gui: Require the recorded fingerprint before import - #28
BenWestgate wants to merge 8 commits into
Conversation
BenWestgate
left a comment
There was a problem hiding this comment.
Looks good, evaluate whether the CLI should require this also.
And whether the user should be asked to type the fingerprint and reject on mismatch (to prevent loading the wrong wallet) or merely verify the displayed recovered fingerprint against the separately stored wallet record.
BitcoinCore.initialize now takes a required expected_fingerprint and checks it before any wallet is listed, created, unlocked or imported into, so the GUI and CLI share one gate. The operator types the value from the wallet record; a new wallet shows it once and asks for it back. Without a record, the backup identifier must derive from the seed (codex32 fingerprint or legacy Bails RIPEMD-160 identifier). Fixes #26. Fixes #30. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
074793b to
0cc5437
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
I actually think writing and typing the fingerprint can be avoided by signing and encrypting the descriptor with keys derived from the master root. The descriptor will only decrypt and signature only validate if the correct master root was recovered. Inside that descriptor will be the descriptor checksum and the fingerprint. This is far more elegant as we kill two birds with one stone and reduce user burden. The extra dependency is gpg which is installed on Tails and debian by default and bip85 which already has a python reference implementation of which we need a tiny fraction of. The fingerprint or seedid identifier does no authentication unless we are dealing with shares. Tamperer will just change it to match the seed he controls. Another time we should be asked for our encrypted descriptor or our fingerprint is when no correction is found due to lack of checksum discrimination, we can push well beyond 13 / 15 erasures when we have a known fingerprint to check against. |
|
@claude review |
Pass the recorded fingerprint through the real Bitcoin Core regtest and smoke harnesses after initialize() made identity verification mandatory.\n\nValidation: Ruff; mypy on both tools; 7 focused identity/CLI tests; git diff --check. The branch also passed 978 normal and 978 optimized tests before this tool-only fix.\n\nrefs #26
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Restoring without a wallet record no longer requires a seed-derived backup identifier. The operator sees the recovered fingerprint, whether the identifier was made from the seed (codex32 fingerprint, Bails RIPEMD-160, or its mid-2023 SHA-256 alpha, first three characters for Bails), and a shared warning, then chooses. Split codex32 backups have random identifiers and were otherwise unrecoverable without a record. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 819bd468a9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Use the same recovery-identity row in the Bitcoin Core controls table as the reviewability-v1 change, and keep only the window's specifics in the graphical section. Trim the gate's docstrings to the library size budget. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 64e6b96d19
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Yes—the CLI should enforce the same pre-import safety boundary; stacked PR #31 does so after #29. The user should not be required to retype the 32-bit fingerprint: it is useful diagnostic metadata, but typing it adds friction without making it a strong authentication check. PR #29 instead requires the separately stored 256-bit recovery commitment before wallet mutation. |
Repeat the recovery identity check immediately before GUI unlock and wallet creation so a stale or inconsistent Core response cannot mutate wallet state first. Treat unavailable RIPEMD-160 as a legacy-rule miss and keep recordless identifier guidance accurate.\n\nSecurity: enforces the verify-before-mutate wallet invariant across GUI-only passphrase and creation paths.\n\nValidation: 986 pytest tests in normal and optimized modes; focused GUI/identifier tests; Ruff; format check; mypy; git diff --check.
Keep the wallet-record fingerprint gate on ms32 wallet restores, while ms32 create only requires the operator to record the new fingerprint. Fresh creation has no pre-existing wallet identity to authenticate.\n\nValidation: 886 tests in normal and optimized modes; Ruff; format check; mypy; git diff --check.
Fresh GUI setup now records the new fingerprint without treating it as evidence for a pre-existing wallet. Restore still verifies recorded identity immediately before creating a destination wallet.\n\nValidation: 987 tests in normal and optimized modes; focused GUI tests; Ruff; format check; mypy; git diff --check.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Claude), posted at the maintainer's request. I wrote 0cc5437, 819bd46 and 64e6b96, so this is partly self-review.
Concept ACK c5f8993.
- e1180b7..c5f8993 look right:
verifynow runs beforeunlock/createin the GUI, and a missing RIPEMD-160 falls through to the SHA-256 rule. - Same question as #57:
create --existingskips the gate (restore=False). - #57's 6da1f2a removed the identifier check; this PR keeps it. Pick one so the library/CLI halves match.
- 0cc5437, 819bd46 and 64e6b96 have
Co-Authored-By: Claudetrailers, which AI_POLICY.md forbids. Squash-merge or reword.
Apply the restore gate before importing an existing seed, whether it is confirmed unchanged or re-shared. Keep fresh setup as record-only confirmation and share the library identity diagnostics with the CLI.
|
Release-gate verification at current head |
|
One non-code release-gate item remains despite the current code ACK: this branch history still contains AI co-author trailers (including |
|
Release-gate history check: the functional review is now ACKed at |
|
Agent release-gate review of the historical GUI evidence at exact head |
|
GUI replay map for the final clean stack:
This map is derived from exact historical head |
Fixes #26.
The library and CLI half is #57, with #81 strengthening
ms32 create --existingby moving its independent wallet-record/no-record decision before any new share ceremony. This older GUI branch carries copies of_bitcoin_core.py,cli.py, their tests and Core tools only because its historicalgui-reference-v1base predates that library work; review those files in #57/#81. Here, review only the GUI restore boundary.Integration note: this branch is reviewed evidence, not the final GUI integration candidate. The clean GUI line is #65 → #66 → #77 → #78. After the library/CLI and remaining foundation/security/API work is integrated into the settled
reviewability-v1, rebase that clean GUI stack once and replay/squash only this PR’s reviewed GUI restore-authentication delta onto the resulting tip. Do not preserve this branch's duplicated library snapshot or exploratory Claude co-author history. Resolve #76 from actual rendered Tails evidence, then rerun automated and manual GUI qualification before the fresh adversarial review.Scope: this PR is the GUI’s accident-safety gate. It prevents a wrong/mixed/miscorrected but checksum-valid recovery from changing Core before the operator identifies the intended wallet. A typed 32-bit fingerprint is not presented as protection against deliberate threshold-share replacement; the seed-keyed encrypted descriptor backup in #55 is the separate first-class malicious-tampering defense.
create(). Fresh setup skips that restore-only check.Validation on the reviewed historical head
be8c243: 987 tests pass normally and under-O; focused GUI tests, Ruff, formatting, mypy andgit diff --checkpass. Final qualification occurs only after replay onto #65/#66/#77/#78 and includes the supported Tails guest-resolution checks.