security(qsfs): read owner mnemonic from MNEMONIC env, not a hard-cod… - #125
Merged
Conversation
…ed const
The qsfs dev script embedded a real sr25519 mnemonic as a package const. Replace it with
`os.Getenv("MNEMONIC")` and fail fast if unset, so no key ships in the source tree. Rotate
the previously-committed key.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Enables an ops team to relocate a Grade-1 VM using COUNCIL authority instead of the owner's private key, while the deployment keeps its original owner twin. The node's chain check already establishes authority: engine.validate() requires the on-chain contract to name THIS node and its deployment_hash to equal the deployment's ChallengeHash — and only the council can set those via migrate_node_contract. So for the migration RMB path we accept a council member (or the owner) as the caller and drop the owner-signature re-check: - substrate gateway: GetCouncilMembers() (raw Council.Members storage read) + interface + regenerated zbus stub. - zos_api deployment handlers (transfer / prepare / start): resolve the owner twin from the on-chain contract (or the deployment), authorize the RMB caller as the owner OR a current council member, and run the per-owner storage ops under the owner twin. - provision engine PrepareDeployment: no owner-signature Verify (unlike CreateOrUpdate) — validate()'s node+hash check is the authority for a migration. Normal deployment create/update is unchanged (still owner-signed). zos_api_light needs the same change before council-driven moves work on zos-light nodes (follow-up). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… (get) Fast-path the owner's own deployment.get (unchanged, no chain lookup); on a miss, resolve the owner from the on-chain contract and authorize the caller as owner-or-council, so an ops caller can inspect a deployment it does not own while driving a keyless migration. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Mirror the council-driven migration change into zos_api_light: transfer/prepare/start/get resolve the owner from the on-chain contract and authorize the RMB caller as owner-or-council (GetCouncilMembers), so ops can migrate a VM on a zos-light node without the owner's key. The provision engine's PrepareDeployment (shared) already skips the owner signature on this path. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ashraffouda
requested review from
Eslam-Nawara,
Omarabdul3ziz,
rawdaGastan and
xmonader
as code owners
August 26, 2026 12:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…ed const
The qsfs dev script embedded a real sr25519 mnemonic as a package const. Replace it with
os.Getenv("MNEMONIC")and fail fast if unset, so no key ships in the source tree. Rotatethe previously-committed key.
Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com### Description
Describe the changes introduced by this PR and what does it affect
Changes
List of changes this PR includes
Related Issues
List of related issues
Checklist