You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a9b9778
Browse filesBrowse the repository at this point in the historyBrowse files
Close Gate 0 by restricting only fresh CLI master-seed generation to 16- and 32-byte sizes while preserving the full BIP93 API and import range. Bound explicit share-index selectors before copying or normalization to resolve the delegated scan's low-severity availability finding.
Reserve 1.0.0rc1, pin the formatter baseline, and align security, capability, provenance, dependency, traceability, and accepted-risk records with the implemented behavior. Add direct regression coverage for every changed boundary.
| ID | Risk and exposure | Disposition and controls | Review trigger |
8
+
|---|---|---|---|
9
+
| AR-001 | Pending BIP93 PR #2258 changes the checksum boundary for expanded HRPs. `ms` strings carrying 44--46-byte seeds can be incompatible with software implementing only the currently published BIP93 rule. | Accepted pending-standard compatibility risk. Follow the frozen PR head and boundary vectors; do not add ambiguous dual decoding. Fresh CLI generation permits only 16 or 32 bytes. The API and imported existing seeds retain all 16--64-byte BIP93 sizes. | Recheck the exact upstream revision before the RC and final release; reassess if the PR changes, closes, or merges differently. |
10
+
| AR-002 | Root-key and wallet derivation rely on `bip32` and its native secp256k1 dependency stack, which this project does not independently audit. | Accepted architecture boundary. Keep all interaction in `_bip32.py`; retain official BIP32, BIP48, descriptor, and wallet fixtures. Gate 2 must add reproducible hash-pinned CLI constraints and cross-platform evidence. | Any resolved dependency change, adapter change, vector failure, advisory, or unsupported release artifact. |
11
+
| AR-003 | A fresh unshared `ms` identifier reveals 20 bits of the BIP32 fingerprint. Identifiers and checksums are public metadata, not authentication. | Accepted BIP93 usability/privacy tradeoff. Shared sets, supplied raw seeds, re-sharing, and CL generation instead use random or explicit identifiers. | Any workflow starts treating an identifier as secret, unique, or proof of wallet identity. |
12
+
| AR-004 | Python and terminal environments cannot guarantee secret zeroization, locked memory, constant-time execution, or removal from scrollback and editor memory. | Accepted implementation-platform limitation. Keep protected material out of argv and machine stdout, disable automatic line history, and document offline use. | A supported runtime or interface adds a stronger secret-memory or terminal boundary. |
13
+
14
+
These dispositions were accepted by the production-ready v1 roadmap. New or
15
+
materially changed risks require explicit human acceptance; agents may record
Copy file name to clipboardExpand all lines: docs/divergences.md
+10-5Lines changed: 10 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,16 +4,21 @@ These choices are not presented as BIP93 requirements.
4
4
5
5
| Decision | Reason |
6
6
|---|---|
7
-
| support every 16–64-byte `ms` length | BIP93 permits them; closed PR #2077 is research only |
7
+
|API and imports support every 16–64-byte `ms` length | BIP93 permits them; closed PR #2077 is research only; fresh CLI generation is deliberately limited to 16 or 32 bytes|
8
8
| random electronic output indices | reduces canonical index disclosure; explicit indices preserve requested order |
9
9
| generation-only CRC padding | small recovery hint; not validity or share semantics |
10
-
| fingerprint identifier only for fresh k=0 | shared sets use random IDs; raw seeds and re-sharing require explicit IDs |
10
+
| fingerprint identifier only for fresh k=0 | shared sets, raw seeds, re-sharing, and CL generation use random IDs unless explicitly overridden|
11
11
| BIP39 profiles are migration-only in CLI | website marks them not recommended; API can recover/derive codex32 only |
| fixed BCH only |structural search/ranking added excessive unauditable policy and code|
13
+
| fixed BCH is the current shipped behavior | a bounded structural adapter ships only if the cuttable Gate 3 passes its completeness, performance, size, and audit conditions|
14
14
| private descriptors contain root xprv | matches Bitcoin Core behavior and carries an explicit authority warning |
15
15
| no partial-basis completion | unauthenticated points can create incompatible same-header polynomials |
|[checksum-boundary PR #2258](https://github.com/bitcoin/bips/pull/2258)| head `7c5251d29acc1446b1b7ed86cc1ab2327bf78271`| expanded-HRP short/long selection and 94/95 gap |
9
+
|[checksum-boundary PR #2258](https://github.com/bitcoin/bips/pull/2258)| head `7c5251d29acc1446b1b7ed86cc1ab2327bf78271`|accepted pending-standard expanded-HRP short/long selection and 94/95 gap |
10
10
|[wallet guidance](https://github.com/BlockstreamResearch/codex32/blob/1a1c22aa895d78f2d385303feb9491d155e14cf7/docs/wallets.md)|`BlockstreamResearch/codex32@1a1c22aa895d78f2d385303feb9491d155e14cf7`| import and worksheet UX |
| R03 | regular ≤93, gap 94/95, Long ≤1023 expanded symbols | same format helper, checksum specs | generic vectors and exact endpoints | Implemented; accepted pending-standard risk|
11
+
| R04 |`ms`API and imports accept every 16–64-byte seed and legal pad |`MasterSeed`| all 49 lengths, every pad value, and CLI imported-size boundaries| Implemented |
12
12
| R05 | k=0/S; k=2–9/S or ordinary index |`Header`| header abuse and B93 invalid vectors | Implemented |
13
13
| R06 | invalid checksum cannot enter domain APIs |`parse_codex32` artifact boundary | negative parser/public API tests | Implemented |
14
14
| R07 | recover from exactly k compatible distinct shares |`recover_secret`| B93 vectors 2/3, k=2–9, mismatch properties | Implemented |
@@ -20,7 +20,7 @@ Every implemented claim identifies one code owner and direct evidence.
| R15 | only `ms` S enters wallet workflows |`wallet._master`| all non-`MasterSeed` types rejected | Implemented |
23
-
| R16 | electronic generation defaults to 128 bits| generation API and CLI `create`|default and complete creation matrix| Implemented |
23
+
| R16 | electronic generation defaults to 128 bits; fresh CLI `ms` is 16/32 bytes while the API remains 16–64 | generation API and CLI `create`|API all-length tests; CLI accepted/rejected/imported-size boundaries| Implemented |
24
24
| R17 | worksheet checksum sizes and private residue correction | CLI `checksum`, residue API | ms/cl sizes, short/long and BIP39 residues | Implemented |
25
25
| R18 | identifier selection is public metadata |`generation` identifier helpers | k=0 fixture, random defaults, explicit override | Accepted divergence |
26
26
| R19 |`cl` custom ID, 32-byte payload, import and generation |`Profile.CL`, `CoreLightningSecret`, `generate_core_lightning_secret`| published examples, import evidence, generation/recovery and padding tests | Implemented |
@@ -33,8 +33,11 @@ Every implemented claim identifies one code owner and direct evidence.
33
33
| R26 | explicit account/timestamp, mandatory Core mode, root-xprv warning | wallet API and CLI | deterministic records, public/private separation and warning tests | Implemented |
34
34
| R27 | no arbitrary security parser for descriptors | fixed templates in `wallet.py`| module/API absence and template fixtures | Implemented by removal |
| R29 | explicit share-index selectors are bounded before copying or normalizing elements |`generation._indices`| oversized string pre-normalization regression across all three public generation APIs | Implemented from standard security scan |
36
37
37
38
The expanded checksum rule from PR #2258 is the only pending-upstream behavior.
38
-
It has direct boundary fixtures and is isolated in one format-layer function.
39
-
All remaining production-release work and gate dependencies are recorded in
0 commit comments