From 85fe944fbf79b8ea5c345b4824c72bc1bf705ab4 Mon Sep 17 00:00:00 2001 From: Codex Date: Sun, 4 Oct 2026 01:59:56 -0500 Subject: [PATCH 1/8] docs: Replace contributor boilerplate Give contributors the actual editable dev install and CI checks, link the local security and AI policies, and remove inherited Bitcoin Core instructions that name nonexistent paths and workflows. This makes the documented on-ramp match the now-dependency-free test suite. Refs #38. --- CONTRIBUTING.md | 385 ++++++++---------------------------------------- 1 file changed, 58 insertions(+), 327 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 5e94775..8b83115 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -1,337 +1,68 @@ -Contributing -============================ +# Contributing to python-codex32 -This project operates an open contributor model where anyone is welcome to -contribute towards development in the form of peer review, testing and patches. -This document explains the practical process and guidelines for contributing. +Review, testing, documentation, and focused patches are welcome. This project +handles Bitcoin recovery material, so use synthetic, unfunded examples in tests, +issues, and pull requests. Read [SECURITY.md](SECURITY.md) before working on a +security-sensitive path; report vulnerabilities privately as directed there. -Getting Started ---------------- +Contributors using AI tools must read the [AI policy](docs/developer/AI_POLICY.md). +A responsible human must understand, test, and explain a proposed change. The +[developer API guide](docs/developer/api.md) describes supported surfaces and +the review order; the [user guide](docs/user/guide.md) describes the operator +contract. -New contributors are very welcome and needed. +## Set up a development environment -If you use AI tools while contributing, please read and follow the [AI -policy](/doc/AI_POLICY.md). - -In-depth reviewing and testing are the bottleneck of the project, and are the -most effective way anyone can start to contribute. It will teach you much more -about the code and process than opening pull requests, and may help you uncover -related issues and follow-ups to contribute code for. Please refer to the [peer -review](#peer-review) section below. - -Before you start contributing, familiarize yourself with the build system and -tests. Refer to the documentation in the repository on how to build the project -and how to run the unit tests, functional tests, and fuzz tests. - -Communication Channels ----------------------- - -Discussion about codebase improvements happens in GitHub issues and pull -requests. - -Contributor Workflow --------------------- - -The codebase is maintained using the "contributor workflow" where everyone -without exception contributes patch proposals using "pull requests" (PRs). This -facilitates social contribution, easy testing and peer review. - -Pull request authors must fully and confidently understand their own changes -and must have tested them. You should mention which tests cover your changes, -or include the manual steps you used to confirm the change. -You are expected to be prepared to clearly motivate and explain your changes. -If there is doubt, the pull request may be closed. -Please refer to the [peer review](#peer-review) section below for more details. - -To contribute a patch, the workflow is as follows: - - 1. Fork repository ([only for the first time](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/fork-a-repo)) - 1. Create topic branch - 1. Commit patches - -The master branch for all monotree repositories is identical. - -The project coding conventions in the [developer notes](doc/developer-notes.md) -must be followed. - -### Committing Patches - -In general, [commits should be atomic](https://en.wikipedia.org/wiki/Atomic_commit#Atomic_commit_convention) -and diffs should be easy to read. For this reason, do not mix any formatting -fixes or code moves with actual code changes. - -Make sure each individual commit is hygienic: that it builds successfully on its -own without warnings, errors, regressions, or test failures. -See the [developer notes](doc/developer-notes.md#commit-structure-for-tests) -for guidance on where test coverage belongs in a commit stack. - -Commit messages should be verbose by default consisting of a short subject line -(50 chars max), a blank line and detailed explanatory text as separate -paragraph(s), unless the title alone is self-explanatory (like "Correct typo -in init.cpp") in which case a single title line is sufficient. Commit messages should be -helpful to people reading your code in the future, so explain the reasoning for -your decisions. Further explanation [here](https://cbea.ms/git-commit/). - -If a particular commit references another issue, please add the reference. For -example: `refs #1234` or `fixes #4321`. Using the `fixes` or `closes` keywords -will cause the corresponding issue to be closed when the pull request is merged. - -Commit messages should never contain any `@` mentions (usernames prefixed with "@"). - -Please refer to the [Git manual](https://git-scm.com/doc) for more information -about Git. - - - Push changes to your fork - - Create pull request - -### Creating the Pull Request - -The title of the pull request should be prefixed by the component or area that -the pull request affects. - -The body of the pull request should contain sufficient description of *what* the -patch does, and even more importantly, *why*, with justification and reasoning. -You should include references to any discussions (for example, other issues or -mailing list discussions). - -The description for a new pull request should not contain any `@` mentions. The -PR description will be included in the commit message when the PR is merged and -any users mentioned in the description will be annoyingly notified each time a -fork copies the merge. Instead, make any username mentions in a subsequent -comment to the PR. - -### Work in Progress Changes and Requests for Comments - -If a pull request is not to be considered for merging (yet), please -prefix the title with [WIP] or use [Tasks Lists](https://docs.github.com/en/get-started/writing-on-github/getting-started-with-writing-and-formatting-on-github/basic-writing-and-formatting-syntax#task-lists) -in the body of the pull request to indicate tasks are pending. - -### Address Feedback - -At this stage, one should expect comments and review from other contributors. You -can add more commits to your pull request by committing them locally and pushing -to your fork. - -You are expected to reply to any review comments before your pull request is -merged. You may update the code or reject the feedback if you do not agree with -it, but you should express so in a reply. If there is outstanding feedback and -you are not actively working on it, your pull request may be closed. - -Please refer to the [peer review](#peer-review) section below for more details. - -### Squashing Commits - -If your pull request contains fixup commits (commits that change the same line of code repeatedly) or too fine-grained -commits, you may be asked to [squash](https://git-scm.com/docs/git-rebase#_interactive_mode) your commits -before it will be reviewed. The basic squashing workflow is shown below. - - git checkout your_branch_name - git rebase -i HEAD~n - # n is normally the number of commits in the pull request. - # Set commits (except the one in the first line) from 'pick' to 'squash', save and quit. - # On the next screen, edit/refine commit messages. - # Save and quit. - git push -f # (force push to GitHub) - -Please update the resulting commit message, if needed. It should read as a -coherent message. In most cases, this means not just listing the interim -commits. - -If your change contains a merge commit, the above workflow may not work and you -will need to remove the merge commit first. See the next section for details on -how to rebase. - -Please refrain from creating several pull requests for the same change. -Use the pull request that is already open (or was created earlier) to amend -changes. This preserves the discussion and review that happened earlier for -the respective change set. - -The length of time required for peer review is unpredictable and will vary from -pull request to pull request. - -### Rebasing Changes - -When a pull request conflicts with the target branch, you may be asked to rebase it on top of the current target branch. - - git fetch # Fetch the latest upstream commit - git rebase FETCH_HEAD # Rebuild commits on top of the new base - -This project aims to have a clean git history, where code changes are only made in non-merge commits. This simplifies -auditability because merge commits can be assumed to not contain arbitrary code changes. Merge commits should be signed, -and the resulting git tree hash must be deterministic and reproducible. The script in -[/contrib/verify-commits](/contrib/verify-commits) checks that. - -After a rebase, reviewers are encouraged to sign off on the force push. This should be relatively straightforward with -the `git range-diff` tool explained in the [productivity -notes](/doc/productivity.md#diff-the-diffs-with-git-range-diff). To avoid needless review churn, maintainers will -generally merge pull requests that received the most review attention first. - -Pull Request Philosophy ------------------------ - -Patchsets should always be focused. For example, a pull request could add a -feature, fix a bug, or refactor code; but not a mixture. Please also avoid super -pull requests which attempt to do too much, are overly large, or overly complex -as this makes review difficult. - - -### Features - -When adding a new feature, thought must be given to the long term technical debt -and maintenance that feature may require after inclusion. Before proposing a new -feature that will require maintenance, please consider if you are willing to -maintain it (including bug fixing). If features get orphaned with no maintainer -in the future, they may be removed by the Repository Maintainer. - - -### Refactoring - -Refactoring is a necessary part of any software project's evolution. The -following guidelines cover refactoring pull requests for the project. - -There are three categories of refactoring: code-only moves, code style fixes, and -code refactoring. In general, refactoring pull requests should not mix these -three kinds of activities in order to make refactoring pull requests easy to -review and uncontroversial. In all cases, refactoring PRs must not change the -behaviour of code within the pull request (bugs must be preserved as is). - -Project maintainers aim for a quick turnaround on refactoring pull requests, so -where possible keep them short, uncomplex and easy to verify. - -Pull requests that refactor the code should not be made by new contributors. It -requires a certain level of experience to know where the code belongs to and to -understand the full ramification (including rebase effort of open pull requests). - -Trivial pull requests or pull requests that refactor the code with no clear -benefits may be immediately closed by the maintainers to reduce unnecessary -workload on reviewing. - - -"Decision Making" Process -------------------------- - -The following applies to code changes to the project (and related -projects). - -Whether a pull request is merged rests with the project merge maintainers. - -Maintainers will take into consideration if a patch is in line with the general -principles of the project; meets the minimum standards for inclusion; and will -judge the general consensus of contributors. - -In general, all pull requests must: - - - Have a clear use case, fix a demonstrable bug or serve the greater good of - the project (for example refactoring for modularisation); - - Be well peer-reviewed; - - Have unit tests, functional tests, and fuzz tests, where appropriate; - - Follow code style guidelines (doc/developer-notes.md, [functional tests](test/functional/README.md)); - - Not break the existing test suite; - - Where bugs are fixed, where possible, there should be unit tests - demonstrating the bug and also proving the fix. This helps prevent regression. - - Change relevant comments and documentation when behaviour of code changes. - -### Peer Review - -Anyone may participate in peer review which is expressed by comments in the pull -request. Typically reviewers will review the code for obvious errors, as well as -test out the patch set and opine on the technical merits of the patch. Project -maintainers take into account the peer review when determining if there is -consensus to merge a pull request. - -Code review is a burdensome but important part of the development process, and -as such, certain types of pull requests are rejected. In general, if the -**improvements** do not warrant the **review effort** required, the PR has a -high chance of being rejected. It is up to the PR author to convince the -reviewers that the changes warrant the review effort, and if reviewers are -"Concept NACK'ing" the PR, the author may need to present arguments and/or do -research backing their suggested changes. - -Moreover, if there is reasonable doubt that the pull request author does not -fully understand the changes they are submitting themselves, or if it becomes -clear that they have not tested the changes on a basic level themselves, the -pull request may be closed immediately. - -#### Conceptual Review - -A review can be a conceptual review, where the reviewer leaves a comment - * `Concept (N)ACK`, meaning "I do (not) agree with the general goal of this pull - request", - * `Approach (N)ACK`, meaning `Concept ACK`, but "I do (not) agree with the - approach of this change". - -A `NACK` needs to include a rationale why the change is not worthwhile. -NACKs without accompanying reasoning may be disregarded. - -#### Code Review - -After conceptual agreement on the change, code review can be provided. A review -begins with `ACK BRANCH_COMMIT`, where `BRANCH_COMMIT` is the top of the PR -branch, followed by a description of how the reviewer did the review. The -following language is used within pull request comments: - - - "I have tested the code", involving change-specific manual testing in - addition to running the unit, functional, or fuzz tests, and in case it is - not obvious how the manual testing was done, it should be described; - - "I have not tested the code, but I have reviewed it and it looks - OK, I agree it can be merged"; - - A "nit" refers to a trivial, often non-blocking issue. - -Project maintainers reserve the right to weigh the opinions of peer reviewers -using common sense judgement and may also weigh based on merit. Reviewers that -have demonstrated a deeper commitment and understanding of the project over time -or who have clear domain expertise may naturally have more weight, as one would -expect in all walks of life. - -### Finding Reviewers - -As most reviewers are themselves developers with their own projects, the review -process can be quite lengthy, and some amount of patience is required. If you find -that you've been waiting for a pull request to be given attention for several -months, there may be a number of reasons for this, some of which you can do something -about: - - - It may be because of a feature freeze due to an upcoming release. During this time, - only bug fixes are taken into consideration. If your pull request is a new feature, - it will not be prioritized until after the release. Wait for the release. - - It may be because the changes you are suggesting do not appeal to people. Rather than - nits and critique, which require effort and means they care enough to spend time on your - contribution, thundering silence is a good sign of widespread (mild) dislike of a given change - (because people don't assume *others* won't actually like the proposal). Don't take - that personally, though! Instead, take another critical look at what you are suggesting - and see if it: changes too much, is too broad, doesn't adhere to the - [developer notes](doc/developer-notes.md), is dangerous or insecure, is messily written, etc. - Identify and address any of the issues you find. Then ask if someone could give - their opinion on the concept itself. - - Remember that the best thing you can do while waiting is give review to others! - - -Backporting ------------ - -Security and bug fixes can be backported from `master` to release -branches. -Maintainers will do backports in batches and -use the proper `Needs backport (...)` labels -when needed (the original author does not need to worry about it). - -A backport should contain the following metadata in the commit body: +Use Python 3.10 through 3.15. From the repository root: -``` -Github-Pull: # -Rebased-From: +```sh +python -m venv .venv +source .venv/bin/activate +python -m pip install -e '.[dev]' +python -m pip check +python -m pytest -q ``` -Have a look at [an example backport PR]( -https://github.com/bitcoin/bitcoin/pull/16189). +On Windows, activate with `.venv\Scripts\activate` instead. The `.[dev]` +extra installs the test and development tools; it does not add a Python +secp256k1 or `bip32` dependency. If the suite cannot collect after these steps, +include the Python version and full error in the report. -Also see the [backport.py script]( -https://github.com/bitcoin-core/bitcoin-maintainer-tools#backport). +CI also runs the following checks on its selected jobs: -Copyright ---------- +```sh +python -O -m pytest -q +python tools/verify_correction_constants.py +python -m mypy src/codex32 +python -m ruff check . +python -m ruff format --check . +python tools/differential_correction.py --verify +``` -By contributing to this repository, you agree to license your work under the -MIT license unless specified otherwise in `contrib/debian/copyright` or at -the top of the file itself. Any work contributed where you are not the original -author must contain its license header with the original author(s) and source. +For changes to Bitcoin Core wallet behavior, run the focused Core fixture +workflow as well; see `.github/workflows/bitcoin-core-fixtures.yml` for the +pinned binary and invocation. Do not use funded wallets for testing. + +## Propose a change + +Open an issue for a behavior or design question before writing a broad patch. +Keep a PR focused, explain both what changed and why, link related issues, and +state which tests and manual checks you ran. Include a regression test for a +bug when practical. Avoid mixing mechanical moves or formatting changes with +behavior changes. Update the affected user or developer documentation when a +contract changes. + +Use a component-prefixed PR title. Make each commit understandable on its own; +write a short subject and, for nontrivial changes, a body explaining the +reasoning and referencing the issue. Do not put `@` mentions in commit messages +or the PR description. Follow the [AI policy](docs/developer/AI_POLICY.md) for +authorship and disclosure. + +Reviewers may leave conceptual objections, code findings, or small nits. Reply +to each substantive review point, either with a tested change or a concrete +reason for retaining the design. If you change a reviewed commit, say what +changed and rerun the relevant checks. Do not repeatedly request automated +reviews when a quota or non-blocking stylistic disagreement is the only issue. + +The maintainer decides integration and release timing. A PR that targets a +release-integration branch is not itself a request to merge into `master`. From 8787bda114452cb22f3a113d2d3ac1ee187d286e Mon Sep 17 00:00:00 2001 From: Codex Date: Sun, 4 Oct 2026 04:17:49 -0500 Subject: [PATCH 2/8] docs: Restore contribution license terms Keep the concise contributor guide while retaining the original licensing and third-party attribution obligations. Point contributors to the actual LICENSE and LICENSES paths rather than the obsolete Bitcoin Core packaging path. refs #38 --- CONTRIBUTING.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8b83115..c84e15b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -66,3 +66,10 @@ reviews when a quota or non-blocking stylistic disagreement is the only issue. The maintainer decides integration and release timing. A PR that targets a release-integration branch is not itself a request to merge into `master`. + +## Licensing and attribution + +By contributing, you agree to license your original work under the project's +[MIT license](LICENSE), unless a file states otherwise. If you contribute work +you did not create, preserve its license notice, original authors, and source. +Third-party notices shipped with this project are in [LICENSES](LICENSES/). From b4bc3646da241cafa753a9c049540a856eb028ee Mon Sep 17 00:00:00 2001 From: Ben Westgate Date: Sun, 4 Oct 2026 14:55:15 -0500 Subject: [PATCH 3/8] docs: Document review budgets Record the maintainer-authorized v1 library and GUI review-size caps in the contributor-facing policy. Budget changes require explicit review plus matching documentation and enforcement, and should not trigger unrelated pre-release refactors.\n\nRefs #38. --- CONTRIBUTING.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index c84e15b..a375f93 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -52,6 +52,12 @@ bug when practical. Avoid mixing mechanical moves or formatting changes with behavior changes. Update the affected user or developer documentation when a contract changes. +For v1, keep the installed library below 5,200 logical review lines. GUI work +uses a separate 2,250-line budget once it is part of the candidate. Changing +either budget requires explicit maintainer review and authorization together +with matching documentation and enforcement; do not take unrelated refactors +solely to create line-count headroom. + Use a component-prefixed PR title. Make each commit understandable on its own; write a short subject and, for nontrivial changes, a body explaining the reasoning and referencing the issue. Do not put `@` mentions in commit messages From 2e947b12f38da38289a233d31c6093a4a9742281 Mon Sep 17 00:00:00 2001 From: Ben Westgate Date: Mon, 5 Oct 2026 00:27:10 -0500 Subject: [PATCH 4/8] docs: Clarify Windows venv activation --- CONTRIBUTING.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a375f93..483718e 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -23,10 +23,11 @@ python -m pip check python -m pytest -q ``` -On Windows, activate with `.venv\Scripts\activate` instead. The `.[dev]` -extra installs the test and development tools; it does not add a Python -secp256k1 or `bip32` dependency. If the suite cannot collect after these steps, -include the Python version and full error in the report. +On Windows, activate with `.\.venv\Scripts\Activate.ps1` in PowerShell or +`.venv\Scripts\activate.bat` in Command Prompt. The `.[dev]` extra installs the +test and development tools; it does not add a Python secp256k1 or `bip32` +dependency. If the suite cannot collect after these steps, include the Python +version and full error in the report. CI also runs the following checks on its selected jobs: From d093165c56641b686cd963d8abd032671caeee44 Mon Sep 17 00:00:00 2001 From: Codex Date: Mon, 5 Oct 2026 04:27:41 -0500 Subject: [PATCH 5/8] docs: Address contributor review feedback Restore the concise open-contributor introduction, keep security reporting guidance near the change-proposal workflow, and remove the obsolete bip32 dependency callout. Preserve the maintainer-authorized v1 review budgets. Refs #38. --- CONTRIBUTING.md | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 483718e..45f2232 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -1,9 +1,8 @@ # Contributing to python-codex32 -Review, testing, documentation, and focused patches are welcome. This project -handles Bitcoin recovery material, so use synthetic, unfunded examples in tests, -issues, and pull requests. Read [SECURITY.md](SECURITY.md) before working on a -security-sensitive path; report vulnerabilities privately as directed there. +This project operates an open contributor model where anyone is welcome to +contribute towards development in the form of peer review, testing and patches. +This document explains the practical process and guidelines for contributing. Contributors using AI tools must read the [AI policy](docs/developer/AI_POLICY.md). A responsible human must understand, test, and explain a proposed change. The @@ -25,9 +24,8 @@ python -m pytest -q On Windows, activate with `.\.venv\Scripts\Activate.ps1` in PowerShell or `.venv\Scripts\activate.bat` in Command Prompt. The `.[dev]` extra installs the -test and development tools; it does not add a Python secp256k1 or `bip32` -dependency. If the suite cannot collect after these steps, include the Python -version and full error in the report. +test and development tools. If the suite cannot collect after these steps, +include the Python version and full error in the report. CI also runs the following checks on its selected jobs: @@ -53,6 +51,9 @@ bug when practical. Avoid mixing mechanical moves or formatting changes with behavior changes. Update the affected user or developer documentation when a contract changes. +For security-sensitive work, follow [SECURITY.md](SECURITY.md), including its +private-reporting and synthetic-test-material requirements. + For v1, keep the installed library below 5,200 logical review lines. GUI work uses a separate 2,250-line budget once it is part of the candidate. Changing either budget requires explicit maintainer review and authorization together From dcb5d47eb243edf127a30f01b4f6424a4589e6c0 Mon Sep 17 00:00:00 2001 From: Codex Date: Mon, 5 Oct 2026 04:32:41 -0500 Subject: [PATCH 6/8] docs: Fix Windows pip quoting Use double quotes for the editable development extra so the same setup command works in POSIX shells, PowerShell, and Command Prompt. Refs #38. --- CONTRIBUTING.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 45f2232..9a3d710 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -17,7 +17,7 @@ Use Python 3.10 through 3.15. From the repository root: ```sh python -m venv .venv source .venv/bin/activate -python -m pip install -e '.[dev]' +python -m pip install -e ".[dev]" python -m pip check python -m pytest -q ``` From 3c13060cd83b33cf0a734bd59a27c63041c6c851 Mon Sep 17 00:00:00 2001 From: Ben Westgate Date: Mon, 5 Oct 2026 14:51:17 -0500 Subject: [PATCH 7/8] docs: Restore contributor workflow structure Keep the Bitcoin Core contributor guide structure and review philosophy while adapting only the setup, test, security, API, and review-budget details that differ for python-codex32. This addresses maintainer review on #115 without losing the documented .[dev] setup or project-specific release constraints. Refs #38 --- CONTRIBUTING.md | 391 +++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 337 insertions(+), 54 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 9a3d710..3703078 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -1,83 +1,366 @@ -# Contributing to python-codex32 +Contributing +============================ This project operates an open contributor model where anyone is welcome to contribute towards development in the form of peer review, testing and patches. This document explains the practical process and guidelines for contributing. -Contributors using AI tools must read the [AI policy](docs/developer/AI_POLICY.md). -A responsible human must understand, test, and explain a proposed change. The -[developer API guide](docs/developer/api.md) describes supported surfaces and -the review order; the [user guide](docs/user/guide.md) describes the operator -contract. +Getting Started +--------------- -## Set up a development environment +New contributors are very welcome and needed. -Use Python 3.10 through 3.15. From the repository root: +If you use AI tools while contributing, please read and follow the [AI +policy](docs/developer/AI_POLICY.md). -```sh -python -m venv .venv -source .venv/bin/activate -python -m pip install -e ".[dev]" -python -m pip check -python -m pytest -q -``` +In-depth reviewing and testing are the bottleneck of the project, and are the +most effective way anyone can start to contribute. It will teach you much more +about the code and process than opening pull requests, and may help you uncover +related issues and follow-ups to contribute code for. Please refer to the [peer +review](#peer-review) section below. + +Before you start contributing, familiarize yourself with the [developer API +guide](docs/developer/api.md), [security model](docs/security/model.md), and +[user guide](docs/user/guide.md). + +The supported development setup uses Python 3.10 through 3.15. From the +repository root: + + python -m venv .venv + source .venv/bin/activate + python -m pip install -e ".[dev]" + python -m pip check + python -m pytest -q On Windows, activate with `.\.venv\Scripts\Activate.ps1` in PowerShell or `.venv\Scripts\activate.bat` in Command Prompt. The `.[dev]` extra installs the test and development tools. If the suite cannot collect after these steps, include the Python version and full error in the report. -CI also runs the following checks on its selected jobs: +CI also runs these checks on selected jobs: -```sh -python -O -m pytest -q -python tools/verify_correction_constants.py -python -m mypy src/codex32 -python -m ruff check . -python -m ruff format --check . -python tools/differential_correction.py --verify -``` + python -O -m pytest -q + python tools/verify_correction_constants.py + python -m mypy src/codex32 + python -m ruff check . + python -m ruff format --check . + python tools/differential_correction.py --verify For changes to Bitcoin Core wallet behavior, run the focused Core fixture workflow as well; see `.github/workflows/bitcoin-core-fixtures.yml` for the pinned binary and invocation. Do not use funded wallets for testing. -## Propose a change +Communication Channels +---------------------- + +Discussion about codebase improvements happens in GitHub issues and pull +requests. + +Contributor Workflow +-------------------- + +The codebase is maintained using the "contributor workflow" where everyone +without exception contributes patch proposals using "pull requests" (PRs). This +facilitates social contribution, easy testing and peer review. + +Pull request authors must fully and confidently understand their own changes +and must have tested them. You should mention which tests cover your changes, +or include the manual steps you used to confirm the change. +You are expected to be prepared to clearly motivate and explain your changes. +If there is doubt, the pull request may be closed. +Please refer to the [peer review](#peer-review) section below for more details. + +To contribute a patch, the workflow is as follows: + + 1. Fork repository ([only for the first time](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/fork-a-repo)) + 1. Create topic branch + 1. Commit patches + +The supported API and review boundaries in the [developer API +guide](docs/developer/api.md) must be followed. Security-sensitive changes must +also follow [SECURITY.md](SECURITY.md), including its private-reporting and +synthetic-test-material requirements. + +For v1, the installed library must remain below 5,200 logical review lines. GUI +work uses a separate 2,250-line budget once it is part of the candidate. +Changing either budget requires explicit maintainer review and authorization, +together with matching documentation and enforcement. Do not take unrelated +refactors solely to create line-count headroom. + +### Committing Patches + +In general, [commits should be atomic](https://en.wikipedia.org/wiki/Atomic_commit#Atomic_commit_convention) +and diffs should be easy to read. For this reason, do not mix any formatting +fixes or code moves with actual code changes. + +Make sure each individual commit is hygienic: that it builds successfully on its +own without warnings, errors, regressions, or test failures. + +Commit messages should be verbose by default consisting of a short subject line +(50 chars max), a blank line and detailed explanatory text as separate +paragraph(s), unless the title alone is self-explanatory (like "Correct typo") +in which case a single title line is sufficient. Commit messages should be +helpful to people reading your code in the future, so explain the reasoning for +your decisions. Further explanation [here](https://cbea.ms/git-commit/). + +If a particular commit references another issue, please add the reference. For +example: `refs #1234` or `fixes #4321`. Using the `fixes` or `closes` keywords +will cause the corresponding issue to be closed when the pull request is merged. + +Commit messages should never contain any `@` mentions (usernames prefixed with "@"). + +Please refer to the [Git manual](https://git-scm.com/doc) for more information +about Git. + + - Push changes to your fork + - Create pull request + +### Creating the Pull Request + +The title of the pull request should be prefixed by the component or area that +the pull request affects. + +The body of the pull request should contain sufficient description of *what* the +patch does, and even more importantly, *why*, with justification and reasoning. +You should include references to any discussions (for example, other issues or +mailing list discussions). + +The description for a new pull request should not contain any `@` mentions. The +PR description will be included in the commit message when the PR is merged and +any users mentioned in the description will be annoyingly notified each time a +fork copies the merge. Instead, make any username mentions in a subsequent +comment to the PR. + +State which automated checks and manual tests you ran. Where a bug is fixed, +include a regression test when practical. Update the affected user or developer +documentation when a contract changes. + +### Work in Progress Changes and Requests for Comments + +If a pull request is not to be considered for merging (yet), please +prefix the title with [WIP] or use [Tasks Lists](https://docs.github.com/en/get-started/writing-on-github/getting-started-with-writing-and-formatting-on-github/basic-writing-syntax#task-lists) +in the body of the pull request to indicate tasks are pending. A draft pull +request is also appropriate for changes that are not ready for review. + +### Address Feedback + +At this stage, one should expect comments and review from other contributors. You +can add more commits to your pull request by committing them locally and pushing +to your fork. + +You are expected to reply to any review comments before your pull request is +merged. You may update the code or reject the feedback if you do not agree with +it, but you should express so in a reply. If there is outstanding feedback and +you are not actively working on it, your pull request may be closed. + +If you change a reviewed commit, say what changed and rerun the relevant checks. +Do not repeatedly request automated reviews when a quota limit or a non-blocking +stylistic disagreement is the only remaining issue. + +Please refer to the [peer review](#peer-review) section below for more details. + +### Squashing Commits + +If your pull request contains fixup commits (commits that change the same line of code repeatedly) or too fine-grained +commits, you may be asked to [squash](https://git-scm.com/docs/git-rebase#_interactive_mode) your commits +before it will be reviewed. The basic squashing workflow is shown below. + + git checkout your_branch_name + git rebase -i HEAD~n + # n is normally the number of commits in the pull request. + # Set commits (except the one in the first line) from 'pick' to 'squash', save and quit. + # On the next screen, edit/refine commit messages. + # Save and quit. + git push --force-with-lease # (force push to GitHub, refusing to clobber + # commits you have not fetched) + +Please update the resulting commit message, if needed. It should read as a +coherent message. In most cases, this means not just listing the interim +commits. + +If your change contains a merge commit, the above workflow may not work and you +will need to remove the merge commit first. See the next section for details on +how to rebase. + +Please refrain from creating several pull requests for the same change. +Use the pull request that is already open (or was created earlier) to amend +changes. This preserves the discussion and review that happened earlier for +the respective change set. -Open an issue for a behavior or design question before writing a broad patch. -Keep a PR focused, explain both what changed and why, link related issues, and -state which tests and manual checks you ran. Include a regression test for a -bug when practical. Avoid mixing mechanical moves or formatting changes with -behavior changes. Update the affected user or developer documentation when a -contract changes. +The length of time required for peer review is unpredictable and will vary from +pull request to pull request. -For security-sensitive work, follow [SECURITY.md](SECURITY.md), including its -private-reporting and synthetic-test-material requirements. +### Rebasing Changes -For v1, keep the installed library below 5,200 logical review lines. GUI work -uses a separate 2,250-line budget once it is part of the candidate. Changing -either budget requires explicit maintainer review and authorization together -with matching documentation and enforcement; do not take unrelated refactors -solely to create line-count headroom. +When a pull request conflicts with the target branch, you may be asked to rebase it on top of the current target branch. -Use a component-prefixed PR title. Make each commit understandable on its own; -write a short subject and, for nontrivial changes, a body explaining the -reasoning and referencing the issue. Do not put `@` mentions in commit messages -or the PR description. Follow the [AI policy](docs/developer/AI_POLICY.md) for -authorship and disclosure. +If you cloned your fork normally, configure the project repository once: -Reviewers may leave conceptual objections, code findings, or small nits. Reply -to each substantive review point, either with a tested change or a concrete -reason for retaining the design. If you change a reviewed commit, say what -changed and rerun the relevant checks. Do not repeatedly request automated -reviews when a quota or non-blocking stylistic disagreement is the only issue. + git remote add upstream https://github.com/BenWestgate/python-codex32.git -The maintainer decides integration and release timing. A PR that targets a -release-integration branch is not itself a request to merge into `master`. +Then fetch and rebase onto the current target branch: -## Licensing and attribution + git fetch upstream + git rebase FETCH_HEAD + git push --force-with-lease + +This project aims to have a clean git history, where code changes are only made +in non-merge commits. This simplifies auditability because merge commits can be +assumed not to contain arbitrary code changes. + +After a rebase, reviewers are encouraged to sign off on the force push. This +should be relatively straightforward with `git range-diff`. To avoid needless +review churn, maintainers will generally merge pull requests that received the +most review attention first. + +Pull Request Philosophy +----------------------- + +Patchsets should always be focused. For example, a pull request could add a +feature, fix a bug, or refactor code; but not a mixture. Please also avoid super +pull requests which attempt to do too much, are overly large, or overly complex +as this makes review difficult. + +### Features + +When adding a new feature, thought must be given to the long term technical debt +and maintenance that feature may require after inclusion. Before proposing a new +feature that will require maintenance, please consider if you are willing to +maintain it (including bug fixing). If features get orphaned with no maintainer +in the future, they may be removed by the Repository Maintainer. + +### Refactoring + +Refactoring is a necessary part of any software project's evolution. The +following guidelines cover refactoring pull requests for the project. + +There are three categories of refactoring: code-only moves, code style fixes, and +code refactoring. In general, refactoring pull requests should not mix these +three kinds of activities in order to make refactoring pull requests easy to +review and uncontroversial. In all cases, refactoring PRs must not change the +behaviour of code within the pull request (bugs must be preserved as is). + +Project maintainers aim for a quick turnaround on refactoring pull requests, so +where possible keep them short, uncomplex and easy to verify. + +Pull requests that refactor the code should not be made by new contributors. It +requires a certain level of experience to know where the code belongs to and to +understand the full ramification (including rebase effort of open pull requests). + +Trivial pull requests or pull requests that refactor the code with no clear +benefits may be immediately closed by the maintainers to reduce unnecessary +workload on reviewing. + +"Decision Making" Process +------------------------- + +The following applies to code changes to the project (and related projects). + +Whether a pull request is merged rests with the project merge maintainers. + +Maintainers will take into consideration if a patch is in line with the general +principles of the project; meets the minimum standards for inclusion; and will +judge the general consensus of contributors. + +In general, all pull requests must: + + - Have a clear use case, fix a demonstrable bug or serve the greater good of + the project (for example refactoring for modularisation); + - Be well peer-reviewed; + - Have tests appropriate to the affected surface; + - Follow the project style and supported API/security guidance; + - Not break the existing test suite; + - Where bugs are fixed, where possible, have tests demonstrating the bug and + proving the fix. This helps prevent regression; + - Change relevant comments and documentation when behaviour of code changes. + +### Peer Review + +Anyone may participate in peer review which is expressed by comments in the pull +request. Typically reviewers will review the code for obvious errors, as well as +test out the patch set and opine on the technical merits of the patch. Project +maintainers take into account the peer review when determining if there is +consensus to merge a pull request. + +Code review is a burdensome but important part of the development process, and +as such, certain types of pull requests are rejected. In general, if the +**improvements** do not warrant the **review effort** required, the PR has a +high chance of being rejected. It is up to the PR author to convince the +reviewers that the changes warrant the review effort, and if reviewers are +"Concept NACK'ing" the PR, the author may need to present arguments and/or do +research backing their suggested changes. + +Moreover, if there is reasonable doubt that the pull request author does not +fully understand the changes they are submitting themselves, or if it becomes +clear that they have not tested the changes on a basic level themselves, the +pull request may be closed immediately. + +#### Conceptual Review + +A review can be a conceptual review, where the reviewer leaves a comment + * `Concept (N)ACK`, meaning "I do (not) agree with the general goal of this pull + request", + * `Approach (N)ACK`, meaning `Concept ACK`, but "I do (not) agree with the + approach of this change". + +A `NACK` needs to include a rationale why the change is not worthwhile. +NACKs without accompanying reasoning may be disregarded. + +#### Code Review + +After conceptual agreement on the change, code review can be provided. A review +begins with `ACK BRANCH_COMMIT`, where `BRANCH_COMMIT` is the top of the PR +branch, followed by a description of how the reviewer did the review. The +following language is used within pull request comments: + + - "I have tested the code", involving change-specific manual testing in + addition to running the relevant automated tests, and in case it is not + obvious how the manual testing was done, it should be described; + - "I have not tested the code, but I have reviewed it and it looks + OK, I agree it can be merged"; + - A "nit" refers to a trivial, often non-blocking issue. + +Project maintainers reserve the right to weigh the opinions of peer reviewers +using common sense judgement and may also weigh based on merit. Reviewers that +have demonstrated a deeper commitment and understanding of the project over time +or who have clear domain expertise may naturally have more weight, as one would +expect in all walks of life. + +### Finding Reviewers + +As most reviewers are themselves developers with their own projects, the review +process can be quite lengthy, and some amount of patience is required. If you find +that you've been waiting for a pull request to be given attention for several +months, there may be a number of reasons for this, some of which you can do something +about: + + - It may be because of a feature freeze due to an upcoming release. During this time, + only bug fixes are taken into consideration. If your pull request is a new feature, + it will not be prioritized until after the release. Wait for the release. + - It may be because the changes you are suggesting do not appeal to people. Rather than + nits and critique, which require effort and means they care enough to spend time on your + contribution, thundering silence is a good sign of widespread (mild) dislike of a given change + (because people don't assume *others* won't actually like the proposal). Don't take + that personally, though! Instead, take another critical look at what you are suggesting + and see if it: changes too much, is too broad, doesn't adhere to the surrounding style, + is dangerous or insecure, is messily written, etc. Identify and address any of the + issues you find. Then ask if someone could give their opinion on the concept itself. + - Remember that the best thing you can do while waiting is give review to others! + +Copyright +--------- + +By contributing to this repository, you agree to license your work under the +MIT license unless specified otherwise at the top of the file itself. Any work +contributed where you are not the original author must contain its license +header with the original author(s) and source. -By contributing, you agree to license your original work under the project's -[MIT license](LICENSE), unless a file states otherwise. If you contribute work -you did not create, preserve its license notice, original authors, and source. Third-party notices shipped with this project are in [LICENSES](LICENSES/). + +Attribution +----------- + +This document is adapted from [Bitcoin Core's CONTRIBUTING.md]( +https://github.com/bitcoin/bitcoin/blob/master/CONTRIBUTING.md), Copyright (c) +2009-present The Bitcoin Core developers, distributed under the MIT software +license. See [https://opensource.org/licenses/MIT](https://opensource.org/licenses/MIT). From 2511af893f018197e4ff03ae62eb68722a7641bc Mon Sep 17 00:00:00 2001 From: Codex Agent Date: Mon, 5 Oct 2026 15:08:31 -0500 Subject: [PATCH 8/8] docs: Correct contributor task-list link --- CONTRIBUTING.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 3703078..b4d8b88 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -138,7 +138,7 @@ documentation when a contract changes. ### Work in Progress Changes and Requests for Comments If a pull request is not to be considered for merging (yet), please -prefix the title with [WIP] or use [Tasks Lists](https://docs.github.com/en/get-started/writing-on-github/getting-started-with-writing-and-formatting-on-github/basic-writing-syntax#task-lists) +prefix the title with [WIP] or use [Tasks Lists](https://docs.github.com/en/get-started/writing-on-github/getting-started-with-writing-and-formatting-on-github/basic-writing-and-formatting-syntax#task-lists) in the body of the pull request to indicate tasks are pending. A draft pull request is also appropriate for changes that are not ready for review.