fix(trust-root)!: accept the ALL and UNDEFINED service selectors - #231
Merged
Merged
Conversation
protobuf-specs defines `ServiceSelector` as SERVICE_SELECTOR_UNDEFINED, ALL, ANY and EXACT, but only ANY and EXACT were modelled. A signing config that used ALL (or spelled out UNDEFINED) failed to deserialize, which also failed the TUF fetch that loads it. Add the missing variants, mark the enum `#[non_exhaustive]` and derive `Copy`, `PartialEq` and `Eq`. An omitted selector still means ANY. BREAKING CHANGE: `ServiceSelector` gains `All` and `Undefined` variants and is `#[non_exhaustive]`; exhaustive matches need a wildcard arm. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
baszalmstra
approved these changes
Sep 23, 2026
Merged
jku
pushed a commit
that referenced
this pull request
Sep 23, 2026
…#234) * fix(sign): pass RekorApiVersion in TUF service requirement test #226 and #227 merged independently: the test from #218 still passed `Some(1)` to `from_tuf_config_with_rekor_version`, which now takes `Option<RekorApiVersion>`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> * fix(sign): drop clone of Copy ServiceSelector in test #231 made ServiceSelector Copy, so clippy's clone_on_copy fires on the test added in #226. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> * fix(sign): give the custom-instance test fixture a TSA #218 (restored in #226) requires an eligible TSA endpoint, but the custom signing config added by #227 listed none. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> --------- Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 24, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ServiceSelectorasSERVICE_SELECTOR_UNDEFINED = 0; ALL = 1; ANY = 2; EXACT = 3, but onlyANYandEXACTwere modelled. A signing config usingALL(or spelling outSERVICE_SELECTOR_UNDEFINED) failed to deserialize, and so did the TUF fetch that loads itAllandUndefined, mark the enum#[non_exhaustive]so future selectors don't break callers, and deriveCopy/PartialEq/EqAny, so behaviour for existing configs is unchangedFollow-up after #226 lands: its signer check (from #218) rejects
EXACTwith a count other than 1, but would treatALLlikeANY. The signer should also rejectALLwhen more than one eligible operator exists, and rejectUndefined. I'll send that once both PRs are inmain, since that code isn't onmainyet.Validation
cargo clippy --workspace --all-targets --all-features -- -D warningscargo test -p sigstore-trust-root -p sigstore-sign --all-features(new tests: every selector parses and round-trips, unknown selectors are rejected, and a full signing config withALLparses)Signed-off-by: Wolf Vollprecht w.vollprecht@gmail.com
🤖 Generated with Claude Code