Skip to content

fix(sign): reject ALL and UNDEFINED service requirements it cannot meet - #235

Merged
baszalmstra merged 1 commit into
mainfrom
fix/sign-all-undefined-selectors
Sep 24, 2026
Merged

baszalmstra merged 1 commit into
mainfrom
fix/sign-all-undefined-selectors

Conversation

@wolfv

@wolfv wolfv commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #231, as noted there. The signer submits to one Rekor log and one TSA. It already rejected EXACT with a count other than 1 (#218), but treated ALL like ANY and accepted UNDEFINED.

  • ALL is accepted only when every eligible endpoint (supported version, valid now) belongs to a single operator. In that case one submission satisfies it; otherwise it's a config error
  • UNDEFINED and future (#[non_exhaustive]) selectors are rejected instead of guessed
  • the embedded production and staging configs use ANY, so their behaviour is unchanged

Validation

  • cargo clippy -p sigstore-sign --all-targets --all-features -- -D warnings
  • cargo test -p sigstore-sign --all-features --lib (new test: ALL with one operator passes; ALL across two operators and UNDEFINED fail, for both Rekor and TSA)

Signed-off-by: Wolf Vollprecht w.vollprecht@gmail.com

🤖 Generated with Claude Code

The signer submits to one Rekor log and one TSA. It already rejected
EXACT with a count other than 1, but treated ALL like ANY and accepted
UNDEFINED. Accept ALL only when every eligible endpoint belongs to one
operator, and reject UNDEFINED and future selectors.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@baszalmstra
baszalmstra merged commit a1d4b08 into main Sep 24, 2026
19 checks passed
@baszalmstra
baszalmstra deleted the fix/sign-all-undefined-selectors branch September 24, 2026 13:32
@wolfv wolfv mentioned this pull request Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants