ngclient: support `StorageBackendInterface`?
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 30/100
- Issue 類型
- 功能
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 技術堆疊
- python
研究方向
從 tuf/ngclient/updater.py 的第 293-312 行附近開始,將其持久化 repository I/O 與低階中繼資料 API 使用的現有 StorageBackendInterface 進行比較。確定 ngclient 所需的 API 和整合範圍,然後驗證 repository 操作可以在分散式部署中使用非本機儲存。
由索引模型根據 Issue 內容生成。
描述
Description of issue or feature request:
Right now, tuf.ngclient is heavily tied to local system I/O: it assumes a metadata directory on disk that can be read/written. For example:
This is problematic in distributed worker setups like Warehouse (PyPI), where each worker has its own container/entire VM and thus can't easily share on-disk TUF repos. In particular, this causes both reliability and security concerns:
- Reliability: an unfortunate corruption in a single worker's TUF repo results in a hard-to-diagnose flaky worker, since each worker has its own copy of the repo.
- Security: each worker's TUF repo is independently stored on a (machine-local) disk, making them harder to audit.
This problem was noted a few years back, before tuf.ngclient was created: https://github.com/theupdateframework/python-tuf/issues/1009. The solution then was to add a filesystem abstraction to the tuf.metadata APIs, which was done via https://github.com/secure-systems-lab/securesystemslib/pull/232 and https://github.com/theupdateframework/python-tuf/issues/1009. However, this abstraction wasn't added to the ngclient APIs, only to the low-level metadata ones.
Current behavior:
tuf.ngclient currently assumes that it can perform persistent local I/O for its repository.
Expected behavior:
tuf.ngclient should support an I/O abstraction (such as the pre-existing StorageBackendInterface, if suitable) for persistent repo operations, enabling use in distributed deployments.
- 主要語言
- Python
- 星號
- 1.7k
- 分支
- 304
- 平均合併
- 9 小時 25 分鐘
- 30 天內合併 PR
- 14
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
theupdateframework/python-tuf 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 48/100
theupdateframework/python-tuf#3001 ·
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 42/100
theupdateframework/python-tuf#2979 · 1 則留言 ·
維護者通常 1 天內回覆
-
enhancement github_actions
難度 3/5 1-2 天 新手友好度 45/100
theupdateframework/python-tuf#2920 · 1 則留言 · 2 個 reaction ·
維護者通常 1 天內回覆
-
難度 3/5 1-2 天 新手友好度 35/100
theupdateframework/python-tuf#2842 · 3 則留言 ·
維護者通常 1 天內回覆
-
難度 5/5 一週以上 新手友好度 25/100
theupdateframework/python-tuf#2836 · 7 則留言 ·
維護者通常 1 天內回覆
查看 theupdateframework/python-tuf 的全部 Issue
相似的 Issue
-
bug
難度 2/5 1-3 小時 新手友好度 85/100
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 90/100
維護者通常 1 天內回覆
-
instance instance add
難度 2/5 1-3 小時 新手友好度 68/100
searxng/searx-instances#941 · 1 則留言 ·
-
難度 1/5 1 小時以內 新手友好度 92/100
FluidNumerics/fluid-walk-blocker#89 ·
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 84/100
維護者通常 1 天內回覆