marigold-dev / marigold-dev/deku
executable only file system
Nobody has claimed this yet.
- Dominant language
- OCaml
- Stars
- 82
- Forks
- 17
- PR merge metrics
- No merged PRs in 30d
Description
A security measurement that I would love to have is allowing the sidechain node to run on a file system where the only thing readable is the initial snapshot state and the only executables are a `signer` and the `node` itself.
This would allow that any failure of the node will not compromise the keys in any possible way or anything else in a node.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by examining how the sidechain node and signer are launched and how they access the initial snapshot state. Define the required filesystem permissions and execution restrictions, then determine how the security measurement can verify that only the signer and node are executable and no other state is readable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ocaml
- Domain
- operating-systems, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100