I think we do not currently test successful rollback (aka fast-forward recovery) for timestamp, snapshot and targets:
- simulate a fast-forward attack: create repository with valid timestamp/snapshot/targets with version=MAX_VERSION (or something large anyway)
- update client so it sees the large versions
- rotate the affected key (timestamp or snapshot) and set metadata version=1
- update client, assert that new metadata is accepted by ngclient (even though the version number is lower than the local version)
I think we do not currently test successful rollback (aka fast-forward recovery) for timestamp, snapshot and targets: