docs: Define trusted-computer boundary - #59
BenWestgate wants to merge 3 commits into
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Claude), posted at the maintainer's request.
ACK b06aedb, nits only.
- Invariant 6 now matches what
create/secret/share/correct/xprvactually do. - Nit: the trusted-computer definition is written out three times (SECURITY.md, model.md, guide.md). Consider one definition in model.md and links elsewhere so they can't drift.
|
On the “trusted computer” duplication nit: keep the short operational definition in all three places. |
|
Release-gate sequencing note: review/merge #57 before final review of this docs PR. #57 and #59 both touch |
59a29bc to
580b8f8
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review, posted at the maintainer's request.
ACK 580b8f8.
|
Agent release-gate review at exact head |
Make the secret-output invariant literal about intentional recovery/export output, define the trusted-computer boundary consistently, and warn that shell command text can be retained even when stdin is safe from argv exposure. Update the shared CLI safety footer and its exact-help regression. Validation: focused help regression; Ruff check/format; strict mypy for the parser; git diff --check. The full generic-HRP module still reaches the pre-existing bip32 test dependency tracked by #3/#6 and fixed by #7. fixes #4
580b8f8 to
ede98a8
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head re-review: ACK ede98a8.
The security documentation now defines “trusted computer” consistently, distinguishes intentional recovery/export output from accidental secret disclosure, and warns that shell command text can persist even when stdin keeps secrets out of argv. The CLI footer matches that contract and the one prior help-text nit is resolved. Exact-head Python-package run 643 and Bitcoin Core wallet-fixture run 30 succeeded.
No code or security-contract blocker found; ready for human integration review after #23.
What
SECURITY.md, the security model, invariants, and user guide;Why
The earlier invariant literally said secrets stay out of ordinary output even though
create,secret,share,correct, andxprvintentionally display secret-bearing material. The documentation also used “trusted computer” without one operational definition. This makes the normative contract literal without changing secret-handling channels.Review stack
Base: #23 (
20-security-audit-docs). Current head:ede98a8.The reviewed policy change was replayed after the restore/security stack settled. One conflict in
docs/security/invariants.mdwas resolved by retaining both current requirements: intentional recovery/export commands may display their intended material, while wallet setup still transfers the master xprv only through child stdin and private descriptors remain only in Python memory/child stdin. The two follow-up commits retain their stable patch IDs. All prior review threads remain resolved.Validation
tests/test_generic_hrp.py: 12 passed normally and 12 underpython -O;python -O;git diff --checkpassed.Fixes #4.
Disclosure: AI tools assisted with the mechanical restack and conflict analysis; the contribution still requires responsible human review before integration.