Reject custom test log lists whose logs lack the "test" marker - #363
Merged
Conversation
A custom test log list (strategy.testLogListFilename) replaces the test TLS logs but never touches the active/usable lists. If one of its logs is also present in the active log list, it would appear in active_tls_logs.json too. Require every log and tiled log in a custom test log list to set log_type: "test". validateLogList now rejects any that don't, so LoadCustomTestLogList fails and ctsubmit refuses to start rather than serving a non-test log as active/usable.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A custom test log list (`strategy.testLogListFilename`) replaces the test TLS logs, but `LoadCustomTestLogList` only reassigns `TestTLSLogs` — it never touches the active/usable lists (which are frozen at package init from the embedded `ctloglists.CrtshV3Active`).
If a log is present in both the embedded active log list and the custom test file, it appears in `active_tls_logs.json` and `test_tls_logs.json`, because there is no de-duplication. That's the source of the "active endpoint emits custom logs" report. It's aggravated by `determineActiveTLSLogs` classifying a log as active whenever `log_type != "test"`, so a test log that omits the marker is treated as active.
Fix
Require every log and tiled log in a custom test log list to set `"log_type": "test"`. `validateLogList` now rejects any that don't, so `LoadCustomTestLogList` returns an error and ctsubmit fails fast at startup (via `lgr.Fatal`) rather than serving a non-test log as active/usable.
Tests
Docs