marigold-dev / marigold-dev/deku

executable only file system

Open
#62 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

backlog
Dominant language
OCaml
Stars
82
Forks
17
PR merge metrics
No merged PRs in 30d

Description

A security measurement that I would love to have is allowing the sidechain node to run on a file system where the only thing readable is the initial snapshot state and the only executables are a `signer` and the `node` itself.

This would allow that any failure of the node will not compromise the keys in any possible way or anything else in a node.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by examining how the sidechain node and signer are launched and how they access the initial snapshot state. Define the required filesystem permissions and execution restrictions, then determine how the security measurement can verify that only the signer and node are executable and no other state is readable.

Written by the indexing model from the issue text.

Assessment

Tech stack
ocaml
Domain
operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.