You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add docs/developer/reviewing.md with the exact base and pre-handoff integration commits, scope, review order, PR stack, evidence-regeneration commands, and intentional exclusions.
Replace the inherited Bitcoin Core boilerplate and dead links in CONTRIBUTING.md.
Mark the alignment benchmark as a snapshot of commit 6802d86; separate historical measurements from current verification, and identify the committed host-specific raw benchmark files as historical evidence rather than reproducible current measurements.
Correct the documented package-level public API count. Current reviewability-v1 actually exports 24 names while docs/developer/api.md still says 25; after wallet: Privatize Core descriptor records #64 removes the obsolete public core_descriptors export, the frozen v1 package __all__ should contain 23 names. api: Expose reference-vector helpers #53 adds supported reference-vector helpers at their owning modules and deliberately does not add them to package-level codex32.__all__.
Update the stale GUI budget in docs/developer/api.md to the separately enforced <2050 logical-line limit. The maintainer explicitly approved gui: Refresh empty wallets automatically #66's GUI-specific increase on 2026-09-30; this is separate from the library <5200 limit.
Document the Core boundary precisely: ms32 secret and ms32 share require Bitcoin Core for fingerprint-aware recovery/output; ms32 correct connects to Core when a master-seed correction needs fingerprint ranking/output, while valid/no-result paths may finish before that connection. The corresponding generic codex32 secret / share / correct commands are the Core-independent fallback.
Record the deliberate mid-recovery secret behavior: if the operator supplies a complete valid S while entering shares, recovery stops using the partial share set and deliberately switches to that supplied secret. PR cli: Announce recovery secret switch #95 makes that mode switch explicit to the operator; it belongs in the frozen library/CLI candidate before the handoff.
Record the deliberate parser divergence for an unshared secret with threshold digit 1: v1 remains stricter than the BIP-93 reference decoder and accepts only the project's documented unshared/shared header forms. State this explicitly so interoperability reviewers do not mistake the difference for an untracked parser bug.
Point reviewers to the existing installed-package and GUI size-budget tests. The v1 installed-package cap is the maintainer-authorized <5200; do not take a pre-release refactor solely to recover the old <5000 target.
Record the deliberate v1 exception for mixed-case correction scheduling: the public correction engine and standalone CLI retain parallel orchestration through v1 because their search-planning contracts differ (CorrectionContext generic reachable lengths versus ms32 --bytes/profile/tie-break behavior). Both paths use the same required-before-optional ordering and capture-accounting contract and are covered by focused regressions plus the frozen differential verifier. Centralizing them is post-v1 architecture work; do not take a pre-release refactor solely to remove roughly 100 lines.
The final fresh adversarial review must cover the GUI as well as the library and CLI, with manual GUI test steps recorded for behavior that CI cannot exercise.
Link the guide from the final human-authored PR description, which must pin the complete candidate commit or commits. Human integration may squash/rewrite stacked AI-assisted follow-ups where the repository authorship policy requires it, after dependency order is settled.
Human integration order
Use this order to avoid repeatedly invalidating reviewed stacks:
Only after those tips are frozen, open the focused handoff-document PR required by this issue and pin the exact candidate commits.
Run final artifact qualification and a fresh adversarial review over the frozen library, CLI, GUI, and user-facing recovery documentation before any human-authored master integration.
Keep planning notes out of the shipped documentation. This handoff is intentionally the last documentation change, after the implementation, packaging, security, GUI, and user-facing documentation integration stacks are settled; opening its PR earlier would make the required commit identifiers stale.
Before freezing the v1 review candidate:
docs/developer/reviewing.mdwith the exact base and pre-handoff integration commits, scope, review order, PR stack, evidence-regeneration commands, and intentional exclusions.CONTRIBUTING.md.6802d86; separate historical measurements from current verification, and identify the committed host-specific raw benchmark files as historical evidence rather than reproducible current measurements.reviewability-v1actually exports 24 names whiledocs/developer/api.mdstill says 25; after wallet: Privatize Core descriptor records #64 removes the obsolete publiccore_descriptorsexport, the frozen v1 package__all__should contain 23 names. api: Expose reference-vector helpers #53 adds supported reference-vector helpers at their owning modules and deliberately does not add them to package-levelcodex32.__all__.docs/developer/api.mdto the separately enforced<2050logical-line limit. The maintainer explicitly approved gui: Refresh empty wallets automatically #66's GUI-specific increase on 2026-09-30; this is separate from the library<5200limit.ms32 secretandms32 sharerequire Bitcoin Core for fingerprint-aware recovery/output;ms32 correctconnects to Core when a master-seed correction needs fingerprint ranking/output, while valid/no-result paths may finish before that connection. The corresponding genericcodex32 secret/share/correctcommands are the Core-independent fallback.Swhile entering shares, recovery stops using the partial share set and deliberately switches to that supplied secret. PR cli: Announce recovery secret switch #95 makes that mode switch explicit to the operator; it belongs in the frozen library/CLI candidate before the handoff.1: v1 remains stricter than the BIP-93 reference decoder and accepts only the project's documented unshared/shared header forms. State this explicitly so interoperability reviewers do not mistake the difference for an untracked parser bug.<5200; do not take a pre-release refactor solely to recover the old<5000target.CorrectionContextgeneric reachable lengths versusms32 --bytes/profile/tie-break behavior). Both paths use the same required-before-optional ordering and capture-accounting contract and are covered by focused regressions plus the frozen differential verifier. Centralizing them is post-v1 architecture work; do not take a pre-release refactor solely to remove roughly 100 lines.ms32 create --existingwallet-record decision before any new share ceremony, cli: Remove unreachable recovery and search paths #105's final unreachable-path cleanup (the patch-identical replacement for historical cli: Remove unreachable recovery and search paths #98), and cli: Announce recovery secret switch #95's explicit mid-recovery secret-switch notice. The GUI candidate must include gui: Add optional graphical interface #65 plus gui: Refresh empty wallets automatically #66, Tails field-test PR gui: Apply Tails field-test feedback #77 (closing gui: Keep card-count choices neutral #71–gui: Fit the finished wallet identity on one screen #74), gui: Let the home window choose its height #78 (closing gui: Size the home window to its content #75), and the reviewed restore-authentication behavior. gui: Refresh empty wallets automatically #66's automatic wallet refresh must preserve an explicit selection when possible, disable Continue if that wallet disappears, retry transient read-only refresh failures, and allow read-only poll workers to end with the process while mutation/relocking workers remain non-daemon. gui: Apply Tails field-test feedback #77/gui: Let the home window choose its height #78 still require the supported Tails guest-resolution visual checks before the candidate is frozen. gui: Give home actions distinct artwork #76 is explicitly deferred until that Tails visual pass identifies which already-distinct bundled book graphics are being confused; do not guess an asset replacement from source filenames alone.Human integration order
Use this order to avoid repeatedly invalidating reviewed stacks:
reviewability-v1.<5200cap without another line-saving patch. wallet: Distinguish unavailable Bails checks #80's two reviewed patch-ids and wallet: Check existing seed before sharing #81's five reviewed patch-ids are unchanged. cli: Announce recovery secret switch #95 then makes the already-intended behavior explicit when a complete valid secret replaces a partial share-recovery session. Rerun the identity-mismatch regression, wallet: Distinguish unavailable Bails checks #80 no-record/identifier regressions, wallet: Check existing seed before sharing #81 early-gate regressions, cli: Remove unreachable recovery and search paths #98 correction/CLI regressions, cli: Announce recovery secret switch #95 recovery-mode-switch regression, the real-Core fixture, and the final full suite on the resolved tip. cli: Remove unreachable recovery and search paths #105/wallet: Distinguish unavailable Bails checks #80/wallet: Check existing seed before sharing #81/cli: Announce recovery secret switch #95 are agent-authored follow-ups and require the repository's responsible-human rewrite/squash policy before integration._bitcoin_core.pyimport-record hunk. Where two overlap, preserve the already-reviewed behavior and perform only the mechanical restack needed by the moved base.codex32.__all__should contain 23 names; api: Expose reference-vector helpers #53's module-level helper publication does not change that count. Rewrite/squash its Codex-authored follow-up under the responsible human author before merge.Keep planning notes out of the shipped documentation. This handoff is intentionally the last documentation change, after the implementation, packaging, security, GUI, and user-facing documentation integration stacks are settled; opening its PR earlier would make the required commit identifiers stale.
Refs #5.