pico-quorum

Operator runbook: a Trust M from the bag to a mainnet Safe owner

Each step that writes to a chip, or sends a transaction, says so. Mainnet gas only after an explicit yes.

The chip inventory is local and gitignored:

Update both after every step below.

0. Before you start

1. The ceremony (on the device)

Swap the chip. USB unplugged, chip in, USB back.

Start:

tools/fw ceremony start                 # a fresh chip
tools/fw ceremony start --unpin         # a pinned chip that needs T9 (TM1)
tools/fw ceremony start --keep-open E0F2,E0F3   # if a second key per chip stays possible

On the board: PROVISION (A, or press the knob). Then each step:

Step What Gate
T1 read-only checks: Infineon certificate, factory key, every object as it came —
T2 make the key (E0F1) two 3 s holds (arm, then do)
T3–T4 test signatures; the factory key binds the key —
T5 the owner address: compare it with getSigner on the laptop before T6 —
T6 write the record and binding —
T7 seal the key, record and binding. PERMANENT two 3 s holds, and an explicit yes for this chip
T8 check the seal —
T9 freeze the spares: PERMANENT, never termination two 3 s holds, and an explicit yes for this chip
T10 done —

A sacrificial chip goes first for anything not yet seen on silicon. T9 is the first such step. Its results go into docs/TRUSTM.md.

Finish:

tools/fw ceremony finish

2. The ceremony record

tools/fw attest                                            # read-only
tools/quorum verify docs/mainnet/attest/attest-<serial>.json --chain eth

3. Enroll on Ethereum (gas: say yes first)

tools/quorum live key --usb                 # this chip's key into live.json
tools/quorum live enroll --chain eth        # deploys its signer proxy: about 110k gas, no funds moved
tools/quorum verify docs/mainnet/attest/attest-<serial>.json --chain eth    # now "deployed"

The proxy must exist before the Pico’s first confirmation. The service checks the signature with an eth_call to it.

4. Become an owner

  1. Every co-signer runs tools/quorum verify … --chain eth. A new chip goes on only after they have.
  2. Propose in the Safe web app:
    • addOwnerWithThreshold(owner, 3) to grow,
    • or swapOwner(prev, old, owner) to replace.
  3. The current owners sign. If a contract signature is on it, execute with tools/quorum live exec --chain eth <nonce>.
  4. Point the console at the Safe: tools/quorum live pico --chain eth --safe <SAFE> --name "<name>" (several chains: --chain base,eth).
  5. Check the console: tools/fw verify shows the Safe as ok, owner.

5. The first approval

6. Running it

7. Lost, stolen, compromised, or out of your hands

  1. Tell the co-signers at once, by voice. Point them to COSIGNERS.md section 4.
  2. Propose swapOwner to a new owner, or removeOwner keeping the threshold at 3, from a different device. Three other owners sign. Execute.
  3. Mark the chip retired in chips/TRUSTM.md, with the date and the transaction.
  4. Never reuse a retired chip as an owner. Its sealed key can’t be replaced.

8. Backups and records

What Where Secret?
backups/<board>/<UTC>/ the board’s files, including secrets.py (WiFi password, API key) yes: keep a copy off this laptop, encrypted
docs/mainnet/attest/ each chip’s ceremony record no: commit it
chips/TRUSTM*.md the inventory and log not secret, but local
tools/mock-tx-service/live.json keys, Safes, sends no secrets; local

The chip’s key has no backup, and can’t have one. The Safe’s other owners are the backup.