Merge pull request from QiWang19/sigpath

fix podman sign signature store for rootless
This commit is contained in:
OpenShift Merge Robot 2019-09-12 22:23:29 +02:00 committed by GitHub
commit 3acfc3b7df
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 22 additions and 10 deletions
cmd/podman

View File

@ -14,6 +14,7 @@ import (
"github.com/containers/libpod/cmd/podman/cliconfig" "github.com/containers/libpod/cmd/podman/cliconfig"
"github.com/containers/libpod/cmd/podman/libpodruntime" "github.com/containers/libpod/cmd/podman/libpodruntime"
"github.com/containers/libpod/libpod/image" "github.com/containers/libpod/libpod/image"
"github.com/containers/libpod/pkg/rootless"
"github.com/containers/libpod/pkg/trust" "github.com/containers/libpod/pkg/trust"
"github.com/containers/libpod/pkg/util" "github.com/containers/libpod/pkg/util"
"github.com/pkg/errors" "github.com/pkg/errors"
@ -130,6 +131,16 @@ func signCmd(c *cliconfig.SignValues) error {
return errors.Wrapf(err, "error pulling image %s", signimage) return errors.Wrapf(err, "error pulling image %s", signimage)
} }
if rootless.IsRootless() {
if sigStoreDir == "" {
runtimeConfig, err := runtime.GetConfig()
if err != nil {
return err
}
sigStoreDir = filepath.Join(filepath.Dir(runtimeConfig.StorageConfig.GraphRoot), "sigstore")
}
} else {
registryInfo := trust.HaveMatchRegistry(rawSource.Reference().DockerReference().String(), registryConfigs) registryInfo := trust.HaveMatchRegistry(rawSource.Reference().DockerReference().String(), registryConfigs)
if registryInfo != nil { if registryInfo != nil {
if sigStoreDir == "" { if sigStoreDir == "" {
@ -146,6 +157,7 @@ func signCmd(c *cliconfig.SignValues) error {
if sigStoreDir == "" { if sigStoreDir == "" {
sigStoreDir = SignatureStoreDir sigStoreDir = SignatureStoreDir
} }
}
repos, err := newImage.RepoDigests() repos, err := newImage.RepoDigests()
if err != nil { if err != nil {