Skip to content

Implement signed A/B updates and graphical rollback #9

Description

@55515-code

Goal

Implement TUF-authorized updates into an inactive boot slot with health commit, automatic fallback, and graphical rollback.

Acceptance criteria

  • Transport cannot authorize installation.
  • Interrupted download/stage, invalid metadata, disk-full, failed boot, and failed health check are fault-tested.
  • Last-known-good rollback and recovery UI work without a terminal.
  • Stable promotion remains human and threshold gated.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    architectureRequires architecture or RFC reviewsecurityPublic security hardening work only

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions