theupdateframework / theupdateframework/specification

Describe and delineate "trusted metadata"

Open
#179 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
405
Forks
59
Avg merge
3d 4h
Merged PRs (30d)
1

Description

The detailed client workflow refers to trusted metadata, or a specific role's trusted metadata, several times. However, it doesn't explain what trusted metadata is, except implicitly during 5.3.7 where we "Set the trusted root metadata file".

This is particularly surprising when discussing the use of trusted metadata when checking for rollback attacks in 5.4.3 and 5.5.5

Furthermore, we should explicitly refer to the initial trusted root metadata that is loaded in 5.2 by a distinct name. This metadata that is delivered out-of-band should be lifecycle managed differently to other trusted metadata and a distinct name makes it easier to discuss in ancillary materials.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the detailed client workflow and sections 5.2 through 5.5 of the specification, especially the references to trusted metadata in rollback checks. Define trusted metadata explicitly, give the out-of-band root metadata a distinct name, and update the affected references so the terminology and lifecycle distinction are consistent.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.