mirror of
https://github.com/anchore/syft.git
synced 2026-08-19 08:38:25 +02:00
fix: PE case-insensitive extensions (Win32/ISO 9660 compatibility) (#4996)
* fix: PE case-insensitive extensions (Win32/ISO 9660 compatibility) Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com> * add tests Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com> * expand cases to bpl files and surrounding catalogers Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com> --------- Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com> Co-authored-by: Alex Goodman <wagoodman@users.noreply.github.com>
This commit is contained in:
parent
76ede661db
commit
987ae7f26a
@ -1055,6 +1055,9 @@ catalogers:
|
||||
detector: # AUTO-GENERATED
|
||||
method: glob # AUTO-GENERATED
|
||||
criteria: # AUTO-GENERATED
|
||||
- '**/*.DLL'
|
||||
- '**/*.EXE'
|
||||
- '**/*.BPL'
|
||||
- '**/*.dll'
|
||||
- '**/*.exe'
|
||||
- '**/*.bpl'
|
||||
|
||||
@ -16,7 +16,7 @@ import (
|
||||
// BPL (Borland Package Library) files are PE-format binaries used by Delphi and C++Builder.
|
||||
func NewPEPackageCataloger() pkg.Cataloger {
|
||||
return generic.NewCataloger("pe-binary-package-cataloger").
|
||||
WithParserByGlobs(parsePE, "**/*.dll", "**/*.exe", "**/*.bpl")
|
||||
WithParserByGlobs(parsePE, "**/*.DLL", "**/*.EXE", "**/*.BPL", "**/*.dll", "**/*.exe", "**/*.bpl")
|
||||
}
|
||||
|
||||
func parsePE(_ context.Context, _ file.Resolver, _ *generic.Environment, reader file.LocationReadCloser) ([]pkg.Package, []artifact.Relationship, error) {
|
||||
|
||||
@ -70,12 +70,16 @@ func Test_PEPackageCataloger_Globs(t *testing.T) {
|
||||
expected []string
|
||||
}{
|
||||
{
|
||||
name: "obtain PE binary files (dll, exe, bpl)",
|
||||
name: "obtain PE binary files (dll, exe, bpl), including uppercase extensions",
|
||||
fixture: "testdata/glob-paths",
|
||||
expected: []string{
|
||||
"src/library.dll",
|
||||
"src/program.exe",
|
||||
"src/archive.bpl",
|
||||
// uppercase extensions appear on Windows/ISO 9660 filesystems and must also match
|
||||
"src/winlibrary.DLL",
|
||||
"src/winprogram.EXE",
|
||||
"src/winarchive.BPL",
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
1
syft/pkg/cataloger/binary/testdata/glob-paths/src/winarchive.BPL
vendored
Normal file
1
syft/pkg/cataloger/binary/testdata/glob-paths/src/winarchive.BPL
vendored
Normal file
@ -0,0 +1 @@
|
||||
bogus PE contents
|
||||
1
syft/pkg/cataloger/binary/testdata/glob-paths/src/winlibrary.DLL
vendored
Normal file
1
syft/pkg/cataloger/binary/testdata/glob-paths/src/winlibrary.DLL
vendored
Normal file
@ -0,0 +1 @@
|
||||
bogus PE contents
|
||||
1
syft/pkg/cataloger/binary/testdata/glob-paths/src/winprogram.EXE
vendored
Normal file
1
syft/pkg/cataloger/binary/testdata/glob-paths/src/winprogram.EXE
vendored
Normal file
@ -0,0 +1 @@
|
||||
bogus PE contents
|
||||
@ -39,6 +39,10 @@ catalogers:
|
||||
- '**/*.deps.json'
|
||||
- '**/*.dll'
|
||||
- '**/*.exe'
|
||||
- '**/*.bpl'
|
||||
- '**/*.DLL'
|
||||
- '**/*.EXE'
|
||||
- '**/*.BPL'
|
||||
metadata_types: # AUTO-GENERATED
|
||||
- pkg.DotnetDepsEntry
|
||||
- pkg.DotnetPortableExecutableEntry
|
||||
@ -173,6 +177,10 @@ catalogers:
|
||||
criteria:
|
||||
- '**/*.dll'
|
||||
- '**/*.exe'
|
||||
- '**/*.bpl'
|
||||
- '**/*.DLL'
|
||||
- '**/*.EXE'
|
||||
- '**/*.BPL'
|
||||
metadata_types: # AUTO-GENERATED
|
||||
- pkg.DotnetPortableExecutableEntry
|
||||
package_types: # AUTO-GENERATED
|
||||
|
||||
@ -36,6 +36,10 @@ func TestCataloger_Globs(t *testing.T) {
|
||||
"src/something.bpl",
|
||||
"src/something.dll",
|
||||
"src/something.exe",
|
||||
// uppercase extensions appear on Windows/ISO 9660 filesystems and must also match
|
||||
"src/winsomething.DLL",
|
||||
"src/winsomething.EXE",
|
||||
"src/winsomething.BPL",
|
||||
},
|
||||
},
|
||||
{
|
||||
@ -47,6 +51,10 @@ func TestCataloger_Globs(t *testing.T) {
|
||||
"src/something.deps.json",
|
||||
"src/something.dll",
|
||||
"src/something.exe",
|
||||
// uppercase extensions appear on Windows/ISO 9660 filesystems and must also match
|
||||
"src/winsomething.DLL",
|
||||
"src/winsomething.EXE",
|
||||
"src/winsomething.BPL",
|
||||
},
|
||||
// the binary cataloger probes executables by MIME type to find embedded bundles,
|
||||
// but the glob fixtures aren't real binaries so those queries go unfulfilled
|
||||
|
||||
@ -27,6 +27,10 @@ const (
|
||||
dllGlob = "**/*.dll"
|
||||
exeGlob = "**/*.exe"
|
||||
bplGlob = "**/*.bpl"
|
||||
// uppercase variants match PE files on case-preserving Windows/ISO 9660 filesystems (doublestar globs are case-sensitive)
|
||||
dllGlobUpper = "**/*.DLL"
|
||||
exeGlobUpper = "**/*.EXE"
|
||||
bplGlobUpper = "**/*.BPL"
|
||||
)
|
||||
|
||||
var elfMagic = []byte{0x7f, 'E', 'L', 'F'}
|
||||
@ -483,7 +487,7 @@ func readDepsJSON(resolver file.Resolver, loc file.Location) (*depsJSON, error)
|
||||
|
||||
// findPEFiles locates and parses all PE files (dll/exe).
|
||||
func findPEFiles(resolver file.Resolver) ([]logicalPE, error, error) {
|
||||
peLocs, err := resolver.FilesByGlob(dllGlob, exeGlob, bplGlob)
|
||||
peLocs, err := resolver.FilesByGlob(dllGlob, exeGlob, bplGlob, dllGlobUpper, exeGlobUpper, bplGlobUpper)
|
||||
if err != nil {
|
||||
return nil, nil, fmt.Errorf("unable to find PE files: %w", err)
|
||||
}
|
||||
|
||||
1
syft/pkg/cataloger/dotnet/testdata/glob-paths/src/winsomething.BPL
vendored
Normal file
1
syft/pkg/cataloger/dotnet/testdata/glob-paths/src/winsomething.BPL
vendored
Normal file
@ -0,0 +1 @@
|
||||
bogus PE contents
|
||||
1
syft/pkg/cataloger/dotnet/testdata/glob-paths/src/winsomething.DLL
vendored
Normal file
1
syft/pkg/cataloger/dotnet/testdata/glob-paths/src/winsomething.DLL
vendored
Normal file
@ -0,0 +1 @@
|
||||
bogus PE contents
|
||||
1
syft/pkg/cataloger/dotnet/testdata/glob-paths/src/winsomething.EXE
vendored
Normal file
1
syft/pkg/cataloger/dotnet/testdata/glob-paths/src/winsomething.EXE
vendored
Normal file
@ -0,0 +1 @@
|
||||
bogus PE contents
|
||||
Loading…
x
Reference in New Issue
Block a user