Skip to content

codex32: Add Bitcoin Core restore flow - #230

Merged
BenWestgate merged 11 commits into
masterfrom
215-python-codex32-restore
Oct 1, 2026
Merged

BenWestgate merged 11 commits into
masterfrom
215-python-codex32-restore

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

Status

Current head fddc710 is mergeable, the stacked diff is one coherent commit / 12 files, Lint CI is green, and all current review threads are resolved. The human Tails 7.13 create/restore runtime gate passed on 2026-09-29.

What

  • pin the reviewed python-codex32 GTK4/libadwaita GUI at 1938b604182b5553f4e724fd2aea814496a24cd4
  • verify recovery identity before Bitcoin Core wallet mutation
  • clone/fetch and verify that exact revision, then run it directly from source with the Tails system Python
  • expose the upstream codex32-gui application directly; Bails adds no wallet UI
  • use the Codex32 book artwork for the launcher/application identity
  • document the reviewed recovery flow and the 32-bit-fingerprint limitation

Why

This replaces the broken legacy GTK3 wallet flow reported in #240 while keeping wallet/recovery logic in python-codex32.

Refs #215, #240

Dependency

#244 is merged. #202 is now rebased on current master; merge #202 first, retarget this PR to master, then merge it immediately so the legacy wallet removal and replacement codex32 flow land in sequence.

Testing

  • mandatory stack refresh preserved the reviewed 12-file diff while collapsing review-fix history to one coherent commit
  • git diff --check and bash -n passed for the integration scripts before the rebase; the final file content is unchanged
  • source-integrity checks reject tracked/ignored modifications and failed git status checks; clean trees pass and dirty/broken-index trees fail
  • repair returns the checkout to the pristine pinned revision; Core 31 is rejected and Core 32.0rc2/32+ is accepted
  • pinned python-codex32 revision: 987 tests pass normally and 987 under python -O; Ruff and mypy pass
  • security records revalidate the exact pinned revision relative to the previously reviewed 64e6b96d…
  • Tails 7.13 VM: the pinned revision installs and verifies without pip/venv and the replacement GUI launches using the system Python
  • Tails 7.13 also confirmed kgx is present but gnome-terminal is not; the launcher avoids adding a terminal dependency
  • Human Tails 7.13 integration pass (2026-09-29): the combined review stack reached codex32 and successfully created a Bitcoin Core wallet and restored one. This satisfies this PR's end-to-end release-validation gate.

Follow-up tracking from hands-on review

The broader findings are intentionally outside this integration PR and are tracked in focused work under #249:

The latest codex32 GUI-specific tester findings are tracked in python-codex32: #43 (retype the recorded fingerprint), #71 (neutral card-count choices), #72 (paper-card group layout), #73 (wallet-encryption guidance), #74 (fit final wallet identity on one screen), #75 (compact home-window sizing), and #76 (distinct home-action artwork). The reported extra-group repair, recovery-vs-repair highlighting, and readback-prefix/cursor behavior are already corrected in the current #65 GUI candidate and were not duplicated as new issues.

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Concept NACK.

CipherStick needs a GUI as easy-to-use GUIs are the standard for software included in Tails.

@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate
BenWestgate force-pushed the 215-python-codex32-restore branch from 4fd6853 to 12d5c49 Compare September 21, 2026 08:55
@BenWestgate
BenWestgate changed the base branch from master to 201-simplify-this-project-by-removing-bails-wallet September 21, 2026 08:55
@BenWestgate

Copy link
Copy Markdown
Owner Author

Addressed the Concept NACK: this no longer opens the ms32 CLI in a terminal. It now pins the actual python-codex32 GTK4/libadwaita GUI branch and launches its codex32-gui entry point directly from a desktop application. The Bails-side code is only the pinned installer and first-run launcher. git diff --check and bash -n pass.

@BenWestgate

Copy link
Copy Markdown
Owner Author

cACK @codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 12d5c4962f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread bails/.local/bin/install-codex32 Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: dd0f0638de

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread bails/.local/bin/open-codex32 Outdated
@BenWestgate BenWestgate self-assigned this Sep 23, 2026
@BenWestgate BenWestgate added enhancement New feature or request help wanted Extra attention is needed priority: high issues raised or encountered by 2 or more testers labels Sep 23, 2026
@BenWestgate BenWestgate added this to the L1 (BETA) milestone Sep 23, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 336a3dae86

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4144c0b91c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/LEGACY_WALLET_RECOVERY.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bd6ed693c8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/LEGACY_WALLET_RECOVERY.md Outdated
Comment thread bails/.local/bin/install-codex32 Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

Rebuilt as 859c4b7. This branch could not be merged with its base, and the reason was structural rather than a
conflict: it shared no common ancestor with 201-simplify-this-project-by-removing-bails-wallet. Its first
commit, 12d5c49, was a second repository root holding a whole-tree snapshot, so git merge-base returned nothing
and every file collided as added-by-both. GitHub reported the PR mergeable only because it will splice unrelated
histories.

The branch therefore carried a stale copy of the whole tree alongside the feature. Replayed onto the current base is
only what it actually contributed:

Not replayed, because the snapshot was simply older than master and would have reverted it: chainstate-preload,
install-core, link-dotfiles and the bitcoin-qt desktop entry, plus the three documents the base has since
consolidated. Reverting those was not intended by any commit here; it was an artifact of the snapshot.

Diff is now +431/-2 against the base, from 523 insertions and 87 deletions before. The previous history is kept as
the tag archive/superseded-215-orphan-history if anything needs checking against it.

#237 is unaffected: it was already merged, and its content is carried into the rebuild.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 859c4b7de8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread bails/.local/bin/open-codex32 Outdated

Copy link
Copy Markdown
Owner Author

Triage: this is the replacement path for #215, but it is not ready for human approval yet. The pinned GUI still imports into Bitcoin Core before a strong wallet-identity check, and the persistent virtualenv can break after a Tails Python minor-version upgrade. Fix those two points, update the recovery text to match the final flow, then run one end-to-end restore test on current Tails.

This comment was marked as outdated.

@BenWestgate

Copy link
Copy Markdown
Owner Author

Update: python-codex32#29 is closed. python-codex32#28 now carries the whole gate on its own: a typed fingerprint, plus a no-record path that accepts Bails' RIPEMD-160 backup identifiers. Once it's reviewed, repin to it.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3d459ff4d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread bails/.local/bin/install-codex32

Copy link
Copy Markdown
Owner Author

The red "Analyze (python)" CodeQL check isn't this PR's failure. It fails on master too: #202 removed the last Python file, so CodeQL finds no Python source to scan. #299 switches the scan to GitHub Actions workflows. This PR's diff doesn't touch CodeQL, so it's fine to merge with that check red.


Generated by Claude Code

claude and others added 2 commits October 1, 2026 01:38
A corrupt .git/index made the install check offer a repair, but the
repair's own fetch and checkout then failed on the same index and set -e
aborted. Remove the index first; checkout --force rebuilds it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PjUU3NvvEE8SGD3RdpXWDr
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

crACK changes since my last review look good.

@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found one blocking source-integrity issue on the current head. I reproduced it against Git: a modified tracked file hidden with git update-index --assume-unchanged leaves git status --porcelain=v1 --untracked-files=all --ignored=matching empty, and even git diff --quiet HEAD -- file returns success. Because both launcher/installer treat that status result as proof that the persistent checkout matches the reviewed pin, modified recovery code can be imported/executed while HEAD still equals the pinned revision. Please make the cleanliness check independent of mutable index flags (and apply the same fix in open-codex32) before human merge.

Comment thread bails/.local/bin/install-codex32
git status trusts index flags, so a tracked file marked assume-unchanged
could be modified while the checkout still looked clean, and the launcher
would import it. Both the installer and the launcher now hash every file
under the checkout and compare it with the pinned tree, rejecting missing,
extra, ignored and replaced files without reading the index.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PjUU3NvvEE8SGD3RdpXWDr
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACK 8006c5a after re-review of the source-integrity fix.

The P1 index-flag bypass is closed at both entry points. I reproduced the original condition with a modified tracked module hidden by assume-unchanged (empty porcelain status) and also tested skip-worktree; source_tree_clean rejects both because it hashes the actual filesystem bytes against the pinned tree rather than trusting the index. Clean pinned source passes, while a missing tracked file, extra ignored file, and a symlink replacing a tracked file are rejected. install-codex32 and open-codex32 carry the same verifier.

Regression review: the pinned python-codex32 tree has no executable tracked source files, so the verifier intentionally comparing blob contents/types rather than ordinary executable-bit changes does not alter the launch boundary. git ls-tree failure is fail-closed under pipefail. bash -n and git diff --check pass; exact-head Lint CI, CodeQL and dependency review are green.

No remaining code blocker found for this PR. Human review/merge is still required.

Run the hash verifier with python3 -I so packages in the user site
directory cannot change its result, and drop the user site from the
import check and the launch. Fail the check when a folder cannot be
read instead of skipping it. Document that the check guards against
corruption, not a local attacker who can already edit these scripts.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PjUU3NvvEE8SGD3RdpXWDr
@chatgpt-codex-connector

This comment has been minimized.

Revert the content-hash verifier (8006c5a, 2378fad). The checkout check
guards against corruption and accidents, which git status already
catches; the hash verifier only defended against a local attacker who
can edit these scripts anyway. Document that scope. The corrupt-index
repair fix stays.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PjUU3NvvEE8SGD3RdpXWDr
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@BenWestgate
BenWestgate merged commit fca5d2f into master Oct 1, 2026
7 of 8 checks passed
@BenWestgate
BenWestgate deleted the 215-python-codex32-restore branch October 1, 2026 04:47
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
Resolve conflicts with the squash-merged #230: keep this branch's Core
datadir probe and wait loop, and take master's corrupt-index repair fix
and checkout-check comment.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PjUU3NvvEE8SGD3RdpXWDr
BenWestgate pushed a commit that referenced this pull request Oct 1, 2026
…y-claims

Bring in the merged codex32 restore flow (#230). Keep this branch's
bounded wording and list the pinned python-codex32 application as
supported, replacing the stale "tracked in #215" notes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PjUU3NvvEE8SGD3RdpXWDr
BenWestgate added a commit that referenced this pull request Oct 1, 2026
Shorten Bitcoin Core verification and synchronization guidance to fit the supported Tails desktop, use current Zenity icon arguments on the touched surfaces, keep signer identity visible without clipping, and describe synchronization as starting only after the user acknowledges the modal dialog.

Keep this presentation-only: no fixed release-specific geometry, new UI framework, or dependency is added.

Refs #256
Refs #230
Refs #249
BenWestgate added a commit that referenced this pull request Oct 2, 2026
Shorten Bitcoin Core verification and synchronization guidance to fit the supported Tails desktop, use current Zenity icon arguments on the touched surfaces, keep signer identity visible without clipping, and describe synchronization as starting only after the user acknowledges the modal dialog.

Keep this presentation-only: no fixed release-specific geometry, new UI framework, or dependency is added.

Refs #256
Refs #230
Refs #249
BenWestgate added a commit that referenced this pull request Oct 7, 2026
Treat PersistentDirectory, GnuPG, and Dotfiles as the required Tails Persistent Storage features, present one concise list of missing features, and wait on tpscli state without repeated refocus or reminder loops.

Closes #251
Refs #230, #249, #267, #273, #276, #289
BenWestgate added a commit that referenced this pull request Oct 7, 2026
Move the installer to a stable working directory before the background persistence worker can delete the cloned source checkout. Later source accesses already use the absolute BAILS_DIR.

Closes #278
Refs #230, #249
BenWestgate added a commit that referenced this pull request Oct 7, 2026
Keep successful chainstate preload silent and replace low-memory modal UI with a transient informational notification.

Closes #281
Refs #256, #230, #249
BenWestgate added a commit that referenced this pull request Oct 7, 2026
Replace the blocking post-install guidance and terminal-kill countdown with one transient desktop notification, and wait for persistence before reporting update completion.

Closes #280
Refs #256, #230, #249, #261
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request help wanted Extra attention is needed priority: high issues raised or encountered by 2 or more testers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants