Repository navigation
Never present a failed or undecided check as a clean result - #4
Merged
Merged
Conversation
Signatures - Load each signature separately. pyHanko's embedded_signatures raised on the first unreadable signature container, which left every signature in the file unvalidated and only produced a LOW note that blamed a legacy format. - An unreadable signature container is now signature.unparseable (HIGH). A pyHanko failure while reading the signatures marks the analysis incomplete instead of only being recorded in the facts. - signature.validation-error keeps MEDIUM effective severity (confidence MEDIUM instead of LOW): integrity is unknown, which needs review. - pdfsig reporting that it did not verify a signature is now pdfsig.integrity-unknown instead of producing no finding. Summary, batch report and exit code - "Checked and found in order" lines are only written for analysers that ran and reported no error, for PDF and Office alike, and the signature line is withheld when any signature finding leaves integrity in doubt. - The batch report marks incomplete verdicts and counts them apart from documents without significant findings. - --fail-on also exits 1 when an analysis is incomplete or a file could not be analysed.
…s, and make --fail-on-incomplete opt-in Follow-up after review: - Document timestamps (/DocTimeStamp) are validated with validate_pdf_timestamp instead of failing validate_pdf_signature, so PAdES-LTA and other timestamped files are no longer flagged. - pdfsig: an unsigned signature field is skipped, and "integrity unknown" is only reported when pyHanko did not settle the integrity of that signature either (Poppler does not verify document timestamps). - pyHanko decrypts files that have only an owner password (empty user password), or uses --password, before reading the signatures. - signature.unparseable is only used when the CMS container itself cannot be read; other loader failures are validation errors. signature.not-validated is not added when pyHanko could not read the file at all, since the analysis is then already incomplete. - Field names are stored as plain strings (pyHanko returns proxy objects for encrypted files, which broke report serialisation). - --fail-on keeps its previous behaviour. The new --fail-on-incomplete exits 1 when an analysis is incomplete or a file could not be analysed. The batch summary lists incomplete files in its JSON.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The README says a failed check never counts as clean. A few paths still presented a failed or undecided check as a clean result:
reader.embedded_signaturesraises on the first signature whose CMS container cannot be read. The error only went into the facts, the analysis stayed complete, and the only finding was a LOW note that blamed a legacy format. One damaged signature also left every other signature in the file unvalidated.signature.validation-errorhad LOW confidence, so it counted as LOW.Changes
signatures.py: signatures are loaded one by one, with the same SubFilter filter pyHanko uses. A CMS container that cannot be read issignature.unparseable(HIGH); other loader failures aresignature.validation-error, now with MEDIUM confidence. A pyHanko failure while reading the file marks the analysis incomplete. Document timestamps are validated withvalidate_pdf_timestamp. Files with only an owner password are decrypted before reading.pdfsig.py: newpdfsig.integrity-unknown(MEDIUM, low confidence) when Poppler did not verify a signature and pyHanko did not settle its integrity either. Empty signature fields are skipped.summary.py: "Checked and found in order" lines are only written for analysers that ran without error, for PDF and Office. The signature line is withheld when any signature finding leaves integrity in doubt. The batch summary counts incomplete files separately and lists them in the JSON.render.py: the batch table marks incomplete verdicts.cli.py: new opt-in--fail-on-incompleteexits 1 when an analysis is incomplete or a file could not be analysed.--fail-onis unchanged. Legacy .doc/.xls/.ppt files are always incomplete, which is why this is a separate flag and noted in the README.Testing
pytest: all tests pass, including new tests for a damaged signature among valid ones, document timestamps with and without a prior signature, an empty signature field, an owner-password-only signed file, analyser failures in the summary and batch output, and both exit-code flags.lowtoinfo. Damaged signature containers go fromlowtohigh.This touches
summary.pyandtests/pdfgen.pynext to #3; whichever is merged second may need a small rebase, which I can do.