theupdateframework / theupdateframework/specification
Describe and delineate "trusted metadata"
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 405
- Forks
- 59
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 1
Description
The detailed client workflow refers to trusted metadata, or a specific role's trusted metadata, several times. However, it doesn't explain what trusted metadata is, except implicitly during 5.3.7 where we "Set the trusted root metadata file".
This is particularly surprising when discussing the use of trusted metadata when checking for rollback attacks in 5.4.3 and 5.5.5
Furthermore, we should explicitly refer to the initial trusted root metadata that is loaded in 5.2 by a distinct name. This metadata that is delivered out-of-band should be lifecycle managed differently to other trusted metadata and a distinct name makes it easier to discuss in ancillary materials.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the detailed client workflow and sections 5.2 through 5.5 of the specification, especially the references to trusted metadata in rollback checks. Define trusted metadata explicitly, give the out-of-band root metadata a distinct name, and update the affected references so the terminology and lifecycle distinction are consistent.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100