Markdown Version | Transcript | Session Recording | Session Materials
SUIT IETF 126 Meeting Minutes
Summary
The Software Updates for Internet of Things (SUIT) Working Group met at IETF 126 to discuss the status of its draft portfolio. The primary focus of the session was resolving the remaining Telechat DISCUSS positions on draft-ietf-suit-update-management. The working group also reviewed the status of other documents currently in the RFC Editor's queue or waiting on the publication of the update management specification.
Adam volunteered as the notetaker for the session.
Key Discussion Points
1. Welcome and Administration
The Chairperson opened the session and presented the SUIT Chair slide, highlighting the IETF Note Well guidelines, session resources, and the agenda. There were no requests for agenda bashing.
2. SUIT Update Management Status Update
Brendan Moran presented the suit-update-management status update covering the changes introduced in draft-ietf-suit-update-management-14 to resolve Telechat reviews.
-
Key Changes in Version 14:
- Versioning in Text: Defined semantic versioning as a normative reference. Clarified that the manifest processor does not validate or consume the free-text version fields; they are purely for intermediate systems and human readability. Defined five comparison operators mapping to version comparisons in the original manifest.
- Deployment and Wait Behavior: Defined update priority with an interoperable numerical ordering (smaller values denote higher priority) and local deployment policy mappings. Added definitions for timezone changes/daylight savings in local time weights, while preferring UTC events. Introduced a "deployment profile" definition for author-recipient specifications.
- COSWID and Extension Handling: Enabled the addition of
suit-COSWIDusing a non-severable CDDL form if severable elements cannot be generated. Well-formed COSWIDs must be accepted by recipients claiming COSWID support, though malformed or policy-prohibited COSWIDs can be rejected. - Symbolic Link Security: Added a dedicated section detailing path traversal prevention and race conditions associated with symbolic links.
- References and CDDL Fixes: Added RFC 8610 as a normative reference for CDDL. Corrected a CDDL typo (
createDirAppend).
-
Technical Discussion:
- Unicode and String Comparison: Dave Thaler raised questions regarding how comparison operators (like greater than or less than) apply to version strings that contain Unicode. Brendan Moran clarified that normative version comparison is performed using integer arrays embedded directly in manifest commands (
set-versionandcheck-version). Dave Thaler and Brendan Moran agreed that the manifest processor should never perform string-based mathematical comparisons (e.g., greater than/less than) on UTF-8 text; rather, the text fields are purely for display. - Normative SemVer Reference: Hannes Tschofenig asked Deb Cooley (AD) about the suitability of referencing the semantic versioning website (semver.org) normatively. Michael Richardson and Henk Birkholz noted in the session chat that RFC 9393 (COSWID) already contains an informative reference to semantic versioning. Michael Richardson highlighted that semantic versioning is also defined as part of CDDL in existing RFCs. Brendan Moran suggested that the document could pivot to normatively reference RFC 9393 instead of the SemVer website. Deb Cooley indicated that this reference alignment could be finalized in the RFC Editor's queue.
- Editorial Improvements: Dave Thaler noted that the draft inconsistently uses capitalized "Manifest Author", lowercase "manifest author", and "the author". To avoid confusion, he recommended unifying these terms as capitalized "Manifest Author" via an editorial pass.
- Unicode and String Comparison: Dave Thaler raised questions regarding how comparison operators (like greater than or less than) apply to version strings that contain Unicode. Brendan Moran clarified that normative version comparison is performed using integer arrays embedded directly in manifest commands (
3. Multiple Draft Status Update
Brendan Moran presented the Multiple-draft-status slide deck to review the status of the rest of the SUIT specifications:
- draft-ietf-suit-manifest: An update was posted following the June interim to address minor feedback from Rust parser implementation testing (by Kun) and correct a CDDL typo. It is currently waiting on the resolution of draft-ietf-suit-update-management.
- draft-ietf-suit-mti: Currently in the RFC Editor's queue.
- draft-ietf-suit-mud: No changes; waiting on draft-ietf-suit-update-management.
- draft-ietf-suit-report: Updated to incorporate review comments from Ken/Kun. Deb Cooley confirmed that version 22 has been approved by the Area Director and is with the RFC Editor.
- draft-ietf-suit-trust-domains: No recent updates; waiting on the update management draft.
Decisions and Action Items
- Action Item: Dave Thaler to post a brief comment to the SUIT mailing list summarizing the agreed-upon intent that string-based greater/less comparisons must not be executed on the UTF-8 text version fields.
- Action Item: Deb Cooley to reach out to the Telechat reviewers (specifically Roman Danyliw and Andy Newton) during the week after IETF 126 to confirm if version 14 successfully resolves their DISCUSS and comment positions on draft-ietf-suit-update-management.
- Action Item: Deb Cooley to check the RFC Editor's queue to determine if the query regarding draft-ietf-suit-manifest was routed to Roman Danyliw.
Next Steps
- Await reviewer verification of draft-ietf-suit-update-management-14 to clear the remaining Telechat DISCUSS positions.
- Advance the dependent SUIT draft cluster (draft-ietf-suit-manifest, draft-ietf-suit-mud, and draft-ietf-suit-trust-domains) in the RFC Editor's queue once draft-ietf-suit-update-management is formally approved.
Related Documents
draft-ietf-suit-manifest, draft-ietf-suit-mti, draft-ietf-suit-mud, draft-ietf-suit-report, draft-ietf-suit-trust-domains, draft-ietf-suit-update-management, draft-ietf-suit-update-management-14, draft-status, draft-status-00