Skip to content

docs: add TezFin resilient oracle security specification - #461

Open
KevinMehrabi wants to merge 1 commit into
mainfrom
codex/oracle-security-spec
Open

docs: add TezFin resilient oracle security specification#461
KevinMehrabi wants to merge 1 commit into
mainfrom
codex/oracle-security-spec

Conversation

@KevinMehrabi

Copy link
Copy Markdown
Contributor

Summary

Adds the consolidated TezFin Resilient Oracle security architecture and engineering acceptance specification.

This document converts the previous oracle discussions and reviews into a normative implementation baseline. In particular, it requires:

  • a production 3-of-4 threshold signer configuration;
  • two independently implemented validator classes;
  • permissionless relaying and fully domain-separated signed payloads;
  • market-observation timestamps and replay protection;
  • delayed activation of newly accepted prices;
  • independent failure isolation for core, USDtz, and tzBTC feeds;
  • delayed risk-increasing governance changes;
  • final-configuration shadow operation and an independent human security audit.

The one-publisher design remains permitted only for testnet and non-authoritative shadow operation.

Relationship to existing plans

Where this specification conflicts with the earlier OraclePlan or OracleCexOnlyPlan, this specification controls. The existing plans remain useful as implementation inventories and cost estimates.

Review requested

Please respond with:

  1. requirements accepted as written;
  2. proposed deviations and their security rationale;
  3. the design for both independent validator classes;
  4. canonical payload and packing test vectors;
  5. staged implementation and operating-cost estimates;
  6. any SmartPy, Michelson, or operation-size limitation supported by a reproducible test.

This is an implementation baseline, not approval to deploy or activate production markets.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant