Repository navigation
docs: Define fresh-Tails handoff - #228
BenWestgate wants to merge 3 commits into
Conversation
This comment has been minimized.
This comment has been minimized.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: def702c112
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
def702c to
f209f64
Compare
This comment has been minimized.
This comment has been minimized.
f209f64 to
dde05c3
Compare
|
Reworked this onto the concise documentation stack. The PR now has one focused commit: fresh Tails, recipient-owned Persistent Storage, authenticated CipherStick software, and only explicitly selected optional data. Full Persistent Storage cloning is no longer recommended. |
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Claude), posted at the maintainer's request.
Not ACKing dde05c3: one factual error.
- "Bitcoin Core validates the copied data when it starts" is wrong. At startup Core only re-verifies the last few blocks (
-checkblocks, default 6), so achainstate/copied from a compromised node is used as-is. The removed sentence ("If you don't trust this node is not compromised, do NOT do this") was the accurate one; restore it.HANDOFF.md:15needs the same caveat. - The fresh-Tails handoff and dropping the Tails Cloner backup look right otherwise. Needs the #226 rebase too.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aca6ad50cd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
67be0b9 to
586bf83
Compare
aca6ad5 to
b8b38fe
Compare
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
b7b2d38 to
52bcf84
Compare
43e70fc to
3b531b5
Compare
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head review at 52bcf84: no findings. The handoff docs explicitly avoid whole-Persistent-Storage cloning, require authenticated software before execution, scope optional data copies path-by-path, and call out the current signed-release prerequisite.
This comment has been minimized.
This comment has been minimized.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head review, posted at the maintainer's request.
ACK 453567f. The outstanding handoff comments are addressed: recipient storage is created by normal setup, and node-data copying requires both source and destination Core shut down. Lint is green.
Replace the full-Persistent-Storage clone instructions with a recipient-owned Tails and Persistent Storage workflow. Keep optional data transfer explicit and require authenticated CipherStick software before execution. Fixes #213.
Keep the fresh-Tails handoff, but state that copied Bitcoin Core chainstate must come from a trusted node because Core does not fully revalidate it at startup.
e0c3744 to
c8b005a
Compare
453567f to
5284581
Compare
What
Replace the full-Persistent-Storage clone instructions with a short fresh-Tails handoff procedure. The recipient owns their Tails installation and Persistent Storage, while any optional data copy is an explicit choice.
Why
A whole Persistent Storage clone can transfer wallet ciphertext, configuration, logs, and identifying state. A handoff should transfer only authenticated CipherStick software plus data the person performing the handoff deliberately selects.
Closes #213
Testing
git diff --check