Skip to content

gui: Require strong recovery commitment - #29

Closed
BenWestgate wants to merge 2 commits into
26-verify-recovery-before-importfrom
27-strong-recovery-commitment
Closed

BenWestgate wants to merge 2 commits into
26-verify-recovery-before-importfrom
27-strong-recovery-commitment

Conversation

@BenWestgate

Copy link
Copy Markdown
Owner

Closes #27.

  • derive a domain-separated SHA-256 commitment from the canonical root xpub
  • require the separately stored commitment before restore can reach wallet mutation
  • keep the 32-bit BIP32 fingerprint as diagnostic metadata only
  • add the commitment to the wallet record and document the trust boundary

Validation: 971 tests pass normally and under python -O; Ruff, format, mypy, and git diff --check pass.

Stacked on #28.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7d1bf6d5d8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/user/guide.md Outdated
@BenWestgate BenWestgate self-assigned this Sep 24, 2026
@BenWestgate BenWestgate added the gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. label Sep 24, 2026
@BenWestgate
BenWestgate marked this pull request as draft September 24, 2026 10:49
@BenWestgate

Copy link
Copy Markdown
Owner Author

Closing: the 256-bit commitment was concept-NACKed. Replaced by the typed-fingerprint gate in #28, with the stronger check discussed in #27.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant