Skip to content

Bump trezor to 0.20.2 and add Ledger/Trezor e2e tests - #670

Draft
Uxío (Uxio0) wants to merge 1 commit into
mainfrom
trezor-0.20-hw-wallet-e2e
Draft

Uxío (Uxio0) wants to merge 1 commit into
mainfrom
trezor-0.20-hw-wallet-e2e

Conversation

@Uxio0

Copy link
Copy Markdown
Member

Replaces #594. That Dependabot PR only bumped the pin, but trezorlib 0.20 removes ClickUI and moves to sessions, so TrezorWallet stopped working with it.

Closes #594

Changes

  • Bump trezor to 0.20.2. requirements.txt from Bump trezor from 0.13.10 to 0.20.0 #594 is gone (main uses uv now), uv.lock is updated.
  • Port TrezorWallet to trezorlib 0.20:
    • One cached client and session, so the passphrase is asked once for all derivation paths.
    • PIN: Model One asks on the host with the matrix positions. Bad input or a "set new PIN" request cancels the flow on the device.
    • Passphrase: typed on the device when supported, otherwise asked on the host (empty = standard wallet).
    • New models pair through THP: the code shown on the device is asked on the host.
    • EIP-712: Model T and newer get the full typed data, so the device shows every SafeTx field and the message hash the CLI prints. Model One keeps signing the hashes.
    • A disconnect drops the cached client and session, so the next call connects again. An invalid session (device locked) is retried once with a new session.
    • More trezorlib errors are mapped to HardwareWalletException (passphrase, busy device, any other TrezorException), so the CLI does not exit with a traceback.
  • HwWallet.sign_typed_data: default signs the hashes. The manager calls it, so Ledger works the same as before.
  • e2e tests in tests/e2e, with testcontainers (images pinned by digest):
    • Ledger on Speculos (-m e2e): list accounts, load the device as owner and sender, sign and execute send_ether, sign a Safe message, check the hashes the device showed.
    • Trezor Safe 5 (-m e2e_trezor): same flow, passphrase on the device, checks the SafeTx fields and message hash screens.
    • Trezor Model One (-m e2e_trezor): same flow, PIN and passphrase on the host, hash signing.
    • Both markers are skipped by default. Trezor is local only (5.5 GB image).
  • New e2e CI job for the Ledger tests, with the Ledger app binary cached.
  • README: how to run the e2e tests.

Known limit

THP pairing credentials are not stored, so new models (Safe 7) ask for the pairing code on every start.

Testing

  • Default suite: 88 passed, 1 skipped.
  • pytest -m "e2e or e2e_trezor": 3 passed locally.

- Port TrezorWallet to trezorlib 0.20 sessions and callbacks
- Show full EIP-712 typed data on Trezor Model T and newer
- Add Ledger and Trezor e2e tests with testcontainers
- Run Ledger e2e in CI
@Uxio0
Uxío (Uxio0) requested a review from a team as a code owner October 2, 2026 12:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T12:49:00.985078Z 8bab803 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@Uxio0
Uxío (Uxio0) marked this pull request as draft October 2, 2026 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant