Each step that writes to a chip, or sends a transaction, says so. Mainnet gas only after an explicit yes.
The chip inventory is local and gitignored:
chips/TRUSTM.md: the TM1–TM10 table and each chip’s detailchips/TRUSTM-LOG.md: the dated logUpdate both after every step below.
tools/fw verify says so.
ALLOW_* are False.tools/fw backup, then copy the folder
somewhere else. It holds secrets.py.Swap the chip. USB unplugged, chip in, USB back.
Start:
tools/fw ceremony start # a fresh chip
tools/fw ceremony start --unpin # a pinned chip that needs T9 (TM1)
tools/fw ceremony start --keep-open E0F2,E0F3 # if a second key per chip stays possible
yes covers the whole start. It does three things:
ALLOW_LOCK and ALLOW_GENKEYbackups/<board>/ceremony.json.On the board: PROVISION (A, or press the knob). Then each step:
| Step | What | Gate |
|---|---|---|
| T1 | read-only checks: Infineon certificate, factory key, every object as it came | — |
| T2 | make the key (E0F1) | two 3 s holds (arm, then do) |
| T3–T4 | test signatures; the factory key binds the key | — |
| T5 | the owner address: compare it with getSigner on the laptop before T6 |
— |
| T6 | write the record and binding | — |
| T7 | seal the key, record and binding. PERMANENT | two 3 s holds, and an explicit yes for this chip |
| T8 | check the seal | — |
| T9 | freeze the spares: PERMANENT, never termination | two 3 s holds, and an explicit yes for this chip |
| T10 | done | — |
A sacrificial chip goes first for anything not yet seen on silicon. T9 is the first such step.
Its results go into docs/TRUSTM.md.
Finish:
tools/fw ceremony finish
yes again. It does four things:
ALLOW_* offstart noted!! needs attention before you go on.tools/fw attest # read-only
tools/quorum verify docs/mainnet/attest/attest-<serial>.json --chain eth
tools/quorum live key --usb # this chip's key into live.json
tools/quorum live enroll --chain eth # deploys its signer proxy: about 110k gas, no funds moved
tools/quorum verify docs/mainnet/attest/attest-<serial>.json --chain eth # now "deployed"
enroll checks getSigner against the console’s own owner address before it sends.The proxy must exist before the Pico’s first confirmation. The service checks the signature
with an eth_call to it.
tools/quorum verify … --chain eth. A new chip goes on only after they
have.addOwnerWithThreshold(owner, 3) to grow,swapOwner(prev, old, owner) to replace.tools/quorum live exec --chain eth <nonce>.tools/quorum live pico --chain eth --safe <SAFE> --name "<name>" (several chains:
--chain base,eth).tools/fw verify shows the Safe as ok, owner.live exec. Record the tx link in chips/TRUSTM-LOG.md and
docs/LADDER.md.tools/fw logs copies log.txt. A “sec” rise of more than 1 on a signature is
flagged there.tools/fw push console, which backs up first and keeps secrets.py.tools/fw verify.ceremony start with a pinned mainnet chip in the board.swapOwner to a new owner, or removeOwner keeping the threshold at 3, from a
different device. Three other owners sign. Execute.chips/TRUSTM.md, with the date and the transaction.| What | Where | Secret? |
|---|---|---|
backups/<board>/<UTC>/ |
the board’s files, including secrets.py (WiFi password, API key) |
yes: keep a copy off this laptop, encrypted |
docs/mainnet/attest/ |
each chip’s ceremony record | no: commit it |
chips/TRUSTM*.md |
the inventory and log | not secret, but local |
tools/mock-tx-service/live.json |
keys, Safes, sends | no secrets; local |
The chip’s key has no backup, and can’t have one. The Safe’s other owners are the backup.