Skip to content

ci: Verify wallet fixtures against Bitcoin Core - #51

Merged
BenWestgate merged 1 commit into
reviewability-v1from
codex/9-core-fixture-ci
Sep 30, 2026
Merged

BenWestgate merged 1 commit into
reviewability-v1from
codex/9-core-fixture-ci

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Fixes #9.

Run the real Bitcoin Core regtest harness on relevant pull requests, weekly, and on demand against pinned v32.0rc2 binaries. The harness loads every frozen seed→fingerprint value from tests/data/wallet_fingerprints.json through tools/_wallet_test_vectors.py and checks it independently against Core, so a stale or wrong frozen value fails rather than merely agreeing with its unit-test fixture.

The workflow is path-filtered on the wallet/Core/fingerprint files, so unrelated pull requests do not pay the Core download cost. #7 has merged into reviewability-v1; this follow-up completes #6's independent real-Core coverage requirement.

The v32.0rc2 x86_64 archive SHA256 is pinned to the value published in the signed RC2 manifest. Rechecked 2026-09-30: v32.0rc2 remains the latest signed v32 tag; neither v32.0rc3 nor final v32.0 exists. The annotated rc2 tag is cryptographically verified. Repin and rerun if a newer signed RC or final appears before release.

Review status

Current head fc82de3 restacks the unchanged 48-line workflow on the #7 integration tip 55d06b0. Its tree is byte-for-byte identical to previously reviewed head 664a668 (git diff --exit-code), and the PR now displays exactly one changed file. All inline review threads are resolved. The path-filtered pull_request trigger remains in place.

Fresh runs on fc82de3 passed: Bitcoin Core wallet fixtures run 36784044686 and all 20 Python-package jobs across runs 36784044679 and 36784039614. The combined correction/Core/restore preflight also passed 920 tests on Python 3.14.

Human review order: this PR follows merged #7 and precedes the planned refresh of #57 and #46.

Disclosure: AI tools were used while implementing and checking this user-requested branch-to-branch contribution. The restack preserved Ben Westgate as the original author and records Codex Agent as its committer.

Closes #6.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate added area: ci Continuous integration and workflow configuration. area: wallet/core Wallet integration and Bitcoin Core boundaries. enhancement New feature or request gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. labels Sep 24, 2026
@BenWestgate

Copy link
Copy Markdown
Owner Author

@claude review #51

@BenWestgate

Copy link
Copy Markdown
Owner Author

Fresh release-gate verification on 2026-09-25: v32.0rc1 and v32.0rc2 are both annotated Bitcoin Core tags with valid GitHub signature verification, no v32.0 final tag exists yet, and the pinned official rc2 binary still passes tools/bitcoin_core_regtest.py end-to-end ({"bitcoin_core": "/Satoshi:32.0.0/", "status": "pass"}). This remains pre-final evidence; #5/#52 must be repinned and rerun if a newer signed RC or final v32.0 appears before publication.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

Not ACKing f01a626 yet.

  • schedule and workflow_dispatch only fire for workflow files on the default branch (master). While this lives on #7 or reviewability-v1, it never runs.
  • Suggest adding pull_request with a paths: filter (tests/data/wallet_fingerprints.json, tools/_wallet_test_vectors.py, tools/bitcoin_core_regtest.py, src/codex32/_bitcoin_core.py). That fixes the trigger, and a changed fixture gets checked before merge instead of up to a week later.
  • Pin/download/checksum steps look right.

Comment thread .github/workflows/bitcoin-core-fixtures.yml

Copy link
Copy Markdown
Owner Author

Release-monitor refresh (2026-09-26): the upstream bitcoin/bitcoin tag namespace still has only v32.0rc1 and v32.0rc2 under v32.0; no final v32.0 tag exists yet. The rc2 pin therefore remains the newest signed v32 candidate for this CI gate. Keep the existing requirement to repin and rerun if rc3/final appears before publication.

Copy link
Copy Markdown
Owner Author

Release-monitor check (2026-09-26): the official Bitcoin Core 32.0 directory still exposes test.rc2/; that RC directory includes both SHA256SUMS and SHA256SUMS.asc dated 2026-09-22. No stable 32.0 artifact set is visible yet. The current v32.0rc2 pin therefore remains the newest signed release-candidate evidence; repin only when a newer signed RC or final appears.

@BenWestgate BenWestgate added the area: security Security invariants, hardening, and security-sensitive boundaries. label Sep 27, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Owner Author

Bitcoin Core release-monitor refresh (2026-09-27): the official bitcoin/bitcoin v32.0* tag namespace still contains only v32.0rc1 and v32.0rc2; there is still no final v32.0 tag. The v32.0rc2 annotated tag continues to have valid GitHub signature verification. No pin change is warranted today; keep the existing repin/rerun condition if a newer signed RC or final appears before publication.

Copy link
Copy Markdown
Owner Author

Release-gate review follow-up: the earlier trigger NACK is resolved. The current workflow includes the path-filtered pull_request trigger, the only review thread is resolved, and current head 0466510 has a passing real-Core verify job plus the full Python package matrix. Keep this PR stacked on #7 until #7 merges; then retarget to reviewability-v1 and preserve the one-workflow-file review delta. No code-review blocker remains from the trigger finding.

@BenWestgate

Copy link
Copy Markdown
Owner Author

Release-monitor refresh (2026-09-27/28): upstream bitcoin/bitcoin still exposes only v32.0rc1 and v32.0rc2 under v32.0*; both annotated tag objects report valid signature verification. The official Bitcoin Core 32.0 directory still exposes only test.rc2/, containing SHA256SUMS and SHA256SUMS.asc. There is no v32.0rc3 or final v32.0, so the current rc2 pin remains correct. Repin and rerun only when a newer signed RC or final appears before release.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review, posted at the maintainer's request.

ACK 1038dfb. The pull_request path trigger fixes the prior blocker.

@BenWestgate BenWestgate added the area: packaging/release Packaging, artifacts, compatibility, and release qualification. label Sep 30, 2026 — with ChatGPT Codex Connector
@BenWestgate
BenWestgate force-pushed the codex/9-core-fixture-ci branch from 1038dfb to 768bcba Compare September 30, 2026 14:54

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated release-gate review, posted at the maintainer's request.

ACK 768bcba.

This is the previously reviewed one-file Core fixture workflow restacked directly onto #7's current Core-native wallet head f9c3bc8. The workflow logic is unchanged. On this exact head, Bitcoin Core wallet-fixtures run 36732713815 passed against the pinned v32.0rc2 binary, and Python-package run 36732713875 passed. The real-Core check therefore covers #7's current addhdkey / createwalletdescriptor account-0 setup and the frozen fingerprint fixtures. All inline threads are resolved.

No remaining code blocker from this review. Integrate #7 first, then this one-file follow-up before refreshing #57.

@BenWestgate
BenWestgate force-pushed the codex/9-core-fixture-ci branch 2 times, most recently from 75d3833 to 664a668 Compare September 30, 2026 18:49

Copy link
Copy Markdown
Owner Author

Agent release-gate review at current head 664a668: the one-file workflow is appropriately path-filtered, pins both Actions by commit and Core rc2 by SHA256, uses permissions: contents: read, and runs the real-Core regtest verifier. Exact-head runs 36761397071 (package) and 36761397161 (Core fixtures) both succeeded. I found no remaining code-review blocker. Review/merge after #7, then retarget to reviewability-v1 without widening the one-workflow-file delta.

Base automatically changed from 3-remove-python-bip32-dependency to reviewability-v1 September 30, 2026 21:59
Run the pinned Bitcoin Core v32 fixture verifier on relevant pull requests, weekly, and on demand so frozen seed-to-fingerprint data cannot silently drift from Core.

Fixes #9
@BenWestgate
BenWestgate force-pushed the codex/9-core-fixture-ci branch from 664a668 to fc82de3 Compare September 30, 2026 22:10
@BenWestgate

Copy link
Copy Markdown
Owner Author

Agent release-gate re-review at fc82de3: the restack changed only the parent and committer. git diff --exit-code 664a668 fc82de3 confirms the entire tree is identical to the previously reviewed head, and GitHub now shows the intended one-file, 48-line workflow diff. The real-Core fixture run 36784044686 and all 20 Python-package jobs on the refreshed head passed; all review threads remain resolved. The previous code ACK stands. This is ready for human review as the next integration step.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is fine. nit: Consider reducing the frequency of the check to monthly or only after a new Bitcoin Core release after v1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci Continuous integration and workflow configuration. area: packaging/release Packaging, artifacts, compatibility, and release qualification. area: security Security invariants, hardening, and security-sensitive boundaries. area: wallet/core Wallet integration and Bitcoin Core boundaries. enhancement New feature or request gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant