The following nodes represent call sites where fuzz blockers occur.
| Amount of callsites blocked | Calltree index | Parent function | Callsite | Largest blocked function |
|---|---|---|---|---|
| 41 | 136 | sigstore.oidc.IdentityToken.__init__ | call site: 00136 | sigstore.oidc.Issuer.identity_token |
| 26 | 62 | sigstore._internal.tuf.TrustUpdater.get_signing_config_path | call site: 00062 | sigstore.models.ClientTrustConfig.from_tuf |
| 23 | 37 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00037 | sigstore._internal.tuf.TrustUpdater.get_trusted_root_path |
| 23 | 104 | model_signing._signing.sign_sigstore_pb.pae | call site: 00104 | model_signing._signing.sign_pkcs11.CertSigner._get_verification_material |
| 6 | 25 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00025 | sigstore._internal.tuf._get_dirs |
| 5 | 19 | ...model-transparency.tests.fuzzing.fuzz_sign_then_mutate_verify_with_valid_key.TestOneInput | call site: 00019 | sigstore.models.ClientTrustConfig.from_tuf |
| 4 | 131 | sigstore.dsse.Statement.__init__ | call site: 00131 | sigstore.oidc.IdentityToken.__init__ |
| 3 | 33 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00033 | urllib.parse.quote |
| 3 | 99 | model_signing.signing.Config.sign | call site: 00099 | model_signing._signing.sign_sigstore_pb.pae |
| 2 | 1 | ...model-transparency.tests.fuzzing.fuzz_sign_then_mutate_verify_with_valid_key.TestOneInput | call site: 00001 | tempfile.TemporaryDirectory |
| 1 | 128 | model_signing.signing.Config.sign | call site: 00128 | sigstore.dsse.Statement.__init__ |
| 1 | 181 | model_signing.signing.Config.sign | call site: 00181 | path.write_text |
...model-transparency.tests.fuzzing.fuzz_sign_then_mutate_verify_with_valid_key.TestOneInput
[function]
[call site]
00000
atheris.FuzzedDataProvider
[function]
[call site]
00001
tempfile.TemporaryDirectory
[function]
[call site]
00002
tempfile.TemporaryDirectory
[function]
[call site]
00003
pathlib.Path
[function]
[call site]
00004
utils.create_fuzz_files
[function]
[call site]
00005
utils.any_files
[function]
[call site]
00006
<builtin>.str
[function]
[call site]
00007
os.path.join
[function]
[call site]
00008
...model-transparency.tests.fuzzing.fuzz_sign_then_mutate_verify_with_valid_key._pick_key_spec
[function]
[call site]
00009
<builtin>.len
[function]
[call site]
00010
fdp.ConsumeIntInRange
[function]
[call site]
00011
utils._build_hashing_config_from_fdp
[function]
[call site]
00012
model_signing.signing.Config.__init__
[function]
[call site]
00013
hashing.Config
[function]
[call site]
00014
model_signing.signing.Config.set_hashing_config
[function]
[call site]
00015
model_signing.signing.Config.use_elliptic_key_signer
[function]
[call site]
00016
pathlib.Path
[function]
[call site]
00017
ec_key.Signer
[function]
[call site]
00018
model_signing.signing.Config.sign
[function]
[call site]
00019
model_signing.signing.Config.use_sigstore_signer
[function]
[call site]
00020
model_signing._signing.sign_sigstore.Signer.__init__
[function]
[call site]
00021
sigstore.models.ClientTrustConfig.staging
[function]
[call site]
00022
sigstore.models.ClientTrustConfig.from_tuf
[function]
[call site]
00023
sigstore._internal.tuf.TrustUpdater.__init__
[function]
[call site]
00024
url.rstrip
[function]
[call site]
00025
sigstore._internal.tuf._get_dirs
[function]
[call site]
00026
urllib.parse.quote
[function]
[call site]
00027
platformdirs.user_data_dir
[function]
[call site]
00028
pathlib.Path
[function]
[call site]
00029
platformdirs.user_cache_dir
[function]
[call site]
00030
pathlib.Path
[function]
[call site]
00031
artifact_path.exists
[function]
[call site]
00032
sigstore._utils.read_embedded
[function]
[call site]
00033
urllib.parse.quote
[function]
[call site]
00034
importlib_resources.files
[function]
[call site]
00035
importlib.resources.files
[function]
[call site]
00036
artifact_path.write_bytes
[function]
[call site]
00037
_logger.debug
[function]
[call site]
00038
_logger.debug
[function]
[call site]
00039
_logger.warning
[function]
[call site]
00040
sigstore._utils.read_embedded
[function]
[call site]
00041
bootstrap_root.read_bytes
[function]
[call site]
00042
tuf.ngclient.Updater
[function]
[call site]
00043
<builtin>.str
[function]
[call site]
00044
urllib.parse.urljoin
[function]
[call site]
00045
<builtin>.str
[function]
[call site]
00046
tuf.ngclient.UpdaterConfig
[function]
[call site]
00047
tuf.ngclient.Updater.refresh
[function]
[call site]
00048
sigstore._internal.tuf.TrustUpdater.get_trusted_root_path
[function]
[call site]
00049
_logger.debug
[function]
[call site]
00050
<builtin>.str
[function]
[call site]
00051
tuf.ngclient.Updater.get_targetinfo
[function]
[call site]
00052
tuf.ngclient.Updater.find_cached_target
[function]
[call site]
00053
tuf.ngclient.Updater.download_target
[function]
[call site]
00054
_logger.debug
[function]
[call site]
00055
pathlib.Path
[function]
[call site]
00056
pathlib.Path.read_bytes
[function]
[call site]
00057
sigstore_models.trustroot.v1.TrustedRoot.from_json
[function]
[call site]
00058
sigstore._internal.tuf.TrustUpdater.get_signing_config_path
[function]
[call site]
00059
_logger.debug
[function]
[call site]
00060
<builtin>.str
[function]
[call site]
00061
tuf.ngclient.Updater.get_targetinfo
[function]
[call site]
00062
tuf.ngclient.Updater.find_cached_target
[function]
[call site]
00063
tuf.ngclient.Updater.download_target
[function]
[call site]
00064
_logger.debug
[function]
[call site]
00065
pathlib.Path
[function]
[call site]
00066
pathlib.Path.read_bytes
[function]
[call site]
00067
sigstore_models.trustroot.v1.SigningConfig.from_json
[function]
[call site]
00068
sigstore.models.ClientTrustConfig.__init__
[function]
[call site]
00069
sigstore_models.trustroot.v1.ClientTrustConfig
[function]
[call site]
00070
sigstore.models.ClientTrustConfig.from_json
[function]
[call site]
00071
sigstore_models.trustroot.v1.ClientTrustConfig.from_json
[function]
[call site]
00072
sigstore.models.ClientTrustConfig.__init__
[function]
[call site]
00073
trust_config.read_text
[function]
[call site]
00074
sigstore.models.ClientTrustConfig.production
[function]
[call site]
00075
sigstore.models.ClientTrustConfig.from_tuf
[function]
[call site]
00076
trust_config.signing_config.get_oidc_url
[function]
[call site]
00077
sigstore.oidc.Issuer.__init__
[function]
[call site]
00078
requests.Session
[function]
[call site]
00079
urllib.parse.urljoin
[function]
[call site]
00080
resp.raise_for_status
[function]
[call site]
00081
resp.json
[function]
[call site]
00082
pydantic.BaseModel.model_validate
[function]
[call site]
00083
sigstore.sign.SigningContext.from_trust_config
[function]
[call site]
00084
sigstore.sign.SigningContext.__init__
[function]
[call site]
00085
signing_config.get_fulcio
[function]
[call site]
00086
signing_config.get_tlogs
[function]
[call site]
00087
signing_config.get_tsas
[function]
[call site]
00088
model_signing.signing.Config._hashing_config.hash
[function]
[call site]
00089
model_signing._signing.signing.Payload.__init__
[function]
[call site]
00090
model_signing._hashing.memory.SHA256.__init__
[function]
[call site]
00091
hashlib.sha256
[function]
[call site]
00092
manifest.resource_descriptors
[function]
[call site]
00093
model_signing._hashing.memory.SHA256.update
[function]
[call site]
00094
resources.append
[function]
[call site]
00095
model_signing._hashing.memory.SHA256.compute
[function]
[call site]
00096
statement.ResourceDescriptor
[function]
[call site]
00097
statement.Statement
[function]
[call site]
00098
model_signing._signing.sign_pkcs11.Signer.sign
[function]
[call site]
00099
google.protobuf.json_format.MessageToJson
[function]
[call site]
00100
ec_key.get_ec_key_hash
[function]
[call site]
00101
model_signing._signing.sign_sigstore_pb.pae
[function]
[call site]
00102
<builtin>.len
[function]
[call site]
00103
<builtin>.len
[function]
[call site]
00104
hash.update
[function]
[call site]
00105
hash.finalize
[function]
[call site]
00106
PyKCS11.Mechanism
[function]
[call site]
00107
asn1crypto.algos.DSASignature.from_p1363
[function]
[call site]
00108
base64.b64encode
[function]
[call site]
00109
sigstore_models.intoto.Signature
[function]
[call site]
00110
sigstore_models.intoto.Envelope
[function]
[call site]
00111
base64.b64encode
[function]
[call site]
00112
model_signing._signing.sign_sigstore_pb.Signature.__init__
[function]
[call site]
00113
sigstore_models.bundle.v1.Bundle
[function]
[call site]
00114
model_signing._signing.sign_pkcs11.Signer._get_verification_material
[function]
[call site]
00115
public_key.public_bytes
[function]
[call site]
00116
hashlib.sha256
[function]
[call site]
00117
sigstore_models.bundle.v1.VerificationMaterial
[function]
[call site]
00118
sigstore_models.common.v1.PublicKeyIdentifier
[function]
[call site]
00119
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material
[function]
[call site]
00120
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material._to_protobuf_certificate
[function]
[call site]
00121
sigstore_models.common.v1.X509Certificate
[function]
[call site]
00122
certificate.public_bytes
[function]
[call site]
00123
chain.extend
[function]
[call site]
00124
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material._to_protobuf_certificate
[function]
[call site]
00125
sigstore_models.bundle.v1.VerificationMaterial
[function]
[call site]
00126
sigstore_models.common.v1.X509CertificateChain
[function]
[call site]
00127
model_signing._signing.sign_sigstore.Signer.sign
[function]
[call site]
00128
sigstore.dsse.Statement.__init__
[function]
[call site]
00129
<builtin>.isinstance
[function]
[call site]
00130
pydantic.BaseModel.model_validate_json
[function]
[call site]
00131
pydantic.BaseModel.model_dump_json
[function]
[call site]
00132
google.protobuf.json_format.MessageToJson
[function]
[call site]
00133
model_signing._signing.sign_sigstore.Signer._get_identity_token
[function]
[call site]
00134
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00135
jwt.decode
[function]
[call site]
00136
sigstore.oidc.IdentityToken.in_validity_period
[function]
[call site]
00137
datetime.datetime.now
[function]
[call site]
00138
_KNOWN_OIDC_ISSUERS.get
[function]
[call site]
00139
<builtin>.str
[function]
[call site]
00140
<builtin>.str
[function]
[call site]
00141
<builtin>.isinstance
[function]
[call site]
00142
federated_claims.get
[function]
[call site]
00143
<builtin>.isinstance
[function]
[call site]
00144
sigstore.oidc.detect_credential
[function]
[call site]
00145
id.detect_credential
[function]
[call site]
00146
typing.cast
[function]
[call site]
00147
sigstore.oidc.IdentityError.raise_from_id
[function]
[call site]
00148
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00149
sigstore.oidc.Issuer.identity_token
[function]
[call site]
00150
sigstore._internal.oidc.oauth._OAuthFlow.__init__
[function]
[call site]
00151
sigstore._internal.oidc.oauth._OAuthRedirectServer.__init__
[function]
[call site]
00152
<builtin>.super
[function]
[call site]
00153
sigstore._internal.oidc.oauth._OAuthSession.__init__
[function]
[call site]
00154
uuid.uuid4
[function]
[call site]
00155
<builtin>.str
[function]
[call site]
00156
uuid.uuid4
[function]
[call site]
00157
<builtin>.str
[function]
[call site]
00158
typing.NewType
[function]
[call site]
00159
os.urandom
[function]
[call site]
00160
base64.urlsafe_b64encode
[function]
[call site]
00161
threading.Thread
[function]
[call site]
00162
webbrowser.open
[function]
[call site]
00163
<builtin>.print
[function]
[call site]
00164
server.enable_oob
[function]
[call site]
00165
<builtin>.print
[function]
[call site]
00166
server.is_oob
[function]
[call site]
00167
time.sleep
[function]
[call site]
00168
server.auth_response.get
[function]
[call site]
00169
<builtin>.input
[function]
[call site]
00170
logging.debug
[function]
[call site]
00171
resp.raise_for_status
[function]
[call site]
00172
resp.json
[function]
[call site]
00173
token_json.get
[function]
[call site]
00174
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00175
signer.sign_dsse
[function]
[call site]
00176
model_signing._signing.sign_sigstore.Signature.__init__
[function]
[call site]
00177
pathlib.Path
[function]
[call site]
00178
model_signing._signing.sign_sigstore_pb.Signature.write
[function]
[call site]
00179
path.write_text
[function]
[call site]
00180
model_signing._signing.sign_sigstore.Signature.write
[function]
[call site]
00181
path.write_text
[function]
[call site]
00182
pathlib.Path.rglob
[function]
[call site]
00183
p.is_file
[function]
[call site]
00184
<builtin>.len
[function]
[call site]
00185
fdp.ConsumeIntInRange
[function]
[call site]
00186
target.read_bytes
[function]
[call site]
00187
fdp.ConsumeIntInRange
[function]
[call site]
00188
fdp.ConsumeBytes
[function]
[call site]
00189
target.relative_to
[function]
[call site]
00190
utils.safe_write
[function]
[call site]
00191
model_signing.verifying.Config
[function]
[call site]
00192
vcfg.set_hashing_config
[function]
[call site]
00193
vcfg.use_elliptic_key_verifier
[function]
[call site]
00194
verifier.verify
[function]
[call site]
00195