Skip to content

fix(trust-root)!: accept the ALL and UNDEFINED service selectors - #231

Merged
baszalmstra merged 1 commit into
mainfrom
fix/service-selector-all
Sep 23, 2026
Merged

baszalmstra merged 1 commit into
mainfrom
fix/service-selector-all

Conversation

@wolfv

@wolfv wolfv commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • protobuf-specs defines ServiceSelector as SERVICE_SELECTOR_UNDEFINED = 0; ALL = 1; ANY = 2; EXACT = 3, but only ANY and EXACT were modelled. A signing config using ALL (or spelling out SERVICE_SELECTOR_UNDEFINED) failed to deserialize, and so did the TUF fetch that loads it
  • add All and Undefined, mark the enum #[non_exhaustive] so future selectors don't break callers, and derive Copy/PartialEq/Eq
  • an omitted selector still defaults to Any, so behaviour for existing configs is unchanged

Follow-up after #226 lands: its signer check (from #218) rejects EXACT with a count other than 1, but would treat ALL like ANY. The signer should also reject ALL when more than one eligible operator exists, and reject Undefined. I'll send that once both PRs are in main, since that code isn't on main yet.

Validation

  • cargo clippy --workspace --all-targets --all-features -- -D warnings
  • cargo test -p sigstore-trust-root -p sigstore-sign --all-features (new tests: every selector parses and round-trips, unknown selectors are rejected, and a full signing config with ALL parses)

Signed-off-by: Wolf Vollprecht w.vollprecht@gmail.com

🤖 Generated with Claude Code

protobuf-specs defines `ServiceSelector` as SERVICE_SELECTOR_UNDEFINED,
ALL, ANY and EXACT, but only ANY and EXACT were modelled. A signing config
that used ALL (or spelled out UNDEFINED) failed to deserialize, which also
failed the TUF fetch that loads it.

Add the missing variants, mark the enum `#[non_exhaustive]` and derive
`Copy`, `PartialEq` and `Eq`. An omitted selector still means ANY.

BREAKING CHANGE: `ServiceSelector` gains `All` and `Undefined` variants and
is `#[non_exhaustive]`; exhaustive matches need a wildcard arm.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@baszalmstra
baszalmstra merged commit 15dad63 into main Sep 23, 2026
19 checks passed
@baszalmstra
baszalmstra deleted the fix/service-selector-all branch September 23, 2026 15:39
@wolfv wolfv mentioned this pull request Sep 23, 2026
wolfv added a commit that referenced this pull request Sep 23, 2026
#231 made ServiceSelector Copy, so clippy's clone_on_copy fires on the
test added in #226.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
jku pushed a commit that referenced this pull request Sep 23, 2026
…#234)

* fix(sign): pass RekorApiVersion in TUF service requirement test

#226 and #227 merged independently: the test from #218 still passed
`Some(1)` to `from_tuf_config_with_rekor_version`, which now takes
`Option<RekorApiVersion>`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>

* fix(sign): drop clone of Copy ServiceSelector in test

#231 made ServiceSelector Copy, so clippy's clone_on_copy fires on the
test added in #226.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>

* fix(sign): give the custom-instance test fixture a TSA

#218 (restored in #226) requires an eligible TSA endpoint, but the
custom signing config added by #227 listed none.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>

---------

Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants