The following nodes represent call sites where fuzz blockers occur.
| Amount of callsites blocked | Calltree index | Parent function | Callsite | Largest blocked function |
|---|---|---|---|---|
| 41 | 135 | sigstore.oidc.IdentityToken.__init__ | call site: 00135 | sigstore.oidc.Issuer.identity_token |
| 26 | 61 | sigstore._internal.tuf.TrustUpdater.get_signing_config_path | call site: 00061 | sigstore.models.ClientTrustConfig.from_tuf |
| 23 | 36 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00036 | sigstore._internal.tuf.TrustUpdater.get_trusted_root_path |
| 23 | 103 | model_signing._signing.sign_sigstore_pb.pae | call site: 00103 | model_signing._signing.sign_pkcs11.CertSigner._get_verification_material |
| 6 | 1 | ...model-transparency.tests.fuzzing.fuzz_sign_with_valid_key_verify_with_invalid_key.TestOneInput | call site: 00001 | fdp.ConsumeIntInRange |
| 6 | 24 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00024 | sigstore._internal.tuf._get_dirs |
| 5 | 18 | ...model-transparency.tests.fuzzing.fuzz_sign_with_valid_key_verify_with_invalid_key.TestOneInput | call site: 00018 | sigstore.models.ClientTrustConfig.from_tuf |
| 4 | 130 | sigstore.dsse.Statement.__init__ | call site: 00130 | sigstore.oidc.IdentityToken.__init__ |
| 3 | 32 | sigstore._internal.tuf.TrustUpdater.__init__ | call site: 00032 | urllib.parse.quote |
| 3 | 98 | model_signing.signing.Config.sign | call site: 00098 | model_signing._signing.sign_sigstore_pb.pae |
| 2 | 181 | model_signing._signing.sign_sigstore_pb.Signature.write | call site: 00181 | os.path.join |
| 1 | 127 | model_signing.signing.Config.sign | call site: 00127 | sigstore.dsse.Statement.__init__ |
...model-transparency.tests.fuzzing.fuzz_sign_with_valid_key_verify_with_invalid_key.TestOneInput
[function]
[call site]
00000
atheris.FuzzedDataProvider
[function]
[call site]
00001
fdp.ConsumeIntInRange
[function]
[call site]
00002
fdp.ConsumeBytes
[function]
[call site]
00003
tempfile.TemporaryDirectory
[function]
[call site]
00004
tempfile.TemporaryDirectory
[function]
[call site]
00005
pathlib.Path
[function]
[call site]
00006
utils.create_fuzz_files
[function]
[call site]
00007
utils.any_files
[function]
[call site]
00008
<builtin>.str
[function]
[call site]
00009
os.path.join
[function]
[call site]
00010
utils._build_hashing_config_from_fdp
[function]
[call site]
00011
model_signing.signing.Config.__init__
[function]
[call site]
00012
hashing.Config
[function]
[call site]
00013
model_signing.signing.Config.set_hashing_config
[function]
[call site]
00014
model_signing.signing.Config.use_elliptic_key_signer
[function]
[call site]
00015
pathlib.Path
[function]
[call site]
00016
ec_key.Signer
[function]
[call site]
00017
model_signing.signing.Config.sign
[function]
[call site]
00018
model_signing.signing.Config.use_sigstore_signer
[function]
[call site]
00019
model_signing._signing.sign_sigstore.Signer.__init__
[function]
[call site]
00020
sigstore.models.ClientTrustConfig.staging
[function]
[call site]
00021
sigstore.models.ClientTrustConfig.from_tuf
[function]
[call site]
00022
sigstore._internal.tuf.TrustUpdater.__init__
[function]
[call site]
00023
url.rstrip
[function]
[call site]
00024
sigstore._internal.tuf._get_dirs
[function]
[call site]
00025
urllib.parse.quote
[function]
[call site]
00026
platformdirs.user_data_dir
[function]
[call site]
00027
pathlib.Path
[function]
[call site]
00028
platformdirs.user_cache_dir
[function]
[call site]
00029
pathlib.Path
[function]
[call site]
00030
artifact_path.exists
[function]
[call site]
00031
sigstore._utils.read_embedded
[function]
[call site]
00032
urllib.parse.quote
[function]
[call site]
00033
importlib.resources.files
[function]
[call site]
00034
importlib_resources.files
[function]
[call site]
00035
artifact_path.write_bytes
[function]
[call site]
00036
_logger.debug
[function]
[call site]
00037
_logger.debug
[function]
[call site]
00038
_logger.warning
[function]
[call site]
00039
sigstore._utils.read_embedded
[function]
[call site]
00040
bootstrap_root.read_bytes
[function]
[call site]
00041
tuf.ngclient.Updater
[function]
[call site]
00042
<builtin>.str
[function]
[call site]
00043
urllib.parse.urljoin
[function]
[call site]
00044
<builtin>.str
[function]
[call site]
00045
tuf.ngclient.UpdaterConfig
[function]
[call site]
00046
tuf.ngclient.Updater.refresh
[function]
[call site]
00047
sigstore._internal.tuf.TrustUpdater.get_trusted_root_path
[function]
[call site]
00048
_logger.debug
[function]
[call site]
00049
<builtin>.str
[function]
[call site]
00050
tuf.ngclient.Updater.get_targetinfo
[function]
[call site]
00051
tuf.ngclient.Updater.find_cached_target
[function]
[call site]
00052
tuf.ngclient.Updater.download_target
[function]
[call site]
00053
_logger.debug
[function]
[call site]
00054
pathlib.Path
[function]
[call site]
00055
pathlib.Path.read_bytes
[function]
[call site]
00056
sigstore_models.trustroot.v1.TrustedRoot.from_json
[function]
[call site]
00057
sigstore._internal.tuf.TrustUpdater.get_signing_config_path
[function]
[call site]
00058
_logger.debug
[function]
[call site]
00059
<builtin>.str
[function]
[call site]
00060
tuf.ngclient.Updater.get_targetinfo
[function]
[call site]
00061
tuf.ngclient.Updater.find_cached_target
[function]
[call site]
00062
tuf.ngclient.Updater.download_target
[function]
[call site]
00063
_logger.debug
[function]
[call site]
00064
pathlib.Path
[function]
[call site]
00065
pathlib.Path.read_bytes
[function]
[call site]
00066
sigstore_models.trustroot.v1.SigningConfig.from_json
[function]
[call site]
00067
sigstore.models.ClientTrustConfig.__init__
[function]
[call site]
00068
sigstore_models.trustroot.v1.ClientTrustConfig
[function]
[call site]
00069
sigstore.models.ClientTrustConfig.from_json
[function]
[call site]
00070
sigstore_models.trustroot.v1.ClientTrustConfig.from_json
[function]
[call site]
00071
sigstore.models.ClientTrustConfig.__init__
[function]
[call site]
00072
trust_config.read_text
[function]
[call site]
00073
sigstore.models.ClientTrustConfig.production
[function]
[call site]
00074
sigstore.models.ClientTrustConfig.from_tuf
[function]
[call site]
00075
trust_config.signing_config.get_oidc_url
[function]
[call site]
00076
sigstore.oidc.Issuer.__init__
[function]
[call site]
00077
requests.Session
[function]
[call site]
00078
urllib.parse.urljoin
[function]
[call site]
00079
resp.raise_for_status
[function]
[call site]
00080
resp.json
[function]
[call site]
00081
pydantic.BaseModel.model_validate
[function]
[call site]
00082
sigstore.sign.SigningContext.from_trust_config
[function]
[call site]
00083
sigstore.sign.SigningContext.__init__
[function]
[call site]
00084
signing_config.get_fulcio
[function]
[call site]
00085
signing_config.get_tlogs
[function]
[call site]
00086
signing_config.get_tsas
[function]
[call site]
00087
model_signing.signing.Config._hashing_config.hash
[function]
[call site]
00088
model_signing._signing.signing.Payload.__init__
[function]
[call site]
00089
model_signing._hashing.memory.SHA256.__init__
[function]
[call site]
00090
hashlib.sha256
[function]
[call site]
00091
manifest.resource_descriptors
[function]
[call site]
00092
model_signing._hashing.memory.SHA256.update
[function]
[call site]
00093
resources.append
[function]
[call site]
00094
model_signing._hashing.memory.SHA256.compute
[function]
[call site]
00095
statement.ResourceDescriptor
[function]
[call site]
00096
statement.Statement
[function]
[call site]
00097
model_signing._signing.sign_pkcs11.Signer.sign
[function]
[call site]
00098
google.protobuf.json_format.MessageToJson
[function]
[call site]
00099
ec_key.get_ec_key_hash
[function]
[call site]
00100
model_signing._signing.sign_sigstore_pb.pae
[function]
[call site]
00101
<builtin>.len
[function]
[call site]
00102
<builtin>.len
[function]
[call site]
00103
hash.update
[function]
[call site]
00104
hash.finalize
[function]
[call site]
00105
PyKCS11.Mechanism
[function]
[call site]
00106
asn1crypto.algos.DSASignature.from_p1363
[function]
[call site]
00107
base64.b64encode
[function]
[call site]
00108
sigstore_models.intoto.Signature
[function]
[call site]
00109
sigstore_models.intoto.Envelope
[function]
[call site]
00110
base64.b64encode
[function]
[call site]
00111
model_signing._signing.sign_sigstore_pb.Signature.__init__
[function]
[call site]
00112
sigstore_models.bundle.v1.Bundle
[function]
[call site]
00113
model_signing._signing.sign_pkcs11.Signer._get_verification_material
[function]
[call site]
00114
public_key.public_bytes
[function]
[call site]
00115
hashlib.sha256
[function]
[call site]
00116
sigstore_models.bundle.v1.VerificationMaterial
[function]
[call site]
00117
sigstore_models.common.v1.PublicKeyIdentifier
[function]
[call site]
00118
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material
[function]
[call site]
00119
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material._to_protobuf_certificate
[function]
[call site]
00120
sigstore_models.common.v1.X509Certificate
[function]
[call site]
00121
certificate.public_bytes
[function]
[call site]
00122
chain.extend
[function]
[call site]
00123
model_signing._signing.sign_pkcs11.CertSigner._get_verification_material._to_protobuf_certificate
[function]
[call site]
00124
sigstore_models.bundle.v1.VerificationMaterial
[function]
[call site]
00125
sigstore_models.common.v1.X509CertificateChain
[function]
[call site]
00126
model_signing._signing.sign_sigstore.Signer.sign
[function]
[call site]
00127
sigstore.dsse.Statement.__init__
[function]
[call site]
00128
<builtin>.isinstance
[function]
[call site]
00129
pydantic.BaseModel.model_validate_json
[function]
[call site]
00130
pydantic.BaseModel.model_dump_json
[function]
[call site]
00131
google.protobuf.json_format.MessageToJson
[function]
[call site]
00132
model_signing._signing.sign_sigstore.Signer._get_identity_token
[function]
[call site]
00133
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00134
jwt.decode
[function]
[call site]
00135
sigstore.oidc.IdentityToken.in_validity_period
[function]
[call site]
00136
datetime.datetime.now
[function]
[call site]
00137
_KNOWN_OIDC_ISSUERS.get
[function]
[call site]
00138
<builtin>.str
[function]
[call site]
00139
<builtin>.str
[function]
[call site]
00140
<builtin>.isinstance
[function]
[call site]
00141
federated_claims.get
[function]
[call site]
00142
<builtin>.isinstance
[function]
[call site]
00143
sigstore.oidc.detect_credential
[function]
[call site]
00144
id.detect_credential
[function]
[call site]
00145
typing.cast
[function]
[call site]
00146
sigstore.oidc.IdentityError.raise_from_id
[function]
[call site]
00147
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00148
sigstore.oidc.Issuer.identity_token
[function]
[call site]
00149
sigstore._internal.oidc.oauth._OAuthFlow.__init__
[function]
[call site]
00150
sigstore._internal.oidc.oauth._OAuthRedirectServer.__init__
[function]
[call site]
00151
<builtin>.super
[function]
[call site]
00152
sigstore._internal.oidc.oauth._OAuthSession.__init__
[function]
[call site]
00153
uuid.uuid4
[function]
[call site]
00154
<builtin>.str
[function]
[call site]
00155
uuid.uuid4
[function]
[call site]
00156
<builtin>.str
[function]
[call site]
00157
typing.NewType
[function]
[call site]
00158
os.urandom
[function]
[call site]
00159
base64.urlsafe_b64encode
[function]
[call site]
00160
threading.Thread
[function]
[call site]
00161
webbrowser.open
[function]
[call site]
00162
<builtin>.print
[function]
[call site]
00163
server.enable_oob
[function]
[call site]
00164
<builtin>.print
[function]
[call site]
00165
server.is_oob
[function]
[call site]
00166
time.sleep
[function]
[call site]
00167
server.auth_response.get
[function]
[call site]
00168
<builtin>.input
[function]
[call site]
00169
logging.debug
[function]
[call site]
00170
resp.raise_for_status
[function]
[call site]
00171
resp.json
[function]
[call site]
00172
token_json.get
[function]
[call site]
00173
sigstore.oidc.IdentityToken.__init__
[function]
[call site]
00174
signer.sign_dsse
[function]
[call site]
00175
model_signing._signing.sign_sigstore.Signature.__init__
[function]
[call site]
00176
pathlib.Path
[function]
[call site]
00177
model_signing._signing.sign_sigstore.Signature.write
[function]
[call site]
00178
path.write_text
[function]
[call site]
00179
model_signing._signing.sign_sigstore_pb.Signature.write
[function]
[call site]
00180
path.write_text
[function]
[call site]
00181
os.path.join
[function]
[call site]
00182
<builtin>.open
[function]
[call site]
00183
f.write
[function]
[call site]
00184
model_signing.verifying.Config
[function]
[call site]
00185
vcfg.set_hashing_config
[function]
[call site]
00186
vcfg.use_elliptic_key_verifier
[function]
[call site]
00187
verifier.verify
[function]
[call site]
00188