test(golang): make the UPX fixture exercise loader padding - #5354
Merged
willmurphyscode merged 1 commit intoSep 29, 2026
Merged
willmurphyscode merged 1 commit into
willmurphyscode merged 1 commit into
Conversation
UPX pads to a 4 byte boundary before it writes the loader stub. The image-small-upx build happened to need no padding, so the cataloger tests over it passed with or without the fix in anchore#5347. - build the fixture with -X main.Version=1.0.11, which needs 2 bytes of padding, so the existing cataloger tests fail without the fix - add TestImageSmallUPXNeedsLoaderPadding, which fails if a change to the fixture's inputs means it no longer needs padding - run the crafted loader test on both sides of the boundary, so a skip that always rounds up is caught too Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
wagoodman
approved these changes
Sep 29, 2026
willmurphyscode
enabled auto-merge (squash)
September 29, 2026 18:51
spiffcs
added a commit
that referenced
this pull request
Sep 30, 2026
* main: (91 commits) feat: catalog CPAN distributions installed by perl clients (#5131) fix(binary): correct traefik version detection on big-endian arches (#5281) Fix hang when scanning a Java resource adapter (.rar) file (#5348) chore(deps): update SPDX license list (#5315) fix: match opensource.org license URLs across SPDX URL forms (#5361) Speed up unit tests in CI (#5360) Fix missing file hashes when running on windows system (#5341) Stop reading the mount table for every single-file source (#5257) fix: conan expat CPE (#5259) fix(spdx): write a name for the root package when the source has none (#5349) fix(python): link uv.lock dependents to the locked version they name (#5351) fix: suppress misleading upstream CPE for PHP extension binaries (#5102) fix: report scanner errors and raise the line cap in metadata parsers (#5353) Harden cataloger parsers against truncated input (do not panic) (#5355) fix(cpe): bound CPE candidate generation for pathological package metadata (#5356) test(golang): make the UPX fixture exercise loader padding (#5354) fix(golang): account for UPX's loader padding when unpacking Go binaries (#5347) test(snap): bound the kernel changelog bomb fixture by ratio, not a fixed 1MB (#5352) test(debian): bound the bomb fixture by ratio, not a fixed 1MB (#5350) fix(ai): handle malformed GGUF headers without panicking (#5345) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
UPX pads to a 4 byte boundary before it writes the loader stub. The image-small-upx build happened to need no padding, so the cataloger tests over it passed with or without the fix in #5347.
This is some additional test coverage that would have made the regression that #5195 introduced and #5347 less like to occur in the first place. (Thanks @huuyafwww!)
Type of change
Checklist
Issue references