Skip to content

docs: Record BIP138 security audit - #237

Merged
BenWestgate merged 1 commit into
215-python-codex32-restorefrom
236-bip138-security-docs
Sep 23, 2026
Merged

BenWestgate merged 1 commit into
215-python-codex32-restorefrom
236-bip138-security-docs

Conversation

@BenWestgate

Copy link
Copy Markdown
Owner

Closes #236.

Records the recovery audit verdict and Bails integration requirements for BIP138.

Key boundary: successful BIP138 decryption must not authorize descriptor activation. Imported policy stays inactive/quarantined until independently committed wallet/policy identity is verified.

Also records the Codex32 set-authentication limits relevant to Bails and the ChaCha20-Poly1305 implementation note.

Validation: git diff --check passes.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 050a153887

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/security/bip138-audit-2026-09-22.md
@BenWestgate
BenWestgate force-pushed the 236-bip138-security-docs branch from a5a4538 to 2fe68cf Compare September 23, 2026 12:13

Copy link
Copy Markdown
Owner Author

Base branch #230 advanced during review; this PR is now non-mergeable against the current base. Please rebase onto the current 215-python-codex32-restore head before human review.

Record the reviewed BIP138 recovery findings, pinned revisions, revalidation status, and Bails integration requirements as one documentation change.

Closes #236.
@BenWestgate
BenWestgate force-pushed the 236-bip138-security-docs branch from 2fe68cf to 4e1cd48 Compare September 23, 2026 22:11
@chatgpt-codex-connector

This comment has been minimized.

@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review this PR

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 4e1cd483f0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good to me, documentation only changes about BIP138 support in bails. Recommend delaying until the weaknesses are ironed out and well reviewed implementations exist.

@BenWestgate
BenWestgate merged commit bd6ed69 into 215-python-codex32-restore Sep 23, 2026
1 of 2 checks passed
@BenWestgate
BenWestgate deleted the 236-bip138-security-docs branch September 23, 2026 23:15
BenWestgate added a commit that referenced this pull request Sep 24, 2026
Rebuilt onto 201-simplify-this-project-by-removing-bails-wallet. The
previous branch shared no ancestor with its own base: its first commit
was a repository root holding a whole-tree snapshot, so every file
collided as added-by-both and the branch carried a stale copy of the
tree alongside the feature.

Replayed here is only what the branch actually contributed: the
install-codex32 and open-codex32 scripts, the Codex32 desktop entry, the
security documentation merged as #237, and the README text describing
the restore flow.

Deliberately not replayed are the four files where the snapshot was
simply older than master and would have reverted it, namely
chainstate-preload, install-core, link-dotfiles and the bitcoin-qt
desktop entry, together with the three documents the base has since
consolidated.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant