Skip to content

docs: Define fresh-Tails handoff - #228

Open
BenWestgate wants to merge 3 commits into
212-supported-threat-modelfrom
213-fresh-tails-handoff
Open

BenWestgate wants to merge 3 commits into
212-supported-threat-modelfrom
213-fresh-tails-handoff

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

What

Replace the full-Persistent-Storage clone instructions with a short fresh-Tails handoff procedure. The recipient owns their Tails installation and Persistent Storage, while any optional data copy is an explicit choice.

Why

A whole Persistent Storage clone can transfer wallet ciphertext, configuration, logs, and identifying state. A handoff should transfer only authenticated CipherStick software plus data the person performing the handoff deliberately selects.

Closes #213

Testing

  • git diff --check
  • verified the added local documentation links resolve

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: def702c112

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md Outdated
Comment thread docs/FAQ.md Outdated
@BenWestgate
BenWestgate force-pushed the 213-fresh-tails-handoff branch from def702c to f209f64 Compare September 21, 2026 08:33
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate
BenWestgate force-pushed the 213-fresh-tails-handoff branch from f209f64 to dde05c3 Compare September 21, 2026 08:53
@BenWestgate
BenWestgate changed the base branch from master to 212-supported-threat-model September 21, 2026 08:53
@BenWestgate

Copy link
Copy Markdown
Owner Author

Reworked this onto the concise documentation stack. The PR now has one focused commit: fresh Tails, recipient-owned Persistent Storage, authenticated CipherStick software, and only explicitly selected optional data. Full Persistent Storage cloning is no longer recommended. git diff --check passes.

@chatgpt-codex-connector

This comment has been minimized.

1 similar comment
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

Not ACKing dde05c3: one factual error.

  • "Bitcoin Core validates the copied data when it starts" is wrong. At startup Core only re-verifies the last few blocks (-checkblocks, default 6), so a chainstate/ copied from a compromised node is used as-is. The removed sentence ("If you don't trust this node is not compromised, do NOT do this") was the accurate one; restore it. HANDOFF.md:15 needs the same caveat.
  • The fresh-Tails handoff and dropping the Tails Cloner backup look right otherwise. Needs the #226 rebase too.

Comment thread docs/FAQ.md Outdated
Comment thread docs/HANDOFF.md Outdated

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review, posted at the maintainer's request.

ACK aca6ad5. The copied-chainstate trust warning is restored in both the FAQ and handoff guide; Lint CI is green. Ready for human review after its parent #227.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aca6ad50cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/HANDOFF.md Outdated
Comment thread docs/HANDOFF.md Outdated
@BenWestgate
BenWestgate force-pushed the 212-supported-threat-model branch from 67be0b9 to 586bf83 Compare September 27, 2026 00:58
@BenWestgate
BenWestgate force-pushed the 213-fresh-tails-handoff branch from aca6ad5 to b8b38fe Compare September 27, 2026 01:03
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review, posted at the maintainer's request.

ACK b8b38fe. The copied-chainstate trust caveat is restored in both guides and the fixup history is squashed cleanly. This head has the same tree that passed Lint CI before the squash. Ready for human review after #227.

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate
BenWestgate force-pushed the 213-fresh-tails-handoff branch from b7b2d38 to 52bcf84 Compare October 1, 2026 09:45
@BenWestgate
BenWestgate force-pushed the 212-supported-threat-model branch from 43e70fc to 3b531b5 Compare October 1, 2026 09:45
@chatgpt-codex-connector

This comment has been minimized.

1 similar comment
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex current-head review at 52bcf84: no findings. The handoff docs explicitly avoid whole-Persistent-Storage cloning, require authenticated software before execution, scope optional data copies path-by-path, and call out the current signed-release prerequisite.

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted current-head review, posted at the maintainer's request.

ACK 453567f. The outstanding handoff comments are addressed: recipient storage is created by normal setup, and node-data copying requires both source and destination Core shut down. Lint is green.

Replace the full-Persistent-Storage clone instructions with a recipient-owned Tails and Persistent Storage workflow. Keep optional data transfer explicit and require authenticated CipherStick software before execution.

Fixes #213.
Keep the fresh-Tails handoff, but state that copied Bitcoin Core chainstate must come from a trusted node because Core does not fully revalidate it at startup.
@BenWestgate
BenWestgate force-pushed the 212-supported-threat-model branch from e0c3744 to c8b005a Compare October 7, 2026 08:34
@BenWestgate
BenWestgate force-pushed the 213-fresh-tails-handoff branch from 453567f to 5284581 Compare October 7, 2026 08:34
@chatgpt-codex-connector

This comment has been minimized.

1 similar comment
@chatgpt-codex-connector

This comment has been minimized.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: Replace cloning with a fresh-Tails handoff workflow

1 participant