theupdateframework / theupdateframework/specification
Is multi-role delegation in 1.0.0 or not?
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 405
- Forks
- 59
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 1
Description
In the current version of the spec, we say:
5.5.6.2.1. If the current delegation is a multi-role delegation, recursively visit each role, and check that each has signed exactly the same non-custom metadata (i.e., length and hashes) about the target (or the lack of any such metadata).
But nowhere else do we actually define how to specify multi-role delegations. Did we: (1) forget to specify how multi-role delegations are listed (since they are backwards-incompatible), or (2) did we agree not to release them as part of 1.0.0, and this is leftover text intended for 2.0.0?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with section 5.5.6.2.1 of tuf-spec.md and compare its multi-role delegation wording with the referenced TAP3 backwards-compatibility discussion. Determine whether multi-role delegations are specified for version 1.0.0 or deferred to 2.0.0, then update the specification to reflect the decision.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100