-
-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathinfection.json5
More file actions
80 lines (80 loc) · 4.35 KB
/
Copy pathinfection.json5
File metadata and controls
80 lines (80 loc) · 4.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
{
"$schema": "https://raw.githubusercontent.com/infection/infection/master/resources/schema.json",
"source": {
"directories": [
"src"
]
},
"timeout": 30,
"logs": {
"text": "infection.log"
},
// Strict: with the equivalent mutants documented below excluded, every generated mutant must be killed.
"minMsi": 100,
"minCoveredMsi": 100,
"mutators": {
"@default": true,
// `protected` → `private` on members only used within their own class or trait is invisible to tests,
// but the protected visibility is part of the extension API (tests themselves subclass these members).
"ProtectedVisibility": false,
"LogicalAnd": {
"ignore": [
// `openssl_sign(...) === true && is_string($signature)`: when openssl_sign() fails, $signature
// stays null, so `&&` and `||` behave identically; the is_string() guard is for static analysis.
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\Ecdsa\\AbstractEcdsaSigner::sign",
// Same shape: when openssl_private_encrypt()/openssl_public_decrypt() fails, the by-ref output
// stays null, so both operands are always equal and `&&`/`||` behave identically; the
// is_string() guard is for static analysis.
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\RsaPss\\AbstractRsaPssSigner::sign",
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\RsaPss\\AbstractRsaPssVerifier::recover"
]
},
"LessThan": {
"ignore": [
// mgf1(): `<` → `<=` in the loop condition only appends one extra hash block that the trailing
// substr() truncates away, so the returned mask is identical.
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\RsaPss\\EmsaPss::mgf1"
]
},
"LogicalOr": {
"ignore": [
// modulusBits(): openssl_pkey_get_details() always returns an array with an int `bits` for the
// handles the Rsa* key classes validate at construction, so both operands are always false and
// `||`/`&&` behave identically; the guard exists for static analysis.
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\RsaPss\\EmsaPss::modulusBits"
]
},
"DecrementInteger": {
"ignore": [
// `max(1, strlen($signature) / 2)` → `max(0, ...)`: both blow up identically for the sub-2-byte
// inputs the guard covers, and verify() length-checks every signature before calling this.
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\Ecdsa\\AbstractEcdsaVerifier::signatureToDer"
]
},
"Assignment": {
"ignore": [
// `$tagHeader |= 0x20` → `=`: $tagHeader is always 0 at that point, so both are identical.
"MiladRahimi\\Jwt\\Cryptography\\Algorithms\\Ecdsa\\AbstractEcdsaVerifier::encodeDer"
]
},
"CastString": {
"ignore": [
// `(string)file_get_contents(...)`: the cast exists for static analysis (false on unreadable
// files); the call is guarded by is_file(), so the cast is unobservable.
"MiladRahimi\\Jwt\\Cryptography\\Keys\\EcdsaPrivateKey::__construct",
"MiladRahimi\\Jwt\\Cryptography\\Keys\\EcdsaPublicKey::__construct",
"MiladRahimi\\Jwt\\Cryptography\\Keys\\Ed448PrivateKey::__construct",
"MiladRahimi\\Jwt\\Cryptography\\Keys\\Ed448PublicKey::__construct",
"MiladRahimi\\Jwt\\Cryptography\\Keys\\RsaPrivateKey::__construct",
"MiladRahimi\\Jwt\\Cryptography\\Keys\\RsaPublicKey::__construct",
// `(string)$this->value` under an is_scalar() guard: string interpolation performs the exact
// same conversion, so the cast is unobservable.
"MiladRahimi\\Jwt\\Validator\\Rules\\EqualsTo::validate",
"MiladRahimi\\Jwt\\Validator\\Rules\\IdenticalTo::validate",
// `(string)$verifier->kid()`: a null kid registers under "" with or without the cast; the cast
// only avoids a PHP 8.1+ deprecation notice.
"MiladRahimi\\Jwt\\VerifierFactory::__construct"
]
}
}
}