CreationCeremony.from_secret() accepts a Bitcoin MasterSeed without calling
the existing stdlib BIP32 root validator. It can emit recovery cards for a seed
whose BIP32 root is invalid. Kimi F7 / consolidated M8 reported this path as well
as the supplied-byte path; merged #16 fixes only the latter.
Reproduction on #53 (cde312b): construct a synthetic MasterSeed, force
codex32.generation._valid_root to return False, then call from_secret()
and next_share(). A share is returned and the validator is never called.
The forced validator models the extremely rare zero/out-of-range HMAC scalar;
this is a correctness failure, not evidence of a practical attack.
Reject before identifier randomness or any share output. Preserve valid Bitcoin
re-sharing, codex32 format parsing, and Core Lightning behavior. Refs #20, #16.
CreationCeremony.from_secret()accepts a BitcoinMasterSeedwithout callingthe existing stdlib BIP32 root validator. It can emit recovery cards for a seed
whose BIP32 root is invalid. Kimi F7 / consolidated M8 reported this path as well
as the supplied-byte path; merged #16 fixes only the latter.
Reproduction on #53 (
cde312b): construct a syntheticMasterSeed, forcecodex32.generation._valid_rootto returnFalse, then callfrom_secret()and
next_share(). A share is returned and the validator is never called.The forced validator models the extremely rare zero/out-of-range HMAC scalar;
this is a correctness failure, not evidence of a practical attack.
Reject before identifier randomness or any share output. Preserve valid Bitcoin
re-sharing, codex32 format parsing, and Core Lightning behavior. Refs #20, #16.