Skip to content

Add root metadata class to new TUF metadata model #1137

Description

@lukpueh

Description of issue or feature request:

Add root metadata class to tuf.api.metadata module and implement (de)serialisation methods (to_dict and from_dict) and adequate metadata update methods (see tuf.api.Signed-subclasses for inspiration).

Current behavior:
No Root class in tuf.api.metadata

Expected behavior:

# In tuf/api/metdata.py
class Root(Signed):
    ...

Activity

  1. added this to the Foundations milestone on Sep 10, 2020
  2. added a commit that references this issue on Sep 10, 2020
  3. added a commit that references this issue on Sep 17, 2020
  4. sechkova commented on Oct 28, 2020

    @sechkova
    Contributor

    Apologies if I had ruined someone's first issue but I needed this so I opened #1193 😁

    I want to mention that in the tests I had to fix dictionaries passed by reference and afterwards used as expected updated values.
    For example:

            fileinfo = snapshot.signed.meta // by reference
            hashes = {'sha256': 'c2986576f5fdfd43944e2b19e775453b96748ec4fe2638a6d2f32f1310967095'}
            fileinfo['role1.json']['version'] = 2
            fileinfo['role1.json']['hashes'] = hashes
            fileinfo['role1.json']['length'] = 123
    
            snapshot.signed.update('role1', 2, 123, hashes) // does not do anything really
            self.assertEqual(snapshot.signed.meta, fileinfo)
    

    I think we should design the metadata classes in a way that discourages such usage.
    Maybe #1139 is where this can take place?

  5. joshuagl commented on Oct 30, 2020

    @joshuagl
    Member

    I want to mention that in the tests I had to fix dictionaries passed by reference and afterwards used as expected updated values.
    For example:

            fileinfo = snapshot.signed.meta // by reference
            hashes = {'sha256': 'c2986576f5fdfd43944e2b19e775453b96748ec4fe2638a6d2f32f1310967095'}
            fileinfo['role1.json']['version'] = 2
            fileinfo['role1.json']['hashes'] = hashes
            fileinfo['role1.json']['length'] = 123
    
            snapshot.signed.update('role1', 2, 123, hashes) // does not do anything really
            self.assertEqual(snapshot.signed.meta, fileinfo)
    

    I think we should design the metadata classes in a way that discourages such usage.
    Maybe #1139 is where this can take place?

    Good catch, thanks! That does seem like another good argument for using classes for metadata fields, rather than passing dicts around.

  6. joshuagl commented on Oct 30, 2020

    @joshuagl
    Member

    fat-fingered the wrong button 🤦

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions