repo/index-v2.json is a re-serialization, not the bytes that were served
まだ誰も着手していません。
評価
調査の方向性
まず btlog.py を読み、json.dump で repo/index-v2.json を生成する方法を調べます。その出力を配信された index-v2.json と比較し、ログに配信されたバイト列を保持させるべきか、シリアライザーの設定を記録させるべきかを判断します。受け手が推測した CPython のデフォルトに頼らず、配信されたファイルを再現または検証できれば完了です。
索引モデルが issue の本文から書いたものです。
説明
The JSON in this log isn't the JSON that was served. btlog.py parses it and writes it back with json.dump(..., indent=2), so repo/index-v2.json here is 1,055,505 bytes where the served file is 687,628.
Checked rather than assumed: parsing today's served index-v2.json with object_pairs_hook=OrderedDict and re-dumping at indent=2 reproduces the file in this repo byte-for-byte, sha256 144593b4ea4f2dd5…. So the log does hold today's index — just not the bytes anyone received.
That makes "People can then check that any file that they received from that F-Droid repository was a publicly released file" true only for someone running CPython who guesses the exact call. The separators, the escaping and the number formatting are json.dump defaults, declared nowhere in the log, and no other language reproduces them.
The .jar path is fine. Stripping to META-INF/ keeps the manifest digests, so a received entry.json can be checked against SHA-256-Digest without the payload being stored twice.
Storing the served bytes would close it. Failing that, recording which serializer produced these files would at least make them reproducible on purpose rather than by inference.
- 主要言語
- 言語のデータがありません
- スター
- 9
- フォーク
- 3
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
guardianproject/binary_transparency_log のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 52/100
guardianproject/binary_transparency_log の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
supabase/agent-skills#614 ·
-
bug cleanup
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
prime-radiant-inc/evener#3199 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
acl documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
valkey-io/valkey-operator#489 ·
メンテナーはふだん 2 日以内に返信