Skip to content

Commit ae3fd14

Browse files
committed
docs: Remove stale CL generation claims
Fresh Core Lightning generation was removed from the public API, but the architecture, capability table, identifier policy, and security model still described it as supported. Align those contracts with the remaining behavior: existing CL secrets may still be parsed, recovered, corrected, derived, and re-shared.\n\nRefs #128
1 parent b6a6de7 commit ae3fd14

3 files changed

Lines changed: 13 additions & 14 deletions

File tree

‎docs/developer/api.md‎

Lines changed: 9 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ The package uses one narrow dependency direction:
77
```text
88
text -> format/header/checksum -> optional profile module -> immutable artifact
99
|-> BIP93 sharing
10-
|-> ms/cl generation
10+
|-> ms generation
1111
|-> bounded correction
1212
`-> MasterSeed wallet adapter
1313
@@ -121,7 +121,7 @@ base artifact types rather than falling back to a registered application.
121121
| semantic S bytes | no | 16, 20, 24, 28, 32, or 64 | exactly 32 | no |
122122
| recovery and API share derivation | yes | yes | yes | yes |
123123
| `codex32` recovery/share/correction | yes | yes | yes | yes |
124-
| unshared generation / shared ceremony API | no | six supported sizes | exactly 32 bytes | no |
124+
| unshared generation / shared ceremony API | no | six supported sizes | no | no |
125125
| fresh generation CLI (`ms32`) | no | six supported sizes | no | no |
126126
| existing-S splitting | no | yes | yes | no |
127127
| wallet API | no | S only | no | no |
@@ -142,11 +142,10 @@ payload symbols; S requires zero outer padding and a valid embedded SHA-256
142142
checksum. Ordinary BIP39 shares are random masks and receive structural
143143
validation only.
144144

145-
CL generation is explicit and uses a random identifier unless one is supplied.
146145
Current Core Lightning defaults to mnemonic recovery, but its recovery command
147-
retains an import path for codex32 HSM secrets. Generated CL S strings use the
148-
zero-padding convention emitted by CLN; parsed nonzero discarded bits remain
149-
valid and are preserved when re-sharing.
146+
retains an import path for codex32 HSM secrets. CLN-produced codex32 S strings
147+
use its zero-padding convention; parsed nonzero discarded bits remain valid and
148+
are preserved when re-sharing.
150149

151150
The generic `codex32` façade supports CL and BIP39 inspection, correction,
152151
recovery, and share derivation. The `ms32` façade accepts only `ms` artifacts.
@@ -676,7 +675,7 @@ These choices are not presented as BIP93 requirements.
676675
| `ms` accepts only six seed sizes | follows the frozen PR #2258 profile with no legacy decoder |
677676
| random electronic output indices | reduces canonical index disclosure; explicit indices preserve requested order |
678677
| generation-only CRC padding | small recovery hint; not validity or share semantics |
679-
| fingerprint identifier only for fresh k=0 | shared sets, raw seeds, re-sharing, and CL generation use random IDs unless explicitly overridden |
678+
| fingerprint identifier only for fresh k=0 | shared sets, raw seeds, and re-sharing use random IDs unless explicitly overridden |
680679
| BIP39 profiles have no construction or wallet CLI | migration artifacts may still be checked, corrected, recovered, and re-shared generically |
681680
| reject existing derivation targets | enforces BIP93's fresh-index wording |
682681
| bounded structural correction is deliberately finite | exact capture safety, complete global rank layers, the 48-character ten-second target, and the package audit budget exclude a general recovery engine; longer valid strings keep the same bounded classes |
@@ -700,9 +699,9 @@ The four-character identifier is public metadata, not authentication.
700699
offline 20-bit predicate against candidate seeds.
701700
- A fresh shared set uses four independent random u5 symbols and leaks no
702701
seed-derived fingerprint bits.
703-
- Raw seed bytes, re-sharing, and CL generation use an independent random
704-
identifier unless the caller supplies all four symbols. A random identifier
705-
does not make a weak supplied seed safe.
702+
- Raw seed bytes and re-sharing use an independent random identifier unless the
703+
caller supplies all four symbols. A random identifier does not make a weak
704+
supplied seed safe.
706705
- Random re-sharing rejects the source set header and draws another identifier.
707706
An explicitly repeated source header remains an error.
708707

‎docs/security/model.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -120,9 +120,9 @@ full-payload OS-CSPRNG request. The current share string must be re-entered
120120
exactly, ignoring case and whitespace, before the next request. Confirmation
121121
text is never reparsed as the source secret and contributes no entropy. Existing
122122
complete Bitcoin master seeds are confirmed unchanged and initialize the wallet
123-
without new entropy. The `ms32` façade rejects CL; CL generation remains
124-
Python-API-only. Generic sharing, recovery, inspection, and correction are
125-
available through `codex32`.
123+
without new entropy. The `ms32` façade rejects CL. Existing CL secrets may still
124+
be parsed, recovered, inspected, corrected, derived, and re-shared through the
125+
generic API; fresh CL generation is not supported.
126126

127127
Creation retries show only entered text in contiguous regions: bold red means review the card, with reverse video added for the active region. Original card formatting is display-only; editable prefills retain entered case and spacing.
128128
Complete matching canonical groups freeze; local alignment preserves entered group ownership before edit minimization and proceeds without crossing frozen boundaries (see the API alignment rules).

‎src/codex32/generation.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
"""Electronic generation for ``ms`` and Core Lightning share sets."""
1+
"""Electronic master-seed generation and sharing of supported secrets."""
22

33
from __future__ import annotations
44

0 commit comments

Comments
 (0)