Skip to content

Make upstream integrations version-adaptive to stop cross-component regressions #249

Description

@BenWestgate

Problem

#240 and the Tails 7.13 testing in #230 exposed one architectural problem: CipherStick integration code was coupled to incidental details of particular upstream releases, so a Tails/Debian/GNOME/Python update broke several unrelated-looking flows.

Examples include hard-coded Python minor-version paths, assumptions about desktop executables, duplicated Tails policy, brittle GUI/layout assumptions, and scattered Bitcoin Core/codex32 compatibility logic.

This conflicts with the maintenance model we want from Tails:

Goal

Keep CipherStick a thin, version-adaptive integration layer so routine releases of Bitcoin Core, Tails, GNOME, Debian, Python, python-codex32, and JoinMarket do not require whack-a-mole fixes across unrelated scripts.

This is a meta issue. Implementation belongs in the focused canonical issues below; avoid adding another symptom issue when one of these boundaries already owns the fix.

Canonical workstreams

Tails / desktop / persistence

Bitcoin Core integration

codex32 integration

Focused UI regressions

Other compatibility-facing cleanup

Externally opened tester reports remain open and can be referenced by the canonical implementation issue/PR without being closed as duplicates.

Acceptance criteria

  • Remove hard-coded Python minor-version package paths; resolve Python code through the running interpreter/package/source layout.
  • Replace direct assumptions about desktop applications with stable interfaces or centralized runtime capability detection.
  • Centralize unavoidable compatibility probes/adapters so each upstream contract has one place to change.
  • Prefer feature/capability detection over version comparisons; document unavoidable version bounds and the contract they protect.
  • Remove duplicated policy/validation/UI already owned by Tails or another upstream when upstream behavior is sufficient.
  • Keep failures at dependency boundaries visible and actionable.
  • Maintain a lightweight compatibility/smoke-test checklist for the latest supported Tails release covering bootstrap, Persistent Storage, Bitcoin Core install/update/launch, codex32 install/launch/restore handoff, and JoinMarket integration when present.
  • Prefer deleting obsolete compatibility code after upstream transitions instead of accumulating branches indefinitely.

Design rule

When several regressions appear after an upstream release, identify and repair the shared dependency boundary first. Keep one canonical issue per coherent fix/PR and close maintainer-opened symptom duplicates into it.

Refs #230, #240.

Activity

  1. BenWestgate commented on Sep 27, 2026

    @BenWestgate
    OwnerAuthor

    "a duplicated passphrase-strength check drifted from the behavior Tails itself accepts;"

    That's not true, Tails always accepted any passphrase, bails added the passphrase-strength check to warn on weak passphrases, something Tails does not do (but could! should it?)

    menu actions assumed gnome-terminal, while current Tails provides kgx instead;

    What's the solution to call whatever terminal the future tails may use? gtk-open?

    cACK Make CipherStick a thin, version-adaptive integration layer so routine releases of Bitcoin Core, Tails, GNOME, Debian, Python, python-codex32, and JoinMarket do not require whack-a-mole fixes across unrelated scripts.

    should python-codex32 be pinned into our bails repository's source tree? I believe this project gets considerably more attention and review it would be good if cloning this project cloned python-codex32 master as well.

    That way we don't have an obscure file downloading a dependency (besides Bitcoin core) that handles secrets.

  2. 16 remaining items

  3. BenWestgate commented on Sep 30, 2026

    @BenWestgate
    OwnerAuthor

    Tails 7.13 GUI follow-ups are tracked upstream in python-codex32: #43 (type back the recorded fingerprint), #71 (neutral card-count choices), #72 (paper-card group layout), #73 (wallet-encryption guidance), #74 (fit final wallet identity on one screen), #75 (compact home-window sizing), and #76 (distinct home-action artwork). The extra-group repair, recovery-vs-repair highlighting, and readback-prefix/cursor findings are already corrected in the current #65 GUI candidate and should not be duplicated. Refs #230.

  4. BenWestgate commented on Sep 30, 2026

    @BenWestgate
    OwnerAuthor

    Additional Tails 7.13 follow-ups are now tracked: Bails #291 for a future Tails-owned passphrase-verification boundary that returns only success/failure, and python-codex32 #75/#76 for compact home-window sizing and distinct home-action artwork. #289 remains the current practical trainer fix; #291 is hardening, not a merge blocker.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions