Skip to content

fix(sign)!: keep the configured instance when selecting a Rekor version - #227

Merged
baszalmstra merged 2 commits into
mainfrom
fix/rekor-version-keeps-instance
Sep 23, 2026
Merged

baszalmstra merged 2 commits into
mainfrom
fix/rekor-version-keeps-instance

Conversation

@wolfv

@wolfv wolfv commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • remove SigningConfig::with_rekor_version. It replaced rekor_url with RekorApiVersion::default_url(), which is always production, so sign_blob --staging --v2 and custom instances uploaded to log2025-1.rekor.sigstore.dev
  • from_tuf_config_with_rekor_version now takes Option<RekorApiVersion> instead of Option<u32>, picks the endpoint from the instance's own signing config, and errors when there is no endpoint for the requested version
  • sign_blob selects the v2 endpoint from the TUF signing config it already fetched

This addresses part of the review comment on #176 about default_url() helpers. Removing the remaining default-URL helpers is left for the 1.0 API cleanup.

Conflict note: #226 also touches from_tuf_config_with_rekor_version (its tests pass Some(1)). Whichever PR merges second needs a small rebase.

Validation

  • cargo clippy -p sigstore-sign -p sigstore-conformance --all-targets --all-features -- -D warnings
  • cargo test -p sigstore-sign --all-features (new tests: staging v1/v2 keep staging URLs; a custom instance without v2 errors instead of falling back)

Signed-off-by: Wolf Vollprecht w.vollprecht@gmail.com

🤖 Generated with Claude Code

wolfv and others added 2 commits September 23, 2026 14:38
`SigningConfig::with_rekor_version` overwrote `rekor_url` with
`RekorApiVersion::default_url()`, which always points at the public-good
production log. `sign_blob --staging --v2` and any custom or TUF-derived
configuration therefore uploaded to production Rekor v2.

Remove the method and select the requested version from the instance's
own signing config via `from_tuf_config_with_rekor_version`, which now
takes `Option<RekorApiVersion>` and errors when no matching endpoint exists.

BREAKING CHANGE: `SigningConfig::with_rekor_version` is removed; use
`SigningConfig::from_tuf_config_with_rekor_version(&tuf, Some(version))`.
`from_tuf_config_with_rekor_version` takes `Option<RekorApiVersion>`
instead of `Option<u32>`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
The production signing config does not publish a Rekor v2 log yet. The
interop job's `sign_blob --v2` only worked because `with_rekor_version`
silently substituted the built-in production v2 URL. Add a `--rekor-url`
option to the example and pass the log URL visibly in the workflow.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@wolfv

wolfv commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator Author

Interop failed on the [V2] Sign step: the production TUF signing config has no Rekor v2 entry (rekorTlogUrls only lists rekor.sigstore.dev v1). The job only passed before because of the silent default this PR removes. I added --rekor-url to sign_blob, and the interop workflow now passes https://log2025-1.rekor.sigstore.dev explicitly, as suggested in the #176 review.

@baszalmstra
baszalmstra merged commit 0ad220d into main Sep 23, 2026
19 checks passed
@baszalmstra
baszalmstra deleted the fix/rekor-version-keeps-instance branch September 23, 2026 15:40
wolfv added a commit that referenced this pull request Sep 23, 2026
#218 (restored in #226) requires an eligible TSA endpoint, but the
custom signing config added by #227 listed none.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
jku pushed a commit that referenced this pull request Sep 23, 2026
…#234)

* fix(sign): pass RekorApiVersion in TUF service requirement test

#226 and #227 merged independently: the test from #218 still passed
`Some(1)` to `from_tuf_config_with_rekor_version`, which now takes
`Option<RekorApiVersion>`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>

* fix(sign): drop clone of Copy ServiceSelector in test

#231 made ServiceSelector Copy, so clippy's clone_on_copy fires on the
test added in #226.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>

* fix(sign): give the custom-instance test fixture a TSA

#218 (restored in #226) requires an eligible TSA endpoint, but the
custom signing config added by #227 listed none.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>

---------

Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants