You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A checksum-valid recovered seed may not be the operator’s wallet. Ask for the independent record fingerprint before listing wallets, then carry it through existing and newly created destinations so a mismatch stops before unlock, create, or import. Keep the explicit no-record visual fallback, but do not allow its revealed fingerprint back into the recorded route in the same attempt.
Raise the separately enforced GUI review cap to the authorized 2,250 lines for this gate. Keep the combined Python 3.10-3.15 package compatible with the GUI code and passphrase encoding check. Exercise the focused boundary and display walkthrough with synthetic data.
Refs #26 and #28.
Copy file name to clipboardExpand all lines: docs/security/model.md
+10Lines changed: 10 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -259,6 +259,16 @@ initialization.
259
259
`codex32_gui/wallet_setup.py`, the only module in that package that imports the
260
260
Core adapter.
261
261
262
+
Before listing wallets on restore, the GUI asks for the master fingerprint from
263
+
the separate wallet record without showing the recovered value. A mismatch
264
+
stops the attempt. The explicit no-record route reveals the recovered
265
+
fingerprint and backup-identifier assessment, then requires **Restore anyway**;
266
+
after that disclosure, this attempt cannot return to the record-entry route.
267
+
The chosen expected fingerprint is checked again before unlocking or creating
268
+
a destination and at the shared library import boundary. Fresh creation instead
269
+
shows its new fingerprint for the operator to record; there is no earlier
270
+
wallet identity to compare.
271
+
262
272
| Departure | Required behavior |
263
273
|---|---|
264
274
| Passphrase | The operator may supply a Bitcoin Core wallet passphrase. It reaches `bitcoin-cli` through `-stdinwalletpassphrase`, never through an argument, so it is absent from `/proc` and process listings. It is not stored, not logged, and not written to disk, and a passphrase containing a line break is refused rather than truncated. A passphrase this computer's locale would encode as something other than what Bitcoin-Qt sends is refused, so no half-encoded secret reaches a screen or a traceback. The screen keeps the command line's behavior as an alternative: the operator may unlock in Bitcoin-Qt instead, and the program then only rechecks wallet state. |
0 commit comments