You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 53cd58b
Browse filesBrowse the repository at this point in the historyBrowse files
wallet: Require the recorded fingerprint before import
Check the recorded master fingerprint before any wallet selection, unlock, creation, or descriptor import. Apply the same restore gate to `ms32 wallet` and `ms32 create --existing`, including re-sharing; fresh creation only records the newly created identity.
Without a wallet record, show the recovered fingerprint, backup identifier, supported codex32/Bails identifier evidence, and the explicit no-record warning before mutation.
Security: this is the release-gate accident-safety boundary for wrong or mixed recovery material. Malicious replacement resistance remains the separate authenticated-descriptor work in #55.
Validation on the identical pre-rewrite tree: full Python package matrix green; focused mismatch tests prove no Core RPC mutation occurs before identity verification.
Fixes#30. Refs #26.
| Preflight | Before entropy or recovery input, explicit chain arguments probe the five standard local networks for Bitcoin Core 32 or newer. One response is selected automatically; multiple responses require operator selection. |
232
+
| Recovery identity |`ms32 wallet` authenticates a recovered seed before any wallet is listed. Core derives the recovered fingerprint statelessly, and a mismatch raises `FingerprintMismatch` before any wallet RPC. The restore prompt does not show the recovered value, so the operator compares by typing the fingerprint from the wallet record. Without a record, the operator is shown the recovered fingerprint, whether the backup identifier was derived from the seed (the codex32 fingerprint rule, Bails' RIPEMD-160 rule, or its mid-2023 alpha's SHA-256 rule), and a warning, and then chooses. `ms32 create` does not authenticate against a pre-existing wallet: it shows the newly created seed's fingerprint and requires the operator to acknowledge recording it. These checks catch mistakes such as wrong or mixed cards; anyone able to replace a threshold of cards could already read them. |
231
233
| Process boundary | codex32 invokes the reviewed `bitcoin-cli` from `PATH` as a child without a shell, direct RPC socket, wallet database, or wallet-creation operation. Every call uses loopback and the selected chain. |
232
234
| Destination | Only an empty descriptor wallet with private keys enabled, no external signer, transactions, descriptors, keypool entries, or active scan is eligible. One eligible wallet is offered directly; multiple wallets are selected by number. New wallets are detected by polling, and rejection returns to every eligible wallet. The escaped name is confirmed exactly. |
233
235
| Seed source | The original ceremony result or validated recovered master seed supplies root-xprv private descriptors for Core's reported chain. After import, Core v32's wallet HD-key RPCs derive the requested BIP44, BIP49, BIP84, and BIP86 account xpubs. |
0 commit comments