Markdown Version

Session Date/Time: 22 Jul 2026 09:30

[00:00:05] Dave Thaler: Okay.

[00:00:46] Chairperson: Hi, everyone. Welcome to the suit session. We are gonna get started. Now Aiko is not here, but she will be joining us soon, hopefully. Before we get started, we do need to find a notetaker. Anyone? Thanks, Adam.

[00:01:11] Chairperson: One more?

[00:01:13] Chairperson: We don't need one more. Okay? Look

[00:01:15] Chairperson: at this.

[00:01:15] Chairperson: Okay. So this is the Notewell. We've all seen it a few times this week already, but it's a reminder about the processes and policies that include conduct, privacy, and intellectual property rights that you agreed to to follow when you participate in the IETF. Please read it carefully, and you're encouraged to read the source document, which is in the little code there. And if you have any questions, please talk to us or the area director about that. And a reminder, can we people in person, can I get you to log in to the data tracker? Make sure that if you're gonna get up with the mic, please join the queue. Obviously, remote participants are already there. And, yeah, here's just some resource links, so our agenda.

[00:02:19] Deb Cooley: Okay.

[00:02:20] Chairperson: Yes. So we already have a minute taker, and this is the today's draft. I mean, not draft, but the agenda. Any agenda bashing? Anything else we want to talk? So we we have suit update management, and it's the main topic today, and everything else is RFC Editor queue. And okay. Then let's get to the first topic. I forgot how it was

[00:03:08] Chairperson: Do you have to take me to the back?

[00:03:09] Chairperson: Put this back again. And

[00:03:12] Deb Cooley: And then change your socks.

[00:03:33] Chairperson: Okay. Okay. This is the suit-update-management status update, Brendan.

[00:03:40] Brendan Moran: Hello.

[00:03:44] Chairperson: I've just asked you control of the slides.

[00:03:47] Brendan Moran: Thank you. This contrary to what the chairs put in, the I suppose this is the fourteenth revision rather than the thirteenth. Since there was a Telechat resolution, it seems to make sense to try and get that resolved before the actual meeting. So if you're not aware of what the update management draft is, it provides features that might be required for any kind of management of updates on the device end rather than on the host end involving authorization, timing, versioning, battery, all that sort of thing. This, as as I mentioned, is a cleanup that handles the Telechat results.

[00:04:46] Dave Thaler: So we are

[00:04:49] Brendan Moran: currently sitting at a d follow-up. This is as a result of the, Telechat, and the ballot record should shows that once we clear the discussed positions, we should be ready to go. I hope that the most recent version, 14, will, in fact, clear those discussed positions. June was the last time that we had a meeting. We had a virtual interim, and that the 13 draft was prepared for that virtual interim. 14 was the result, as I said, of the telechat. So, just as a high level, we had five different comments or five different reviews that required, addressing, and I'll go through each of those in turn. But they are largely centered around the Unicode encoding of comparison operators, a COSWID behavior development pro sorry, deployment profiles, some normative references and citations, and, that's most of the content. So first off, there was versioning in text. The versioning breaks down into requiring a semantic versioning, reference as a normative reference. The suit set version, had to have, an update because it does not carry a comparison operator. It did not sorry. It does not.

[00:06:41] Deb Cooley: The

[00:06:43] Brendan Moran: we also defined what the free text version fields allow in terms of Unicode characters. Now this I I need I hasten to add that this is not something that a manifest processor is required to validate since the manifest processor is not required to validate anything in the text section. So this is something that needs to be validated only by intermediate systems and the author. Everything else in there, of course, is free text, and we defined the five specific comparison operators that map to the comparisons that can be performed by the, version comparison, feature in the in the original manifest document. I think I think that's where it is, or is it in this one? Next, we had deployment and wait behavior. So we provided a update priority with interoperable ordering. Numerically, smaller values mean higher priority, and deployment policy assigns local meaning. So we had to define what deployment policy and deployment profiles meant. Local time weights do define time zone changes and daylight savings, repeated and skipped and repeated times. UTC events are preferred, of course, because that solves the local common time policy problem a bit better. The deployment profile, as I said, is defined, and it is defined as a specification or agreement between the author and the recipient and specifies local mappings that are left open by the protocol. This is just a definition. There is no protocol action here. The other device was previously defined as an opaque byte string. Now we add a namespace encoding and uniqueness scope, version source, and version encoding. Oh, that's sorry. That's in the profile that that's defined. We've also added a new operational section that covers access control mappings, telemetry, etcetera, etcetera for, essentially to to define how this may be relevant in terms of operational and deployment considerations. We've added, more detail on COSWID and extension handling. So the the main thing here is that if it's possible that you we have an implementation that cannot generate severable elements, it the suit COSWID can be added using the nonseverable CDDL form. In this scenario, a recipient that claims to support suit COSWID must accept a well formed COSWID even if it is not severable. Recipients can reject a malformed or or policy prohibited, COSWID, but they must accept a well formed one. Unsupported commands cause rejection, of course, but that was previously being referenced to the wrong, base manifest citation, so that's been updated. And the security text calls out the the point of COSWID in this scenario, essentially, the the inventory and vulnerability information. We also had a feedback request on, symbolic link security. So we've added an additional section that defines the, problems that can occur with symbolic links in the, in in the processing of a manifest, that there are race conditions in some scenarios and that the, they must prevent path traversal outside of acceptable areas, etcetera. We've updated a bunch of references. So RFC eighty six ten was added as the normative, CDDL reference. We've moved semantic versioning from informative to normative. CBOR's first use now cites the CBOR RFC. The IANA section identifies and links the software update for the Internet of Things suit registry properly now. We also have updated the abstract to define that this is extensions to the based and the sorry. The this document specifies extensions. We've also mentioned that the base manifest reject rejection citations point to the correct location as I I mentioned before. And, the CDDL, we've corrected a typo in CDDL and fixed the createDirAppend, typo. So as I mentioned, there were for there was some further review Telechat resolutions. Resolutions. Those have been updated. We the the latest pull request off of GitHub was merged, and the updated version has been published. And I have sent follow-up emails to all of the reviewers. So I think that we are now waiting for the reviewers to correct or to to accept the changes, and I think that's where we stand.

[00:13:01] Chairperson: Okay. Dave, you're in the queue.

[00:13:08] Dave Thaler: Hey, Brendan. So I was just trying to find the answers in the document. I had questions about the, Unicode issues that you talked about. Looks to me like the versions, both the, you know, the actual version numbers and the constraints, you know, greater than and so on, are not limited to ASCII characters. Right? It can be anything with Unicode character l among other things. Right? Yep. And so that means there can be multiple normalization forms and so on. What does greater than and less than mean when there's not a single representation of a particular character?

[00:13:43] Brendan Moran: Well, I mean answer in

[00:13:45] Dave Thaler: the document, and I think it it should unless there's some simple answer that I just missed. So

[00:13:50] Brendan Moran: Okay. I I'm I'm so here's my my frustration on this. We've already have a well defined way of comparing version numbers. Right? We embedded that directly in the soup manifest. Not in the text, in the actual manifest commands. Right? We have a set version, and we have a check version. So that's the normative answer to your question.

[00:14:18] Dave Thaler: I don't remember what it says. Can you remind me? Can like, can you have one dot zero alpha, and can you have one dot zero Greek letter alpha, and can you have one

[00:14:28] Brendan Moran: dot zero No. You can't have any of that. No. None of that's acceptable in the actual manifest. So in the actual manifest commands, what you have is you've got a sequence of integers. Right? So it's, it's an sorry. Not a sequence. An array. Specifically, an array of integers. That array is not length limited, so you can have as many as you like, and the comparison operation between those is defined exactly as compare the first two with the defined comparison operator. Compare the second two with the defined comparison operator, and you progress down that until you get a mismatch according to the comparison operator. So and that's when the command fails. That is the defined correct way of handling this.

[00:15:19] Chairperson: Okay.

[00:15:19] Brendan Moran: This is for text based display purposes. If you want to encode some kind of crazy logic into that and process it, you are outside of the spec. So this you know, e even going down the road of defining specific comparison operators was a stretch for a text field that's not meant to be processed by machines. But we've already been asked to do that, so we have. So I don't want to have to define more here. I very much prefer to stop defining additional things that don't matter.

[00:15:58] Dave Thaler: Gotcha. So just to repeat back, what you're supposed to be doing is comparing versions by comparing integer sets. Yes. And the whole notion of allowing UTF eight with Unicode general categories and things is really not helpful. At least that's my interpretation of what you said. And it would be better to remove that from the spec because it causes potential problems and maybe mismatches. Right?

[00:16:24] Brendan Moran: No. This is the problem because you have to have something to display to an operator so that the operator understands what's going on.

[00:16:31] Dave Thaler: Yes. But I didn't hear anything that would require you to do something other than ASCII in there because you can represent integers in ASCII. So just as an example. Right? I p v four and v six string literals must be displayed in ASCII. Right? There's no, like, other languages or UTF eight and so on. So you can make the same constraint for version numbers given that they have to be representable as integers. Why do we need to have UTF eight, in there for things that are just version numbers? Right?

[00:17:06] Brendan Moran: For localization reasons. Right? Because

[00:17:09] Dave Thaler: do that for IP addresses. What's the difference?

[00:17:13] Brendan Moran: You can do some IP addresses are not human readable. Sorry. I realize that we treat them that way sometimes, but they're not. Right? That's why we have domain names.

[00:17:26] Deb Cooley: They're also binary.

[00:17:27] Dave Thaler: Okay. So I think that there's two points here. Right? You have to have a way to display a version to a user that internally is represented as a sequence of integers.

[00:17:38] Brendan Moran: Yes.

[00:17:39] Dave Thaler: What I don't understand is why you need to do less than or greater than operations on strings. If you said what you're supposed to do is you're supposed to take this the the display string, find the actual integer sequence, and what you're actually doing greater than or less than or whatever on is the integer sequence, not the display string, that would be a useful way to describe it.

[00:18:01] Brendan Moran: That's exactly what I'm saying.

[00:18:04] Dave Thaler: Okay. Then in that case, I don't get that in the spec, but I may have misread it or whatever, but I think that's what should be stated. I didn't get that in there right now, but, you know, if that's the intent, then I agree with that as the intent. It says you're never supposed to do a greater than or less than or less than operation on a UTF eight string.

[00:18:24] Brendan Moran: Yes. I agree. You're never supposed to do that.

[00:18:28] Deb Cooley: K.

[00:18:28] Dave Thaler: Great. I I think you and I are saying the same thing now. Let's just make sure the draft says that. And maybe it does, maybe it doesn't, but I think we agree on the intent. So thanks.

[00:18:36] Brendan Moran: Dave, would you mind putting a comment on the list to that effect, please? Sure. Thank you.

[00:18:50] Chairperson: Perfect. No other questions in regards to this one? So I guess that right now, we'll just have to wait to see how everyone responds to the emails that you sent through, regarding the Telechat actions that were asked about. So we'll just have to give that a little bit, I

[00:19:11] Chairperson: guess. Yes. And Brendan's update was yesterday midnight. So, yeah, it won't be it's expected to be have no reply today, but yes. On the next okay.

[00:19:37] Deb Cooley: Wow. That's crazy. So so you you won't get a response today, and you won't get a response this week because they're here. And it's a meeting week, and it's ridiculous. Right? So, you will we'll I will we'll give them the week to to go to the meeting, and next week, will ping and see whether they are, happy with it. I will also look myself because, again, I haven't looked at them either. We're gonna look at both the discusses and the no objection comments. You've it looks to me like you've replied to all of them. Right?

[00:20:15] Brendan Moran: Yep.

[00:20:16] Deb Cooley: Okay. So I'll look at all of them probably at the beginning of next week because it is meeting week. And if the no objections are good, then I'll ping the discusses. Modulo Dave Teller's comments. Right? So Yeah. If you, look at that and make changes, then, you know, do that soonish because that is part of a discuss. Right?

[00:20:43] Brendan Moran: Yes.

[00:20:44] Deb Cooley: Okay. Is that Romans?

[00:20:47] Brendan Moran: I let's let me just double check so I'm not getting this wrong. Yes. It is Romans.

[00:20:56] Deb Cooley: Okay. Yeah.

[00:20:58] Brendan Moran: So do you guys you don't

[00:20:59] Deb Cooley: get him to look at it this week either. Right? So once it's

[00:21:04] Brendan Moran: It was actually also brought up by Andy Newton.

[00:21:08] Deb Cooley: Right. Okay. But, hopefully, the same thing will address both both of those.

[00:21:17] Hannes Tschofenig: Deb, a question, for you. So there's now a normative reference to the semantic versioning, specification, which is, essentially a website. Is that a problem?

[00:21:31] Deb Cooley: There's a version number for this. Right? We've done semantic versioning as normative references before. I'm trying to remember where. There is a way to do it. I I you know, as much of, you know, versions and dates that we can get our hands on, that's the way to that's generally the way to beat that. Is it here? Have you used semantic versioning some someplace else, or have we talked about it for this draft in the past?

[00:22:04] Hannes Tschofenig: I think we did. We we talked about it, but previously, it was just informative. And we only use we don't completely use it like this the previously discussed alpha annotations to to versions is something that is not sort of, like, incorporated. So it's really only the major, minor version type of concept.

[00:22:28] Chairperson: So

[00:22:30] Deb Cooley: So so it's also come up in other drafts, not not my not my drafts, not security security area, but other areas. And I I I believe there's a way to do it. I am gonna have to go back and look and see. That what you got a review that said make it normative. Right? Was that probably met? Probably met.

[00:22:53] Brendan Moran: Yes. That's correct.

[00:22:55] Deb Cooley: Right. So we'll look. Is he thing to look at is whether he's actually correct or not.

[00:23:04] Brendan Moran: When RFC ninety three ninety three, defined a reference to Semver, it was informative.

[00:23:15] Deb Cooley: Yeah. But it has come up recently for another draft.

[00:23:19] Hannes Tschofenig: I when I looked at it, I I thought that it would be just easier to describe the basic things from that document in in the draft, but, probably it it, in in the end, like, if it if this works out fine, then

[00:23:34] Deb Cooley: Otherwise, we'll have to figure out a way to

[00:23:35] Dave Thaler: make it a. Yeah.

[00:23:38] Deb Cooley: There are ways. Which nine three six two? What? The CDL that defines an in semver or min nine three nine three. But that's a form. No. It, like, defines it as CDL. What does that mean? It's a formal specification of the thing.

[00:23:59] Hannes Tschofenig: Mikey Richardson is saying that, there's a document that defines, semantic versions as part of CDDL in some document, which I hadn't known about previously.

[00:24:10] Brendan Moran: Was that also RFC ninety three ninety three?

[00:24:12] Chairperson: I was gonna say it was the one that you just mentioned before.

[00:24:16] Brendan Moran: So should we then pivot this slightly and take a normative reference to ninety three ninety three, which I think we already have since it's COSWID instead?

[00:24:29] Deb Cooley: So you had a comment to make it normative.

[00:24:32] Brendan Moran: Yeah.

[00:24:33] Deb Cooley: We made it normative. Yep. The change to this can be done in the editor's queue.

[00:24:41] Brendan Moran: Okay.

[00:24:42] Deb Cooley: So the editor if the editor will object to it being normative a normative reference, then we will have to change it.

[00:24:49] Brendan Moran: Alright.

[00:24:50] Deb Cooley: At this point, you've not got you don't have a comment from the IESG about it being an issue as a normative reference. In fact, you have a comment from the IESG saying that you need to make it a normative reference. Yep. I will do a little bit of asking around the the back to make sure like, I can go back and ask who who did who who did this recently as a normative reference and make sure we do it right. Yeah. Or it can be changed later if there's an option. I I don't know. I mean, there's it's a little bit of a, you know, hard place to be in. But I will ask Okay. And we'll know.

[00:25:42] Hannes Tschofenig: Okay.

[00:25:51] Chairperson: And there was a message comment from Dave Tauter on the chat. The manifest process the draft was updated that the manifest process processor does not consume this version. It is human readability only. Yes. And he he's fine with that.

[00:26:20] Brendan Moran: Oh, okay. So does that mean that we are good already?

[00:26:29] Dave Thaler: This is Dave. I've just been looking over the text. I think we're good already, meaning I think your response to Roman and so on does resolve it. I'm just rereading it to make sure I don't spot anything else. But, if you don't hear from me, assume if I don't post anything to the list in the next twenty four hours, assume that I agree that your response is good and, that Andy's and Roman's responses are are have been resolved. So

[00:26:52] Brendan Moran: Great. Thank you.

[00:27:00] Chairperson: Anything else? K.

[00:27:32] Brendan Moran: Okay. So this is just a, quick update on where we are, today as it stands. I I normally leave this one to Hannes, but, he so he can speak to it if he'd like. But I think that the, the the the overall here is that there's nothing to say. I think this one is, essentially in the editor's queue. It's done. We're just waiting for everything to go through now. I see Hannah's nodding. Excellent. Okay. The suit manifest, we did have to post a an update to this. There were a couple of changes that came through, but there's been nothing since our, since our update, for the June interim. We are waiting for update management, of course, as you are aware, and, hopefully, that will, open the cluster shortly. Same thing with suit MTI. It's done. It's in the editor's queue, and every you know, we're gonna have a lot of saying this is waiting for, update management because that's the status of every single draft. So, there have been no changes since the June 19. Suit Mud, same deal. That one's pretty old. There's been no changes. Suit report has had some updates. So that one is a little bit different. There were some some reviews from Ken that needed to be, accounted for, and we discussed them at the June interim. And I published an update that incorporated Ken's commentary, and I published that, I think, actually, just the the next couple of days after the June interim. So that one is done, hopefully now. Suit trust domains, again, has not had any recent updates. And suit update management, it did have the, an update just before, the June interim, then a a follow-up, from review on the, seventh or eighth of July or sorry, on the July 3 to to get it ready for the Telechat. The then the Telechat happened, which resulted in the, reviews that we discussed. There were a couple of discusses, which we have already addressed, and that is now waiting for, an update. And that is it. That is the status of all of the drafts we have pending.

[00:30:40] Deb Cooley: So I just did a quick check of my email, and we have the editor has queried about the suit report updates, and I have approved them. So as far as the editor is concerned, they're looking at version 22.

[00:30:53] Brendan Moran: Excellent. Thank you for that.

[00:31:00] Deb Cooley: That's the only one. Right? Manifest was done a while ago?

[00:31:03] Brendan Moran: Yeah. If I look back, it's I've got the dates in here. So manifest was posted on the June 18.

[00:31:16] Deb Cooley: That's not a long time ago.

[00:31:18] Brendan Moran: I mean

[00:31:18] Chairperson: I think

[00:31:19] Brendan Moran: that But we had those requests for changes come in.

[00:31:23] Deb Cooley: So I must have I I mean, I can go back and look at my email again and see. But, for the most part, if you make a change to the draft while it's sitting in the editor's queue, the first thing that happens is they ping me and say, yo. Is this okay?

[00:31:37] Brendan Moran: Yep.

[00:31:37] Deb Cooley: So I'm I'm I have to go back and look. But mostly, I say yes if it's something I know about, which Right. A report I knew, and I'm sure it manifest probably too. So that Manifest is Manifest is still Romans. Right? So Yeah. There is a chance that it goes back to Roman, and not to me. Just depends. Right? He has I believe as mud, I think.

[00:32:03] Brendan Moran: I believe these updates were discussed at the June interim. So that that should have been something that we already discussed and minuted.

[00:32:11] Dave Thaler: Yeah. Well,

[00:32:26] Chairperson: It's Dave. I see your comment on the chat. So

[00:32:47] Dave Thaler: I'm just going back to the mic since, you were commenting. I don't know if you, have time on the agenda or not, but I had just finished rereading the, update management update text here, and so I can comment on that. But if you want to go on, that's okay. But if you want to take a minute, then I'm happy to.

[00:33:05] Chairperson: Go for it.

[00:33:06] Dave Thaler: Okay. After rereading it three times, I think the intent is clear. The only thing that confused me and why it took me three times is, the document seems a little bit inconsistent in an editorial sense that I hope the RFC editor could fix up, which is sometimes it uses the term capitalized, manifest author, sometimes it uses the term lowercase manifest author, and sometimes it uses the term the author. If all of those were exactly the same, like always capitalized manifest author and all uses of author was changed to capital manifest author, then I think I wouldn't have had been confused to begin with. And so thinking that, oh, well, maybe manifest author and capitalized and the author could be different was what led me down a a wrong path. And so I think that's just an editorial tweak, which I wasn't gonna bring up here. But if we got an extra minute, then that was my comment. So I think other than, maybe that editorial fix, think the text is fine.

[00:34:08] Chairperson: Hannes?

[00:34:09] Hannes Tschofenig: Yeah. I was just checking the changes on the suit manifest. They were really minor. I think those were came from Ken or Kun, actually. Actually, it was Kun who did another implementation of the suit manifest parser for their new IoT operating system in Rust type of thing. And the changes were obviously, the the the references are updated, but there was just a a clarification on the on the use of a specific field. So that's, like, certainly no normative change. And the the other thing was in the in the in the CDDL, we made a typo, and so that was corrected. So the version really, really small updates from the 2015 version, May 2015 to the, to the current version. So at least that's, how I see the diff.

[00:35:15] Deb Cooley: I don't see a query from the editor to

[00:35:17] Chairperson: me. Okay.

[00:35:19] Deb Cooley: So I don't know whether it went to Roman, and he can't hear me. So what

[00:35:26] Chairperson: you didn't hear, Brendan, was Deb saying that she doesn't have a query in regards to the manifest, and so when she's not sure if it went to Roman.

[00:35:35] Brendan Moran: Okay.

[00:35:36] Deb Cooley: And I'll check.

[00:35:38] Chairperson: She is gonna check that.

[00:35:40] Brendan Moran: Thank you.

[00:35:52] Chairperson: Anything else today? Mhmm. Okay. Then thank you. We're going to finish the session, and, hopefully, we'll be the last update will be in RFC edit queue. Yes. Thank you.

[00:36:14] Brendan Moran: Thanks, everyone.