The following nodes represent call sites where fuzz blockers occur.
| Amount of callsites blocked | Calltree index | Parent function | Callsite | Largest blocked function |
|---|---|---|---|---|
| 41 | 130 | sigstore.oidc.IdentityToken.__init__ | call site: 00130 | sigstore.oidc.Issuer.identity_token |
| 26 | 61 | sigstore._internal.tuf.TrustUpdater.get_signing_config_path | call site: 00061 | sigstore.models.ClientTrustConfig.from_tuf |
| 23 | 36 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00036 | sigstore._internal.tuf.TrustUpdater.get_trusted_root_path |
| 18 | 103 | model_signing._signing.sign_sigstore_pb.pae | call site: 00103 | model_signing._signing.sign_pkcs11.CertSigner._get_verification_material |
| 6 | 1 | ...model-transparency.tests.fuzzing.fuzz_sign_with_valid_key_verify_with_invalid_key.TestOneInput | call site: 00001 | fdp.ConsumeIntInRange |
| 6 | 24 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00024 | sigstore._internal.tuf._get_dirs |
| 5 | 18 | ...model-transparency.tests.fuzzing.fuzz_sign_with_valid_key_verify_with_invalid_key.TestOneInput | call site: 00018 | sigstore.models.ClientTrustConfig.from_tuf |
| 4 | 125 | sigstore.dsse.Statement.__init__ | call site: 00125 | sigstore.oidc.IdentityToken.__init__ |
| 3 | 32 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00032 | urllib.parse.quote |
| 3 | 98 | model_signing.signing.Config.sign | call site: 00098 | model_signing._signing.sign_sigstore_pb.pae |
| 3 | 175 | model_signing.signing.Config.sign | call site: 00175 | path.write_text |
| 1 | 122 | model_signing.signing.Config.sign | call site: 00122 | sigstore.dsse.Statement.__init__ |
...model-transparency.tests.fuzzing.fuzz_sign_with_valid_key_verify_with_invalid_key.TestOneInput
[function]
[call site]
00000
atheris.FuzzedDataProvider
[function]
[call site]
00001
fdp.ConsumeIntInRange
[function]
[call site]
00002
fdp.ConsumeBytes
[function]
[call site]
00003
tempfile.TemporaryDirectory
[function]
[call site]
00004
tempfile.TemporaryDirectory
[function]
[call site]
00005
pathlib.Path
[function]
[call site]
00006
utils.create_fuzz_files
[function]
[call site]
00007
utils.any_files
[function]
[call site]
00008
<builtin>.str
[function]
[call site]
00009
os.path.join
[function]
[call site]
00010
utils._build_hashing_config_from_fdp
[function]
[call site]
00011
model_signing.signing.Config.__init__
[function]
[call site]
00012
hashing.Config
[function]
[call site]
00013
model_signing.signing.Config.set_hashing_config
[function]
[call site]
00014
model_signing.signing.Config.use_elliptic_key_signer
[function]
[call site]
00015
pathlib.Path
[function]
[call site]
00016
ec_key.Signer
[function]
[call site]
00017
model_signing.signing.Config.sign
[function]
[call site]
00018
model_signing.signing.Config.use_sigstore_signer
[function]
[call site]
00019
model_signing._signing.sign_sigstore.Signer.__init__
[function]
[call site]
00020
sigstore.models.ClientTrustConfig.staging
[function]
[call site]
00021
sigstore.models.ClientTrustConfig.from_tuf
[function]
[call site]
00022
sigstore._internal.tuf.TrustUpdater.__init__
[function]
[call site]
00023
url.rstrip
[function]
[call site]
00024
sigstore._internal.tuf._get_dirs
[function]
[call site]
00025
urllib.parse.quote
[function]
[call site]
00026
platformdirs.user_data_dir
[function]
[call site]
00027
pathlib.Path
[function]
[call site]
00028
platformdirs.user_cache_dir
[function]
[call site]
00029
pathlib.Path
[function]
[call site]
00030
artifact_path.exists
[function]
[call site]
00031
sigstore._utils.read_embedded
[function]
[call site]
00032
urllib.parse.quote
[function]
[call site]
00033
importlib.resources.files
[function]
[call site]
00034
importlib_resources.files
[function]
[call site]
00035
artifact_path.write_bytes
[function]
[call site]
00036
_logger.debug
[function]
[call site]
00037
_logger.debug
[function]
[call site]
00038
_logger.warning
[function]
[call site]
00039
sigstore._utils.read_embedded
[function]
[call site]
00040
bootstrap_root.read_bytes
[function]
[call site]
00041
tuf.ngclient.Updater
[function]
[call site]
00042
<builtin>.str
[function]
[call site]
00043
urllib.parse.urljoin
[function]
[call site]
00044
<builtin>.str
[function]
[call site]
00045
tuf.ngclient.UpdaterConfig
[function]
[call site]
00046
tuf.ngclient.Updater.refresh
[function]
[call site]
00047
sigstore._internal.tuf.TrustUpdater.get_trusted_root_path
[function]
[call site]
00048
_logger.debug
[function]
[call site]
00049
<builtin>.str
[function]
[call site]
00050
tuf.ngclient.Updater.get_targetinfo
[function]
[call site]
00051
tuf.ngclient.Updater.find_cached_target
[function]
[call site]
00052
tuf.ngclient.Updater.download_target
[function]
[call site]
00053
_logger.debug
[function]
[call site]
00054
pathlib.Path
[function]
[call site]
00055
pathlib.Path.read_bytes
[function]
[call site]
00056
sigstore_models.trustroot.v1.TrustedRoot.from_json
[function]
[call site]
00057
sigstore._internal.tuf.TrustUpdater.get_signing_config_path
[function]
[call site]
00058
_logger.debug
[function]
[call site]
00059
<builtin>.str
[function]
[call site]
00060
tuf.ngclient.Updater.get_targetinfo
[function]
[call site]
00061
tuf.ngclient.Updater.find_cached_target
[function]
[call site]
00062
tuf.ngclient.Updater.download_target
[function]
[call site]
00063
_logger.debug
[function]
[call site]
00064
pathlib.Path
[function]
[call site]
00065
pathlib.Path.read_bytes
[function]
[call site]
00066
sigstore_models.trustroot.v1.SigningConfig.from_json
[function]
[call site]
00067
sigstore.models.ClientTrustConfig.__init__
[function]
[call site]
00068
sigstore_models.trustroot.v1.ClientTrustConfig
[function]
[call site]
00069
sigstore.models.ClientTrustConfig.from_json
[function]
[call site]
00070
sigstore_models.trustroot.v1.ClientTrustConfig.from_json
[function]
[call site]
00071
sigstore.models.ClientTrustConfig.__init__
[function]
[call site]
00072
trust_config.read_text
[function]
[call site]
00073
sigstore.models.ClientTrustConfig.production
[function]
[call site]
00074
sigstore.models.ClientTrustConfig.from_tuf
[function]
[call site]
00075
trust_config.signing_config.get_oidc_url
[function]
[call site]
00076
sigstore.oidc.Issuer.__init__
[function]
[call site]
00077
requests.Session
[function]
[call site]
00078
urllib.parse.urljoin
[function]
[call site]
00079
resp.raise_for_status
[function]
[call site]
00080
resp.json
[function]
[call site]
00081
pydantic.BaseModel.model_validate
[function]
[call site]
00082
sigstore.sign.SigningContext.from_trust_config
[function]
[call site]
00083
sigstore.sign.SigningContext.__init__
[function]
[call site]
00084
signing_config.get_fulcio
[function]
[call site]
00085
signing_config.get_tlogs
[function]
[call site]
00086
signing_config.get_tsas
[function]
[call site]
00087
model_signing.signing.Config._hashing_config.hash
[function]
[call site]
00088
model_signing._signing.signing.Payload.__init__
[function]
[call site]
00089
model_signing._hashing.memory.SHA256.__init__
[function]
[call site]
00090
hashlib.sha256
[function]
[call site]
00091
manifest.resource_descriptors
[function]
[call site]
00092
model_signing._hashing.memory.SHA256.update
[function]
[call site]
00093
resources.append
[function]
[call site]
00094
model_signing._hashing.memory.SHA256.compute
[function]
[call site]
00095
statement.ResourceDescriptor
[function]
[call site]
00096
statement.Statement
[function]
[call site]
00097
model_signing._signing.sign_pkcs11.Signer.sign
[function]
[call site]
00098
google.protobuf.json_format.MessageToJson
[function]
[call site]
00099
ec_key.get_ec_key_hash
[function]
[call site]
00100
model_signing._signing.sign_sigstore_pb.pae
[function]
[call site]
00101
<builtin>.len
[function]
[call site]
00102
<builtin>.len
[function]
[call site]
00103
hash.update
[function]
[call site]
00104
hash.finalize
[function]
[call site]
00105
PyKCS11.Mechanism
[function]
[call site]
00106
asn1crypto.algos.DSASignature.from_p1363
[function]
[call site]
00107
base64.b64encode
[function]
[call site]
00108
sigstore_models.intoto.Signature
[function]
[call site]
00109
sigstore_models.intoto.Envelope
[function]
[call site]
00110
base64.b64encode
[function]
[call site]
00111
model_signing._signing.sign_sigstore_pb.Signature.__init__
[function]
[call site]
00112
sigstore_models.bundle.v1.Bundle
[function]
[call site]
00113
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material
[function]
[call site]
00114
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material._to_protobuf_certificate
[function]
[call site]
00115
sigstore_models.common.v1.X509Certificate
[function]
[call site]
00116
certificate.public_bytes
[function]
[call site]
00117
chain.extend
[function]
[call site]
00118
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material._to_protobuf_certificate
[function]
[call site]
00119
sigstore_models.bundle.v1.VerificationMaterial
[function]
[call site]
00120
sigstore_models.common.v1.X509CertificateChain
[function]
[call site]
00121
model_signing._signing.sign_sigstore.Signer.sign
[function]
[call site]
00122
sigstore.dsse.Statement.__init__
[function]
[call site]
00123
<builtin>.isinstance
[function]
[call site]
00124
pydantic.BaseModel.model_validate_json
[function]
[call site]
00125
pydantic.BaseModel.model_dump_json
[function]
[call site]
00126
google.protobuf.json_format.MessageToJson
[function]
[call site]
00127
model_signing._signing.sign_sigstore.Signer._get_identity_token
[function]
[call site]
00128
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00129
jwt.decode
[function]
[call site]
00130
sigstore.oidc.IdentityToken.in_validity_period
[function]
[call site]
00131
datetime.datetime.now
[function]
[call site]
00132
_KNOWN_OIDC_ISSUERS.get
[function]
[call site]
00133
<builtin>.str
[function]
[call site]
00134
<builtin>.str
[function]
[call site]
00135
<builtin>.isinstance
[function]
[call site]
00136
federated_claims.get
[function]
[call site]
00137
<builtin>.isinstance
[function]
[call site]
00138
sigstore.oidc.detect_credential
[function]
[call site]
00139
id.detect_credential
[function]
[call site]
00140
typing.cast
[function]
[call site]
00141
sigstore.oidc.IdentityError.raise_from_id
[function]
[call site]
00142
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00143
sigstore.oidc.Issuer.identity_token
[function]
[call site]
00144
sigstore._internal.oidc.oauth._OAuthFlow.__init__
[function]
[call site]
00145
sigstore._internal.oidc.oauth._OAuthRedirectServer.__init__
[function]
[call site]
00146
<builtin>.super
[function]
[call site]
00147
sigstore._internal.oidc.oauth._OAuthSession.__init__
[function]
[call site]
00148
uuid.uuid4
[function]
[call site]
00149
<builtin>.str
[function]
[call site]
00150
uuid.uuid4
[function]
[call site]
00151
<builtin>.str
[function]
[call site]
00152
typing.NewType
[function]
[call site]
00153
os.urandom
[function]
[call site]
00154
base64.urlsafe_b64encode
[function]
[call site]
00155
threading.Thread
[function]
[call site]
00156
webbrowser.open
[function]
[call site]
00157
<builtin>.print
[function]
[call site]
00158
server.enable_oob
[function]
[call site]
00159
<builtin>.print
[function]
[call site]
00160
server.is_oob
[function]
[call site]
00161
time.sleep
[function]
[call site]
00162
server.auth_response.get
[function]
[call site]
00163
<builtin>.input
[function]
[call site]
00164
logging.debug
[function]
[call site]
00165
resp.raise_for_status
[function]
[call site]
00166
resp.json
[function]
[call site]
00167
token_json.get
[function]
[call site]
00168
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00169
signer.sign_dsse
[function]
[call site]
00170
model_signing._signing.sign_sigstore.Signature.__init__
[function]
[call site]
00171
pathlib.Path
[function]
[call site]
00172
model_signing._signing.sign_sigstore_pb.Signature.write
[function]
[call site]
00173
path.write_text
[function]
[call site]
00174
model_signing._signing.sign_sigstore.Signature.write
[function]
[call site]
00175
path.write_text
[function]
[call site]
00176
os.path.join
[function]
[call site]
00177
<builtin>.open
[function]
[call site]
00178
f.write
[function]
[call site]
00179
model_signing.verifying.Config
[function]
[call site]
00180
vcfg.set_hashing_config
[function]
[call site]
00181
vcfg.use_elliptic_key_verifier
[function]
[call site]
00182
verifier.verify
[function]
[call site]
00183