docs: Answer first-time questions in the user guide - #97
BenWestgate wants to merge 6 commits into
Conversation
Apply the established majority-case interpretation to standalone correction while preserving immutable context, entered edit semantics, and disclosure accounting. Account the normalized retry frontier even when the first optional search reaches its deadline after finding a candidate, so cumulative capture mass remains fail-closed. Fixes #37.
Give standalone correction a stable status contract: 0 for already-valid input, 1 when a suggestion is emitted, 2 for command or input syntax errors, and 3 when no usable suggestion is emitted. Keep incomplete best-effort suggestions at status 1 and document status 3 only for incomplete searches without a usable suggestion. Fixes #39.
Remove unreachable creation guards and the permanently false correction ambiguity field, align the CLI test Core stub with production, and move reference-only correction helpers out of the installed package.\n\nSecurity: fail-closed correction and wallet behavior are unchanged.\n\nRefs #38.
Gate restore and existing-seed wallet initialization on the independently recorded BIP32 master fingerprint before any Bitcoin Core wallet mutation. Keep the correction path from disclosing or reusing a fingerprint derived from the candidate being authenticated. Fixes #30.
A tester asked why the fingerprint stays off the cards, why restore asks for it, how long a string is, which share indices create uses, and whether letter case matters. Answer each in a short section. The restore answer describes the typed-fingerprint step from #57, so this sits on that branch. Closes #90 Claude-Session: https://claude.ai/code/session_015CuLXqAvAovfoVcUmmogwa
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated release-gate review, posted at the maintainer's request.
Concept ACK, but I would keep this draft for two documentation fixes before human review:
- “
ms32 create 2and the other thresholds write shares at random indices” is only true when indices are not explicitly supplied. The guide already documents--indices, so this answer should say the presets/default share-count path chooses random ordinary indices while--indicesuses the operator's explicit indices. - #90 explicitly says the length-specific cards from #88 show where the string ends. Once #88/#96 is settled, this answer should link the 48- and 74-character card templates (or state that the rarer lengths have no dedicated template yet) rather than leaving the length answer disconnected from that requested guidance.
The fingerprint/no-record and case answers match #57's reviewed contract. No security blocker beyond preserving that wording. The commit is Claude-authored and still requires responsible-human rewrite/squash before integration.
The FAQ treated random indices and identifiers as unconditional even though the CLI accepts chosen share indices and an explicit set identifier. State the default behavior and the available choices accurately. Refs #90.
|
Reviewed the FAQ against the CLI. Follow-up 7fa8137 qualifies the two defaults: operators can choose share indices with --indices and specify an identifier. The original answers about the wallet-record fingerprint, length, and case remain unchanged. The updated documentation diff is ready for human review; the follow-up is agent-authored and should be handled under the repository authorship policy. |
a7efaae to
054e8d9
Compare
Closes #90.
Add a short Common questions section to the user guide covering the first-time tester questions: why the wallet fingerprint stays off recovery cards, why restore asks the operator to type it, supported codex32 lengths, share indices and
S, and letter case.This documentation is based on #57 because the restore answer describes its typed-fingerprint gate and explicit no-record path.
Current review state:
7fa8137:ms32 create 2now says random share indices are the default and points to--indices; explicit identifiers are likewise distinguished from the random default;Keep this draft stacked on the final #57-derived restore contract, and refresh it after #96 is integrated so the links resolve in the resulting candidate. The Claude/agent-authored commits require responsible-human rewrite/squash before integration.