Skip to content

docs: revert threat model for node (#24465) - #24610

Merged
spalladino merged 2 commits into
merge-train/spartan-v5from
cb/revert-threat-model-doc
Jul 8, 2026
Merged

docs: revert threat model for node (#24465)#24610
spalladino merged 2 commits into
merge-train/spartan-v5from
cb/revert-threat-model-doc

Conversation

@AztecBot

@AztecBot AztecBot commented Jul 8, 2026

Copy link
Copy Markdown
Collaborator

Removes yarn-project/THREAT_MODEL.md, added in #24465.

@AztecBot AztecBot added ci-draft Run CI on draft PRs. claudebox Owned by claudebox. it can push to this PR. labels Jul 8, 2026
@spalladino spalladino changed the title Revert "docs: threat model for node (#24465)" docs: revert threat model for node (#24465) Jul 8, 2026
Restores yarn-project/p2p/README.md, yarn-project/p2p/src/services/reqresp/README.md,
and yarn-project/slasher/README.md to their post-#24465 state. Per feedback, the revert
should only remove the threat model doc itself, not the incidental doc cleanups
(stale BLOCK protocol references, missing DUPLICATE_ATTESTATION entry) bundled into
the same squashed commit.
@spalladino
spalladino marked this pull request as ready for review July 8, 2026 18:00
@spalladino
spalladino enabled auto-merge (squash) July 8, 2026 18:00
@spalladino
spalladino merged commit 4d02692 into merge-train/spartan-v5 Jul 8, 2026
24 checks passed
@spalladino
spalladino deleted the cb/revert-threat-model-doc branch July 8, 2026 18:01
PhilWindle pushed a commit that referenced this pull request Jul 21, 2026
Removes `yarn-project/THREAT_MODEL.md`, added in
[#24465](#24465).

Per discussion in #team-alpha: detailed threat models and invariants may
make it easier for attackers to find bugs, so the team wants this
content pulled from the public repo for now. It will be re-added to
LabsBox/ClaudeBox (private/internal) — see
[claudebox#1357](AztecProtocol/claudebox#1357) —
and can come back here once the team is finding fewer bugs.

Only the threat model doc itself is removed here — the incidental doc
cleanups bundled into the same squashed commit (stale BLOCK protocol
references in `yarn-project/p2p/README.md` and
`yarn-project/p2p/src/services/reqresp/README.md`, and the missing
`DUPLICATE_ATTESTATION` entry in `yarn-project/slasher/README.md`) are
kept as-is.

(cherry picked from commit 4d02692)
PhilWindle pushed a commit that referenced this pull request Jul 21, 2026
Removes `yarn-project/THREAT_MODEL.md`, added in
[#24465](#24465).

Per discussion in #team-alpha: detailed threat models and invariants may
make it easier for attackers to find bugs, so the team wants this
content pulled from the public repo for now. It will be re-added to
LabsBox/ClaudeBox (private/internal) — see
[claudebox#1357](AztecProtocol/claudebox#1357) —
and can come back here once the team is finding fewer bugs.

Only the threat model doc itself is removed here — the incidental doc
cleanups bundled into the same squashed commit (stale BLOCK protocol
references in `yarn-project/p2p/README.md` and
`yarn-project/p2p/src/services/reqresp/README.md`, and the missing
`DUPLICATE_ATTESTATION` entry in `yarn-project/slasher/README.md`) are
kept as-is.

(cherry picked from commit 4d02692)
rangozd pushed a commit to rangozd/aztec-packages that referenced this pull request Aug 5, 2026
…ol#24610)

Removes `yarn-project/THREAT_MODEL.md`, added in
[AztecProtocol#24465](AztecProtocol#24465).

Per discussion in #team-alpha: detailed threat models and invariants may
make it easier for attackers to find bugs, so the team wants this
content pulled from the public repo for now. It will be re-added to
LabsBox/ClaudeBox (private/internal) — see
[claudebox#1357](AztecProtocol/claudebox#1357) —
and can come back here once the team is finding fewer bugs.

Only the threat model doc itself is removed here — the incidental doc
cleanups bundled into the same squashed commit (stale BLOCK protocol
references in `yarn-project/p2p/README.md` and
`yarn-project/p2p/src/services/reqresp/README.md`, and the missing
`DUPLICATE_ATTESTATION` entry in `yarn-project/slasher/README.md`) are
kept as-is.

(cherry picked from commit 4d02692)
rangozd pushed a commit to rangozd/aztec-packages that referenced this pull request Aug 5, 2026
…Protocol#24934)

Forward-ports the small **cli / bot / docs** commits of the v5-next →
next backlog, plus an owner checklist for the spartan-config and
standard-contract-repin commits (both need an explicit v6 decision — see
below).

## Applied (clean cherry-picks, chronological)
- perf(bot): parallelize independent bot factory setup steps (AztecProtocol#24581)
- docs: revert threat model for node (AztecProtocol#24465) (AztecProtocol#24610)
- feat(cli): support funding accounts in validator-keys
new/set-funding-account (AztecProtocol#24476)

## ⚠️ Needs owner conflict-resolution (conflict against reshaped `next`;
not included here)
Cherry-pick onto this branch and resolve:
- [x] `git cherry-pick -x 38202d9` — chore(spartan): restore 7 day
mainnet slash grace period (AztecProtocol#24804)
- [x] `git cherry-pick -x c3a2a85` — chore: re-pin handshake registry
with owner-bound nullifiers (AztecProtocol#24893)

Part of the manual v5-next → next backlog sweep. Draft until conflicts
are resolved and CI is green.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-draft Run CI on draft PRs. claudebox Owned by claudebox. it can push to this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants