[Suit] Ordering of elements in SUIT Manifest

Brendan Moran <Brendan.Moran@arm.com> Thu, 28 July 2022 22:37 UTC

Return-Path: <Brendan.Moran@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80751C131946 for <suit@ietfa.amsl.com>; Thu, 28 Jul 2022 15:37:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=KhPFaTgA; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=KhPFaTgA
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d34eFcE4HGN6 for <suit@ietfa.amsl.com>; Thu, 28 Jul 2022 15:37:44 -0700 (PDT)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (mail-eopbgr10072.outbound.protection.outlook.com [40.107.1.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B5159C15C504 for <suit@ietf.org>; Thu, 28 Jul 2022 15:37:42 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass; b=TkfbJLtjseGw/Dwprz0EJ+6b9sopBpfkgpyITJYc8KF2TM9add+wC3xiuxT1Rr4/jKcCplz+wxJYH8W4HP78Sp0RjzYvEoLrIbmV6pkSx1beFJsgP4TMns1NWNK/jkcwHk4AT6C2mByt9XjMD89z+2+zo5R9rzRtR/Me85PGFtGAWvc+lNoWiAiKmHA/ailv49HMnuep3J0L4NbSO/gaMJEFBvnE3pX2/qzkGT3aLuwuXnDQ4adfZV8PMqNQW+mySvq6Nsy+Dn00qtdmkB+NjUUAFEcfRFbjqjCb7oB500lqnup1kN+GQb68M3U+EyjW5IrUCMtu812cqQs9plczww==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=LReK+PVIDZOjOdAO0efNjc9BJVskZATUQAdfVsz0cfU=; b=iLu84zBtZQAofpt7QjE+Md6r1aYG99uBWcpOW3GWX/INlambU5nFYWqxBLXcC/P4bxlCA2olc221rJHQvGzASkKYfyJyB5fZTdaK78BysWeL7ns6ar/LL0dIoOFLpDISQLquM+kPQMtTBtFwY5ae/yJl7XZN7+HMMpRQ69l7SsnmVrzJUvZHVkfZZDPq0RsJjjw6IZxJykf2TBPn+xZyEezMheHJqwEdzSP1Fc/euzDxZS8MTjl882fxrR9skbp37DcN2uWyPGCqYOlTXoUX6QrRrDzrjPJwpFpqrolOJ4cgBB9vBHOoc1uwH+ZivaV0ZQCDmTuRviUySczT4Ri7Zg==
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 63.35.35.123) smtp.rcpttodomain=ietf.org smtp.mailfrom=arm.com; dmarc=pass (p=none sp=none pct=100) action=none header.from=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1 spf=[1,1,smtp.mailfrom=arm.com] dkim=[1,1,header.d=arm.com] dmarc=[1,1,header.from=arm.com])
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=LReK+PVIDZOjOdAO0efNjc9BJVskZATUQAdfVsz0cfU=; b=KhPFaTgAcltjLd5FnVLLo9KWj9vKMcm2UtQPAHponfhJYc9K7rkYfynRA8dMuqiNVaPUGzeUjjRL8pkx0lcuASx1sgILpjP/etu4sPtW75P0ItKy9jJQzSJkoJa9d6a+7e3cagj8A6E38/KHk1RSQ5M3nTqo+TCrCdP6vw+VSfM=
Received: from AM5PR0701CA0001.eurprd07.prod.outlook.com (2603:10a6:203:51::11) by AS8PR08MB6039.eurprd08.prod.outlook.com (2603:10a6:20b:23c::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5458.19; Thu, 28 Jul 2022 22:37:37 +0000
Received: from VE1EUR03FT005.eop-EUR03.prod.protection.outlook.com (2603:10a6:203:51:cafe::44) by AM5PR0701CA0001.outlook.office365.com (2603:10a6:203:51::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5504.7 via Frontend Transport; Thu, 28 Jul 2022 22:37:37 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com; pr=C
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT005.mail.protection.outlook.com (10.152.18.172) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5482.12 via Frontend Transport; Thu, 28 Jul 2022 22:37:36 +0000
Received: ("Tessian outbound 63c09d5d38ac:v123"); Thu, 28 Jul 2022 22:37:36 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 93c87e57e9b4404c
X-CR-MTA-TID: 64aa7808
Received: from fc90d64d95bf.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id E6515B11-CDA2-4876-8580-B8D3CFC30EB8.1; Thu, 28 Jul 2022 22:37:29 +0000
Received: from EUR04-VI1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id fc90d64d95bf.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 28 Jul 2022 22:37:29 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lQ7pHsmOtbbLg1CNz0DMxY2qcpN6RW24a+eo0UrzhjJg3s0PAb8c/7Yn2NEyURCknaEKXnQ/GFxmsZBCmf95fJZ6xnbsJFhjtFZzoz2u0PmJPRlBMrhR/Wmo1ShHl+ByZy9R/2rUZcEo+I9jZoFp4ewQxOlAvWWxG2U8x/B7fxjb+WpItE31ThVDCXg6ruztrLUq1GuAiBZZZ8ljlW1LNQwqaCOWKxLiLzUGjWRhxb9orowpJPtw13sZWLO733acmat/SQAX4A9V//e2tSxInAhgVNNBBPs8XWMfY3g9aH3BPeQG/V3ELvnU+PCgsqUSnxp3anchJAh84RExYCU0hw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=LReK+PVIDZOjOdAO0efNjc9BJVskZATUQAdfVsz0cfU=; b=J5JJ0A1VSTZIsCeHDXDPX5Ympp54ouMV58vpULIwRRFvvgs1HZ90wfO+7UpGm9JByZf3vI8jRhzXBRS0IS/rbFF7bA9a7SoLGYOE/NC5mcEwU5LlsAB+g5205n9tsuQnP1sDEfv1J+FX53Qg4FVs8KyJBWeY69ruTdWhV6m5yMhLTkAh2/gmaUY48fkoMJHt5TLmEBMqFOlqg/Q6AOgG1yhrAbMe2DQKRiCf7MSb7OUz8L7N0YLqAqd4FoyzxZbuaF1AHv6ZNittEsAqMUhMSW0hvPX/qXrmXpmo8ZzUCiGJ1+qjED4WMJmx4/ssEUFBR3dKCOqUgv/plizIkUHndg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=LReK+PVIDZOjOdAO0efNjc9BJVskZATUQAdfVsz0cfU=; b=KhPFaTgAcltjLd5FnVLLo9KWj9vKMcm2UtQPAHponfhJYc9K7rkYfynRA8dMuqiNVaPUGzeUjjRL8pkx0lcuASx1sgILpjP/etu4sPtW75P0ItKy9jJQzSJkoJa9d6a+7e3cagj8A6E38/KHk1RSQ5M3nTqo+TCrCdP6vw+VSfM=
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com (2603:10a6:10:1ae::11) by AM6PR08MB3638.eurprd08.prod.outlook.com (2603:10a6:20b:4b::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5482.11; Thu, 28 Jul 2022 22:37:21 +0000
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::f109:f88a:5672:ce59]) by DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::f109:f88a:5672:ce59%9]) with mapi id 15.20.5458.025; Thu, 28 Jul 2022 22:37:21 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: Ken Takayama <11kenterada@gmail.com>
CC: suit <suit@ietf.org>
Thread-Topic: Ordering of elements in SUIT Manifest
Thread-Index: AQHYotKZFsxsRhQDi0OI3lBrc1BUjg==
Date: Thu, 28 Jul 2022 22:37:21 +0000
Message-ID: <E29A3CBC-F330-4686-8FCF-35829AF4889C@arm.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3696.100.31)
Authentication-Results-Original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-MS-Office365-Filtering-Correlation-Id: 61db5615-aa2e-4b69-7cdd-08da70e9c52b
x-ms-traffictypediagnostic: AM6PR08MB3638:EE_|VE1EUR03FT005:EE_|AS8PR08MB6039:EE_
x-checkrecipientrouted: true
nodisclaimer: true
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: SnkyMg3D44ZlOViZ7M9v2eFp7CSB/BcPt/P5BQmzOn/yoR86gFhtKNPE9szW1/lxweOHGLxP7Y8YzzoXxTF3ffLHv8uwGMwGGcwfjmidfX979TStlS58VSSJtYIn5nT7Yj6n2Y0KBPpHOm/h2IpvpZuFWU3Pdz7jPHejEKkdk3bg692QQVnnJwDEU0IE3hvUFKoZW5lWl3ZMB+6Yr2mDCL4RkIbCjo0dJZNik0lw2gFmgxT5p+lYT+RF3ixD1vhVx0SAd2ecgQfbF+leQZPxa0swN4QaxL5pSh2RX8faZ2BBADVgd+78ss08j5BQBNp9+gV0NurhZtGWTk1yEgtbpn/5NiMaFAxEgYIqiI3ctVy3OyKJkuAtfUP3eN+G8hvS8zTFveAzGIbVkY9zesxHT28Ytg66lEXS5X6RFYFYJ1zCgFnaOcC6wFIG9HgIooxA7/jShRAr2Ccyteyf4Gos/P4/vxXllK1jnXy93nFInqvdaHEywLyMAUH/fqQPXSGvKdYdh/iPSx+wvuAQ5wv3TusZMHMY3JCkT7x6GQm2fCFIdRV5odfRGeTN4yjGkAy4FV3tyaZbeM+XcrrgotRoB173Znxe8sU+iDFhmrsqqLIbiP/KAMM0JXgr94nLE/hxEjt8Gp0P5xLMOqmu9epXVQ/pcQ6wno3O/3/SPFolynWQT2cEO3gsejaiXNw1DOp4qKm+U64C9faaD2WHHkoC6SS9RzpooLMfGaur5Ye9QnqoAfQ8Tr9cLJ8FpbWMFIGOxmLRtJI7UajIM5BCO7m3EcjWVwI3P0bZZu+9jb4jzCD+t0VTkJ13AsF7aSA+zzxe3JdisKAqfk4xJHK23OaxcA==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBAPR08MB5576.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(136003)(346002)(396003)(39860400002)(366004)(376002)(2906002)(36756003)(5660300002)(66946007)(66476007)(91956017)(8936002)(76116006)(6916009)(4326008)(66556008)(8676002)(64756008)(66446008)(55236004)(6486002)(478600001)(71200400001)(41300700001)(2616005)(26005)(6506007)(6512007)(33656002)(316002)(186003)(83380400001)(38070700005)(86362001)(122000001)(38100700002)(45980500001); DIR:OUT; SFP:1101;
Content-Type: text/plain; charset="utf-8"
Content-ID: <4D85402A2B785846815967785F06DCBD@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB3638
Original-Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT005.eop-EUR03.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: 4e8945d8-c4a3-4985-c065-08da70e9bc2f
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: VYKTU4k+z2pPaZlY4ZGEUCT5vOBhaVusn92r/+T20NcWDxJ7LhwzliiQy4/+j5KvQ2UkQ9wQJ3bk4/M4JzAqz364VBI/1TxeppjdySHmRbONZCIF7SStup5SgXjerLg18xtYbAzZXlWRVjDn8sAA0YQuJkcA7kTNxQAzHO0Qptc6TQomAyEDaImHsbYlRJONflHd6cRhoAZmEhrnigo45p63cOLrbqq0tCqFoh+5K2/rV80GZb+Pyzib4B/ZwFV16+yMaZnMBoTe1Xyx1qIMN2Njghv0KG9UC+S5fhmQDZp17nIvPp0fSwpJfcq+AFWWVqxd28vjMk580J0JqsjYTNTR0n4CGzHHrAd9PacJ/lXV5ji1GFfAfPevbey9B2Kajd1enkHcj3leAElziDCAYohUXUwPY7B4Xy+iiCrAW4OoSXWQhaGrAXF2lB+hrb0gnlaq60mqw8gCABJRV2dT4mpd9sB7dj1lCBA3hDB5AcgsMfngWWDj3G/sqNsZNlrkieepFOaDeYSWQwu7HNEqGWIrQg26wdTFF6NAkiRfA+MTkix/4cWw43xSb5OfxzI29XurABxSj3IYkZ0EexCvwQqt119Phd9Sri/gjtIXvotoK+9zJUlY+1IIK/PVk6jklgZhYpBl+D2NzQuQjcYcRrLX7Hk9vNQKRVm1KV0a6SCJEdcs+pVBlaa/E2RKNnGmgLdHoQBSUDojJaS2Q9yIITlTZ4hhpIXFJJftqhf+KdA9Q3seFjHKGBJI5UskC9AUO6emw5apnNC+NTOX93c3dja32rDmVJzwNN6HTPo9sYWDRo8tnFw96kZTUq+Ur+NS
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(13230016)(4636009)(376002)(39860400002)(136003)(346002)(396003)(40470700004)(46966006)(36840700001)(82310400005)(186003)(70206006)(81166007)(6486002)(336012)(36756003)(40460700003)(33656002)(2616005)(6862004)(47076005)(2906002)(5660300002)(8936002)(316002)(356005)(6506007)(8676002)(83380400001)(41300700001)(4326008)(86362001)(36860700001)(6512007)(478600001)(40480700001)(82740400003)(26005)(70586007); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Jul 2022 22:37:36.2749 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 61db5615-aa2e-4b69-7cdd-08da70e9c52b
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT005.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR08MB6039
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/sGFdn-nqg1DCd2txBBHN1Wky3pg>
Subject: [Suit] Ordering of elements in SUIT Manifest
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jul 2022 22:37:45 -0000

Hi Ken,

I noticed your message in the meet echo chat; unfortunately, it wasn’t repeated at the mic and I missed it during the meeting.

> Related to the order of the manifest, I'm not convinced but I think the integrated elements should be before the suit-manifest because it would be referred by suit-install or suit-dependency-resolution section.

I think it is reasonable to say that elements the recipient requires should come before the elements the recipient does not require.

I also think it is reasonable to say that severable elements should come after non-severable elements.

But these are both “should” not “must.” So I don’t hold the opinion strongly.


Now as to the location of the integrated elements, I think I have to disagree. The problem is the order of operations:

When a constrained recipient receives a manifest, the first thing it encounters is delegation chains. This allows it to work down towards the public key that is in use. Next, it finds the authentication block. By now, it has the correct public key to validate the authentication block. The authentication block allows the constrained recipient to validate a single digest. Once it has done this, it can discard the authentication block (from memory anyway). It does not need to parse the authentication block again. Having parsed the authentication block, it has the expected hash of the manifest in memory. The next step it takes is to hash the manifest to verify/authenticate it. If this passes, then it can begin executing the manifest.

The constrained recipient won’t even know it needs an integrated element until after it has completed all these steps, so I am reluctant to put them first, since this would require random-access parsing of the manifest, rather than the linear process we have up to this point.

However, I’m happy to hear other opinions!

Regardless, the manifest now encodes integrated items with string keys, so it may well be that your CBOR encoder puts those before integers?

Best Regards,
Brendan
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.