Wallet primitives for the Pilot Protocol: Ed25519 keypairs (the daemon identity) and EVM secp256k1 keys (for on-chain payments / signed receipts).
pkg/wallet— local Ed25519 signer; reads / writesidentity.jsonwith mode 0600 + (since the May 2026 audit sweep) emits a warning when an existing file is mode 0644 or looser.pkg/evm— secp256k1 signer; ParseAddress enforces EIP-55 checksum on mixed-case input; cross-chain replay protection via EIP-712 domain separation.cmd/wallet— CLI for generating / inspecting wallets.
go test -race -coverprofile=coverage.out -covermode=atomic ./...Pushing a v* tag runs .github/workflows/release.yml:
- Tests.
- A native
CGO_ENABLED=0build on linux/amd64, linux/arm64, darwin/amd64 and darwin/arm64. The job checks each binary'sfileoutput and requireswallet -versionto equal the tag. - The binary's sha256 is pinned into
manifest.json, which is signed with thePILOT_APP_PUBLISHER_KEYrepo secret (public keyed25519:VF8fdEP/Oe2aWN3ozQ7Ar22137tHb7dkSw0hlzlk/os=, the catalogue's publisher pin forio.pilot.wallet). - Each platform is packed as
io.pilot.wallet-<version>-<os>-<arch>.tar.gzbyscripts/pack-bundle.py. - The four bundles are published with
checksums.txtand build provenance.
The catalogue entry (pilot-protocol/pilotprotocol catalogue/catalogue.json) then gets a bundles map with one entry per platform, built from those URLs and checksums. The Version constant in cmd/wallet and app_version in manifest.json must equal the tag.