From 35a41c39a4bed2ad4379cfcd49587a7f79e8f8b4 Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Sun, 24 Aug 2025 13:52:33 +0200 Subject: [PATCH] cli/trust: check for Digested, Tagged reference instead of Canonical The [Canonical] interface defines images that are both [Named] and [Digested], but in all places where it was used, we were only interested whether the reference contained a digest. Similarly [NamedTagged] is a superset of [Tagged], so checking for [Tagged] is sufficient if we're already dealing with a [Named] reference. This patch changes those checks to check for [Digested] and [Tagged] references, as that's what's relevant for these checks. [Named]: https://pkg.go.dev/github.com/distribution/reference#Named [NamedTagged]: https://pkg.go.dev/github.com/distribution/reference#NamedTagged [Canonical]: https://pkg.go.dev/github.com/distribution/reference#Canonical [Digested]: https://pkg.go.dev/github.com/distribution/reference#Digested Signed-off-by: Sebastiaan van Stijn --- cli/trust/trust.go | 10 ++++------ cli/trust/trust_push.go | 4 ++-- 2 files changed, 6 insertions(+), 8 deletions(-) diff --git a/cli/trust/trust.go b/cli/trust/trust.go index 7af2a27350..a70a496669 100644 --- a/cli/trust/trust.go +++ b/cli/trust/trust.go @@ -346,9 +346,9 @@ func GetImageReferencesAndAuth(ctx context.Context, func getTag(ref reference.Named) string { switch x := ref.(type) { - case reference.Canonical, reference.Digested: - return "" - case reference.NamedTagged: + case reference.Digested: + return "" // TODO(thaJeztah): is it intentional to discard the tag when "Tagged+Digested"? + case reference.Tagged: return x.Tag() default: return "" @@ -357,12 +357,10 @@ func getTag(ref reference.Named) string { func getDigest(ref reference.Named) digest.Digest { switch x := ref.(type) { - case reference.Canonical: - return x.Digest() case reference.Digested: return x.Digest() default: - return digest.Digest("") + return "" } } diff --git a/cli/trust/trust_push.go b/cli/trust/trust_push.go index 47057b3f48..ef7f19f1af 100644 --- a/cli/trust/trust_push.go +++ b/cli/trust/trust_push.go @@ -63,9 +63,9 @@ func PushTrustedReference(ctx context.Context, ioStreams Streams, repoInfo *Repo var tag string switch x := ref.(type) { - case reference.Canonical: + case reference.Digested: return errors.New("cannot push a digest reference") - case reference.NamedTagged: + case reference.Tagged: tag = x.Tag() default: // We want trust signatures to always take an explicit tag,