theupdateframework / theupdateframework/rust-tuf

Remove errant metadata/targets from local repo on failure

Open
#143 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Feature :: Improvement Priority :: Low
Dominant language
Rust
Stars
198
Forks
39
Avg merge
9h 19m
Merged PRs (30d)
2

Description

If an attacker manages to compromise the local repository (in this case only FS repos are susceptible, others may be in the future) and adds bad metadata, the client would attempt to update from the local repo initially then fail. It will never be able to recover without outside intervention.

We could delete the offending metadata to allow us to continue. This is safe so long as the bad metadata isn't correctly signed (which is technically good metadata, so we couldn't even tell anyway).

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by tracing the filesystem-repository update failure path and metadata validation behavior, then determine how recovery should remove only offending metadata while preserving correctly signed metadata; done means a compromised local repository can recover without outside intervention.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.