commit into
anchore:mainfrom
willmurphyscode:test/upx-loader-padding-coverage

Conversation

@willmurphyscode

Copy link
Copy Markdown
Contributor

UPX pads to a 4 byte boundary before it writes the loader stub. The image-small-upx build happened to need no padding, so the cataloger tests over it passed with or without the fix in #5347.

  • build the fixture with -X main.Version=1.0.11, which needs 2 bytes of padding, so the existing cataloger tests fail without the fix
  • add TestImageSmallUPXNeedsLoaderPadding, which fails if a change to the fixture's inputs means it no longer needs padding
  • run the crafted loader test on both sides of the boundary, so a skip that always rounds up is caught too

This is some additional test coverage that would have made the regression that #5195 introduced and #5347 less like to occur in the first place. (Thanks @huuyafwww!)

Type of change

  • Chore (improve the developer experience, fix a test flake, etc, without changing the visible behavior of Syft)

Checklist

  • I have added unit tests that cover changed behavior
  • I have tested my code in common scenarios and confirmed there are no regressions - n/a - test only change
  • I have added comments to my code, particularly in hard-to-understand sections

Issue references

UPX pads to a 4 byte boundary before it writes the loader stub. The
image-small-upx build happened to need no padding, so the cataloger
tests over it passed with or without the fix in anchore#5347.

- build the fixture with -X main.Version=1.0.11, which needs 2 bytes of
  padding, so the existing cataloger tests fail without the fix
- add TestImageSmallUPXNeedsLoaderPadding, which fails if a change to the
  fixture's inputs means it no longer needs padding
- run the crafted loader test on both sides of the boundary, so a skip
  that always rounds up is caught too

Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
@willmurphyscode willmurphyscode added the changelog-ignore do not add a entry for this when generating the changelog label Sep 29, 2026
@willmurphyscode
willmurphyscode enabled auto-merge (squash) September 29, 2026 18:51
@willmurphyscode willmurphyscode moved this to In Review in OSS Sep 29, 2026
@willmurphyscode
willmurphyscode merged commit c60aaba into anchore:main Sep 29, 2026
15 checks passed
@willmurphyscode
willmurphyscode deleted the test/upx-loader-padding-coverage branch September 29, 2026 19:15
spiffcs added a commit that referenced this pull request Sep 30, 2026
* main: (91 commits)
  feat: catalog CPAN distributions installed by perl clients (#5131)
  fix(binary): correct traefik version detection on big-endian arches (#5281)
  Fix hang when scanning a Java resource adapter (.rar) file (#5348)
  chore(deps): update SPDX license list (#5315)
  fix: match opensource.org license URLs across SPDX URL forms (#5361)
  Speed up unit tests in CI (#5360)
  Fix missing file hashes when running on windows system (#5341)
  Stop reading the mount table for every single-file source (#5257)
  fix: conan expat CPE (#5259)
  fix(spdx): write a name for the root package when the source has none (#5349)
  fix(python): link uv.lock dependents to the locked version they name (#5351)
  fix: suppress misleading upstream CPE for PHP extension binaries (#5102)
  fix: report scanner errors and raise the line cap in metadata parsers (#5353)
  Harden cataloger parsers against truncated input (do not panic) (#5355)
  fix(cpe): bound CPE candidate generation for pathological package metadata (#5356)
  test(golang): make the UPX fixture exercise loader padding (#5354)
  fix(golang): account for UPX's loader padding when unpacking Go binaries (#5347)
  test(snap): bound the kernel changelog bomb fixture by ratio, not a fixed 1MB (#5352)
  test(debian): bound the bomb fixture by ratio, not a fixed 1MB (#5350)
  fix(ai): handle malformed GGUF headers without panicking (#5345)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog-ignore do not add a entry for this when generating the changelog

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants