Joystream / Joystream/joystream

Leader storage state protection

Open
#2,866 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

mainnet_review runtime
Dominant language
Rust
Stars
1.4k
Forks
116
PR merge metrics
No merged PRs in 30d

Description

I think we need a careful examination of how well we are protecting storage state from abuse from leads, this means both in working group module, but more importantly, also in the different subsystem modules. I suspect there are attacks vectors here, and simply relying, or hoping to rely on, stake is not ideal if avoidable without substantial inconvenience.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by examining the working group module and then the different subsystem modules for how leader-controlled storage state is validated and protected. Identify concrete abuse or attack vectors and document the affected flows before proposing changes. Done means the relevant storage-state protections are understood and any avoidable leader abuse paths are addressed without substantial inconvenience.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
blockchain, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
18/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.