Skip to content

wallet: Validate Bitcoin Core state types - #12

Open
BenWestgate wants to merge 1 commit into
codex/63-private-core-descriptorsfrom
codex/v1-core-state-validation
Open

BenWestgate wants to merge 1 commit into
codex/63-private-core-descriptorsfrom
codex/v1-core-state-validation

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

What

  • require exact nonnegative integer types for Core transaction, keypool, and unlock fields;
  • require an exact integer zero when verifying walletlock;
  • cover RPC failure, unsuccessful lock verification, explicit-null unlock state, and malformed boolean/string state.

Why

Python treats booleans as integers, so values such as False previously passed numeric zero checks. Core RPC responses are untrusted and wallet eligibility and relocking must fail closed. This adapts Rob1Ham#10 and closes the same type-confusion path in final relock verification.

Current head 5d128b8 is one focused commit and remains mergeable into reviewability-v1; the prior inline review threads are resolved. The separate public descriptor API question raised during review is handled by focused #64 rather than widening this state-validation fix.

Reviewed-head validation

  • full suite: 864 passed;
  • optimized suite: 864 passed under python -O;
  • Ruff check/format and strict mypy: pass;
  • historical differential-wallet verifier: 768 records matched;
  • exact-head GitHub Python-package run 333: success.

The differential-wallet verifier cited above was subsequently removed by merged #7 together with the bip32/Coincurve test dependency. On the final integration tip, use the current real-Bitcoin-Core fixture path from merged #51 plus the focused malformed-state/relocking tests and normal CI; do not reintroduce the removed Python wallet oracle merely to reproduce the old validation line. #12 can be integrated after the #42/#57/#46/#80/#81 runtime stack settles.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3f60a4600e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/codex32/_bitcoin_core.py Outdated
@BenWestgate
BenWestgate force-pushed the codex/v1-core-state-validation branch from 3f60a46 to d574d1e Compare September 21, 2026 09:14
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate added gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. area: security Security invariants, hardening, and security-sensitive boundaries. area: wallet/core Wallet integration and Bitcoin Core boundaries. bug Something isn't working labels Sep 24, 2026
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: d574d1e309

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

ACK d574d1e

  • type(x) is int closes the False == 0 path for eligibility and the relock check; an absent unlocked_until still means unencrypted.
  • Merges cleanly with #57.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please justify why this function is actually necessary to the function of this project or remove it.

Comment thread src/codex32/_bitcoin_core.py

Copy link
Copy Markdown
Owner Author

Resolution of the 2026-09-28 review question: the legacy public descriptor-record helper is not necessary as a supported public API. That concern is deliberately separated into #63 / PR #64, which removes core_descriptors from the public surface and deletes the unused public-deriver branch while keeping the current private Core import-record builder until the separately reviewed Core-native setup work replaces it. #12 should remain the focused fail-closed RPC state-type fix rather than mixing that API/architecture cleanup into this two-file PR.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release-gate ACK 5d128b8.

The current one-commit head keeps this PR scoped to fail-closed Bitcoin Core state typing. The explicit-null unlock-state bug is fixed; boolean/string numeric lookalikes are rejected; relock verification requires exact integer zero. The separate descriptor-API question is correctly isolated in #64. All inline threads are resolved and exact-head Python-package run 333 is green.

No remaining code blocker from this review.

Copy link
Copy Markdown
Owner Author

Agent release-gate review at exact head 5d128b8: the Core-state validation is correctly fail-closed. Wallet eligibility now requires exact integer types for transaction/keypool/unlock fields so Python booleans, strings, and nulls cannot alias valid numeric state, and post-walletlock verification likewise requires exact integer zero. The added regressions cover malformed state plus lock-call/verification failures. Exact-head Python-package run 36361066324 succeeded. No remaining code-review blocker found; keep the separate descriptor-API cleanup in #64.

@BenWestgate
BenWestgate force-pushed the codex/v1-core-state-validation branch from 5d128b8 to afee360 Compare October 1, 2026 18:51
@BenWestgate
BenWestgate changed the base branch from reviewability-v1 to codex/63-private-core-descriptors October 1, 2026 18:51
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

1 similar comment
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Require exact nonnegative integer types for wallet counts and unlock state,
including final relock verification. This prevents booleans and malformed RPC
values from passing numeric equality checks.

Security: fail closed on untrusted Bitcoin Core state while preserving valid
encrypted and unencrypted wallet flows.

Validation: python -m pytest -q; python -O -m pytest -q; Ruff check and format;
strict mypy; differential_wallet.py --verify.
@BenWestgate
BenWestgate force-pushed the codex/v1-core-state-validation branch from afee360 to a860035 Compare October 1, 2026 19:08
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: security Security invariants, hardening, and security-sensitive boundaries. area: wallet/core Wallet integration and Bitcoin Core boundaries. bug Something isn't working gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant