Skip to content

fix: Honor --external-manifest option on export and inspect paths - #355

Merged
ssanthosh merged 1 commit into
mainfrom
ssaanthosh/vuln-37580
Oct 3, 2026
Merged

ssanthosh merged 1 commit into
mainfrom
ssaanthosh/vuln-37580

Conversation

@ssanthosh

Copy link
Copy Markdown
Contributor

Changes in this pull request

Vulnerability

--external-manifest is documented to override the asset's embedded/remote manifest, but it was honored only on the default read path. Adding --output DIR (and --certs, --tree, --ingredient, info) silently fell back to the embedded store, so exported reports could validate the very manifest the operator overrode.

Fix

Route the reader-based paths (--output report, --certs, --tree) through a shared read_asset helper that applies the external manifest when set. The ingredient and info paths build from the embedded manifest and cannot substitute an external one, so they now reject --external-manifest with a clear error instead of ignoring it. Behavior is unchanged when the flag is absent.

Backward compatibility

Changes are gated on --external-manifest being present, so any invocation without the flag runs the same code as before — no change to --help, arg parsing, defaults, or the SDK/Cargo surface. The only behavior changes affect combinations that were previously silently wrong:

Invocation Before After Impact
any command without --external-manifest — unchanged None
--external-manifest (default read) honored honored None
--external-manifest --output DIR silently used embedded store uses sidecar Report content changes (mismatch now Invalid); success exit code unchanged
--external-manifest --certs silently used embedded store uses sidecar Cert chain sourced from sidecar; success exit code unchanged
--external-manifest --tree silently used embedded store uses sidecar Tree reflects sidecar; success exit code unchanged
--external-manifest --ingredient (folder or plain) exited 0, misleading output errors, non-zero exit Hard break for automation relying on the old exit 0
--external-manifest --info exited 0, misleading output errors, non-zero exit Hard break for automation relying on the old exit 0

The ingredient/info combinations never honored the override, so the previous success was misleading rather than correct.

Tests added

Integration tests covering every modified combination: default read and --output report are Invalid for a mismatched sidecar and Valid for a matching one; --tree reflects the sidecar's manifest; --certs yields a cert chain only from the sidecar (the bare asset has none); --ingredient (folder and plain) and --info error out.

Checklist

  • This PR represents a single feature, fix, or change.
  • All applicable changes have been documented.
  • Any TO DO items (or similar) have been entered as GitHub issues and the link to that issue has been included in a comment.

@codecov

codecov Bot commented Sep 27, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.65217% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 79.39%. Comparing base (3f0165c) to head (887445a).

Files with missing lines Patch % Lines
src/main.rs 94.87% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #355      +/-   ##
==========================================
+ Coverage   76.42%   79.39%   +2.97%     
==========================================
  Files           4        4              
  Lines        1073     1097      +24     
==========================================
+ Hits          820      871      +51     
+ Misses        253      226      -27     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ssanthosh
ssanthosh merged commit 74ce1bd into main Oct 3, 2026
17 checks passed
@ssanthosh
ssanthosh deleted the ssaanthosh/vuln-37580 branch October 3, 2026 04:16
@ssanthosh ssanthosh added the backport-stable Cherry-pick this merged main PR onto the stable release line label Oct 3, 2026
@caiopensrc

caiopensrc commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Backport-action backported this pull request in workflow run 37097441106.

Target Status
stable ✅ Created #356

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-stable Cherry-pick this merged main PR onto the stable release line

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants