roll: third_party/pigweed pw_software_update: Document PersistManifest() expectations

Document the integration expectations and security model around
PersistManifest(). Sourcing and deciding when to trust/commit an OTA
(by persisting the manifest) is the responsibility of the client.
Explain why the reference BundledUpdateService implementations (both
nanopb and pwpb) do not automatically call PersistManifest() during
DoApply().

Original-Bug: b/523287826
Original-Reviewed-on: https://pigweed-review.googlesource.com/c/pigweed/pigweed/+/426872
Original-Revision: b7aa4f8d761e316eef9a4ec4fa42e9b21babf7a3

Rolled-Repo: https://pigweed.googlesource.com/pigweed/pigweed
Rolled-Commits: 8bc35d07baf800..b7aa4f8d761e31
Roll-Count: 1
Roller-URL: https://cr-buildbucket.appspot.com/build/8678186784663849921
GitWatcher: ignore
CQ-Do-Not-Cancel-Tryjobs: true
Change-Id: I0dd4d80e5a4ec82ae49180335d4c4c0599cc754a
Reviewed-on: https://pigweed-review.googlesource.com/c/gonk/+/427252
diff --git a/third_party/pigweed b/third_party/pigweed
index 8bc35d0..b7aa4f8 160000
--- a/third_party/pigweed
+++ b/third_party/pigweed
@@ -1 +1 @@
-Subproject commit 8bc35d07baf8000f8db57674a23c5e06f7516d79
+Subproject commit b7aa4f8d761e316eef9a4ec4fa42e9b21babf7a3