theupdateframework / theupdateframework/rust-tuf
Remove errant metadata/targets from local repo on failure
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 198
- Forks
- 39
- Avg merge
- 9h 19m
- Merged PRs (30d)
- 2
Description
If an attacker manages to compromise the local repository (in this case only FS repos are susceptible, others may be in the future) and adds bad metadata, the client would attempt to update from the local repo initially then fail. It will never be able to recover without outside intervention.
We could delete the offending metadata to allow us to continue. This is safe so long as the bad metadata isn't correctly signed (which is technically good metadata, so we couldn't even tell anyway).
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Start by tracing the filesystem-repository update failure path and metadata validation behavior, then determine how recovery should remove only offending metadata while preserving correctly signed metadata; done means a compromised local repository can recover without outside intervention.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100