theupdateframework / theupdateframework/specification

Is multi-role delegation in 1.0.0 or not?

Open
#140 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
Python
Stars
405
Forks
59
Avg merge
3d 4h
Merged PRs (30d)
1

Description

In the current version of the spec, we say:

5.5.6.2.1. If the current delegation is a multi-role delegation, recursively visit each role, and check that each has signed exactly the same non-custom metadata (i.e., length and hashes) about the target (or the lack of any such metadata).

But nowhere else do we actually define how to specify multi-role delegations. Did we: (1) forget to specify how multi-role delegations are listed (since they are backwards-incompatible), or (2) did we agree not to release them as part of 1.0.0, and this is leftover text intended for 2.0.0?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with section 5.5.6.2.1 of tuf-spec.md and compare its multi-role delegation wording with the referenced TAP3 backwards-compatibility discussion. Determine whether multi-role delegations are specified for version 1.0.0 or deferred to 2.0.0, then update the specification to reflect the decision.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.