ms32 secret shows the master fingerprint along with the recovered secret. ms32 share never shows it. It doesn't appear while confirming a correction to an input, with the derived share, or when the secret itself is one of the inputs.
Show it once the threshold of input strings has been accepted, whether every input is a share or one of them is the secret. The operator can then compare it with the wallet record before writing a new card for the set.
This doesn't change #57's rule that ms32 wallet and ms32 create --existing keep the recovered fingerprint hidden until the operator types the recorded one.
In the code, _share_command in cli.py calls _emit(derived, plain) without a fingerprint. _confirm_correction previews the fingerprint only when basis is false, and share never passes false.
ms32 secretshows the master fingerprint along with the recovered secret.ms32 sharenever shows it. It doesn't appear while confirming a correction to an input, with the derived share, or when the secret itself is one of the inputs.Show it once the threshold of input strings has been accepted, whether every input is a share or one of them is the secret. The operator can then compare it with the wallet record before writing a new card for the set.
This doesn't change #57's rule that
ms32 walletandms32 create --existingkeep the recovered fingerprint hidden until the operator types the recorded one.In the code,
_share_commandincli.pycalls_emit(derived, plain)without a fingerprint._confirm_correctionpreviews the fingerprint only whenbasisis false, andsharenever passes false.