fix: strip digest algorithm prefix before hex decoding

OCI references with tag+digest (e.g., chart:1.0@sha256:abc...) failed with "invalid byte" error because the sha256: prefix was passed to hex.DecodeString().

Signed-off-by: Evans Mungai <mbuevans@gmail.com>
pull/31601/head
Evans Mungai 10 months ago
parent ff35414bed
commit c5112b91df
No known key found for this signature in database
GPG Key ID: BBEB812143DD14E1

@ -125,7 +125,8 @@ func (c *ChartDownloader) DownloadTo(ref, version, dest string) (string, *proven
var digest32 [32]byte var digest32 [32]byte
if hash != "" { if hash != "" {
// if there is a hash, populate the other formats // if there is a hash, populate the other formats
digest, err = hex.DecodeString(hash) // Strip the algorithm prefix (e.g., "sha256:") if present
digest, err = hex.DecodeString(stripDigestAlgorithm(hash))
if err != nil { if err != nil {
return "", nil, err return "", nil, err
} }
@ -225,7 +226,8 @@ func (c *ChartDownloader) DownloadToCache(ref, version string) (string, *provena
c.Options = append(c.Options, getter.WithAcceptHeader("application/gzip,application/octet-stream")) c.Options = append(c.Options, getter.WithAcceptHeader("application/gzip,application/octet-stream"))
// Check the cache for the file // Check the cache for the file
digest, err := hex.DecodeString(digestString) // Strip the algorithm prefix (e.g., "sha256:") if present
digest, err := hex.DecodeString(stripDigestAlgorithm(digestString))
if err != nil { if err != nil {
return "", nil, fmt.Errorf("unable to decode digest: %w", err) return "", nil, fmt.Errorf("unable to decode digest: %w", err)
} }
@ -578,3 +580,12 @@ func loadRepoConfig(file string) (*repo.File, error) {
} }
return r, nil return r, nil
} }
// stripDigestAlgorithm removes the algorithm prefix (e.g., "sha256:") from a digest string.
// If no prefix is present, the original string is returned unchanged.
func stripDigestAlgorithm(digest string) string {
if idx := strings.Index(digest, ":"); idx >= 0 {
return digest[idx+1:]
}
return digest
}

@ -485,3 +485,41 @@ func TestDownloadToCache(t *testing.T) {
c.Keyring = "" c.Keyring = ""
}) })
} }
func TestStripDigestAlgorithm(t *testing.T) {
tests := []struct {
name string
input string
expected string
}{
{
name: "sha256 prefixed digest",
input: "sha256:aef46c66a7f2d5a12a7e3f54a64790daf5c9a9e66af3f46955efdaa6c900341d",
expected: "aef46c66a7f2d5a12a7e3f54a64790daf5c9a9e66af3f46955efdaa6c900341d",
},
{
name: "sha512 prefixed digest",
input: "sha512:abcdef1234567890",
expected: "abcdef1234567890",
},
{
name: "plain hex digest without prefix",
input: "aef46c66a7f2d5a12a7e3f54a64790daf5c9a9e66af3f46955efdaa6c900341d",
expected: "aef46c66a7f2d5a12a7e3f54a64790daf5c9a9e66af3f46955efdaa6c900341d",
},
{
name: "empty string",
input: "",
expected: "",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
result := stripDigestAlgorithm(tt.input)
if result != tt.expected {
t.Errorf("stripDigestAlgorithm(%q) = %q, want %q", tt.input, result, tt.expected)
}
})
}
}

Loading…
Cancel
Save