You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Field-test follow-ups #99–#104 now have a concrete v1 disposition. #99 removed the unrelated <5250 cap change, is below the authorized <5200 limit, has a current-head Codex ACK plus green Python/Core CI, and belongs in v1 because it closes the supplied adversarial audit's Bitcoin-Core-boundary UX gap. #100 is explicitly deferred to post-v1. #104 is also explicitly deferred: its recovery-identity delta has a focused security ACK, but the current implementation exceeds <5200 and is not required to close the supplied audit. #101 removed its cap change, is below <5200, and has a current-head Codex ACK plus green Python CI. #102 is docs-only, reviewed, and green. #103 is below <5200, has a complete focused security review with no reportable finding, a current-head follow-up ACK, and green exact-head CI. Before freeze, integrate or explicitly defer #101/#102/#103; no v1 decision depends on approving <5250.
The focused cleanup PRs are #115 (contributor guide), #116 (historical benchmark evidence), #117 (Core test-double signature), and #127 (all-report disposition ledger and remaining contract clarifications). #126 separately closes the previously missed existing-secret BIP32-root path from #125; merged #16 covered only raw bytes. The local ignored checklist docs/planning/v1-pre-review-cleanup.md records mechanical follow-ups for agents working in this checkout; verify each item on the frozen integration tip before the one-commit cleanup.
Post-audit release-gate fixes are #130 (#128, unauthenticated unused descriptor API) and #132 (#129, correction-edit default-rendering disclosure). Keep both in the frozen library candidate; they were found after the four supplied reports and are not retroactively attributed to those reviewers.
Add docs/developer/reviewing.md with the exact base and pre-handoff integration commits, scope, review order, PR stack, evidence-regeneration commands, and intentional exclusions.
Replace the inherited Bitcoin Core boilerplate and dead links in CONTRIBUTING.md.
Mark the alignment benchmark as a snapshot of commit 6802d86; separate historical measurements from current verification, and identify the committed host-specific raw benchmark files as historical evidence rather than reproducible current measurements.
The maintainer approved a separate GUI cap of <2250 logical lines for the restore-identity gate. Draft gui: Require wallet identity before restore #118 updates the enforcement test and both developer guides; its GUI measures 2,177 lines. Keep the library <5200 cap separate.
Document the Core boundary precisely: ms32 secret and ms32 share require Bitcoin Core for fingerprint-aware recovery/output; ms32 correct connects to Core when a master-seed correction needs fingerprint ranking/output, while valid/no-result paths may finish before that connection. The corresponding generic codex32 secret / share / correct commands are the Core-independent fallback.
Record the deliberate mid-recovery secret behavior: if the operator supplies a complete valid S while entering shares, recovery stops using the partial share set and deliberately switches to that supplied secret. PR cli: Announce recovery secret switch #95 makes that mode switch explicit to the operator; it belongs in the frozen library/CLI candidate before the handoff.
Record the deliberate parser divergence for an unshared secret with threshold digit 1: v1 remains stricter than the BIP-93 reference decoder and accepts only the project's documented unshared/shared header forms. State this explicitly so interoperability reviewers do not mistake the difference for an untracked parser bug.
Point reviewers to the existing installed-package and GUI size-budget tests. The v1 installed-package cap is the maintainer-authorized <5200; do not take a pre-release refactor solely to recover the old <5000 target.
Record the deliberate v1 exception for mixed-case correction scheduling: the public correction engine and standalone CLI retain parallel orchestration through v1 because their search-planning contracts differ (CorrectionContext generic reachable lengths versus ms32 --bytes/profile/tie-break behavior). Both paths use the same required-before-optional ordering and capture-accounting contract and are covered by focused regressions plus the frozen differential verifier. Centralizing them is post-v1 architecture work; do not take a pre-release refactor solely to remove roughly 100 lines.
The final fresh adversarial review must cover the GUI as well as the library and CLI, with manual GUI test steps recorded for behavior that CI cannot exercise.
Link the guide from the final human-authored PR description, which must pin the complete candidate commit or commits. Human integration may squash/rewrite stacked AI-assisted follow-ups where the repository authorship policy requires it, after dependency order is settled.
Human integration order
Use this order to avoid repeatedly invalidating reviewed stacks:
Only after those tips are frozen, open the focused handoff-document PR required by this issue and pin the exact candidate commits.
Run final artifact qualification and a fresh adversarial review over the frozen library, CLI, GUI, and user-facing recovery documentation before any human-authored master integration.
Keep planning notes out of the shipped documentation. This handoff is intentionally the last documentation change, after the implementation, packaging, security, GUI, and user-facing documentation integration stacks are settled; opening its PR earlier would make the required commit identifiers stale.
The finished finding map is proposed in #127 at docs/security/adversarial-2026-10-04.md; it is not the final frozen-tip handoff. On 2026-10-04, a local #53/#126 proof with the reviewed #99 delta and #127's AST-equivalent cleanup passed 59 focused Core/CLI/disclosure tests and the official Core 32.0rc2 regtest fixture. These limited checks do not replace the final integrated full suite, artifact qualification, Tails visual pass, or GUI-to-Core qualification.
Before freezing the v1 review candidate:
Field-test follow-ups #99–#104 now have a concrete v1 disposition. #99 removed the unrelated
<5250cap change, is below the authorized<5200limit, has a current-head Codex ACK plus green Python/Core CI, and belongs in v1 because it closes the supplied adversarial audit's Bitcoin-Core-boundary UX gap. #100 is explicitly deferred to post-v1. #104 is also explicitly deferred: its recovery-identity delta has a focused security ACK, but the current implementation exceeds<5200and is not required to close the supplied audit. #101 removed its cap change, is below<5200, and has a current-head Codex ACK plus green Python CI. #102 is docs-only, reviewed, and green. #103 is below<5200, has a complete focused security review with no reportable finding, a current-head follow-up ACK, and green exact-head CI. Before freeze, integrate or explicitly defer #101/#102/#103; no v1 decision depends on approving<5250.The focused cleanup PRs are #115 (contributor guide), #116 (historical benchmark evidence), #117 (Core test-double signature), and #127 (all-report disposition ledger and remaining contract clarifications). #126 separately closes the previously missed existing-secret BIP32-root path from #125; merged #16 covered only raw bytes. The local ignored checklist
docs/planning/v1-pre-review-cleanup.mdrecords mechanical follow-ups for agents working in this checkout; verify each item on the frozen integration tip before the one-commit cleanup.Post-audit release-gate fixes are #130 (#128, unauthenticated unused descriptor API) and #132 (#129, correction-edit default-rendering disclosure). Keep both in the frozen library candidate; they were found after the four supplied reports and are not retroactively attributed to those reviewers.
docs/developer/reviewing.mdwith the exact base and pre-handoff integration commits, scope, review order, PR stack, evidence-regeneration commands, and intentional exclusions.CONTRIBUTING.md.6802d86; separate historical measurements from current verification, and identify the committed host-specific raw benchmark files as historical evidence rather than reproducible current measurements.reviewability-v1exports 24 names; focused api: Remove unused public entry points #130 supersedes wallet: Privatize Core descriptor records #64 by removing obsoletecore_descriptorsplus unused fresh Core Lightning generation exports, so the frozen v1 package__all__should contain 22 names after api: Remove unused public entry points #130. api: Expose reference-vector helpers #53 adds supported reference-vector helpers at their owning modules and deliberately does not add them to package-levelcodex32.__all__.<2250logical lines for the restore-identity gate. Draft gui: Require wallet identity before restore #118 updates the enforcement test and both developer guides; its GUI measures 2,177 lines. Keep the library<5200cap separate.ms32 secretandms32 sharerequire Bitcoin Core for fingerprint-aware recovery/output;ms32 correctconnects to Core when a master-seed correction needs fingerprint ranking/output, while valid/no-result paths may finish before that connection. The corresponding genericcodex32 secret/share/correctcommands are the Core-independent fallback.Swhile entering shares, recovery stops using the partial share set and deliberately switches to that supplied secret. PR cli: Announce recovery secret switch #95 makes that mode switch explicit to the operator; it belongs in the frozen library/CLI candidate before the handoff.1: v1 remains stricter than the BIP-93 reference decoder and accepts only the project's documented unshared/shared header forms. State this explicitly so interoperability reviewers do not mistake the difference for an untracked parser bug.<5200; do not take a pre-release refactor solely to recover the old<5000target.CorrectionContextgeneric reachable lengths versusms32 --bytes/profile/tie-break behavior). Both paths use the same required-before-optional ordering and capture-accounting contract and are covered by focused regressions plus the frozen differential verifier. Centralizing them is post-v1 architecture work; do not take a pre-release refactor solely to remove roughly 100 lines.a77f83bwas printed by Chromium 154 on 2026-10-04: both templates are one 792×612 pt US-letter landscape page; 160-dpi raster inspection found all 12 and 19 numbered boxes visible, including the half-width final box, with no clipping or overlap. A physical paper proof remains optional human qualification. docs: Answer first-time questions in the user guide #97 states that 54/61/67/127-character backups do not yet have dedicated templates. Claude/agent-authored documentation commits require responsible-human rewrite/squash before integration.ms32 create --existingwallet-record decision before any new share ceremony, cli: Remove unreachable recovery and search paths #105's final unreachable-path cleanup (the patch-identical replacement for historical cli: Remove unreachable recovery and search paths #98), cli: Name the real Bitcoin Core requirement when it is missing #99's audited Core-boundary/error-path fix, and cli: Announce recovery secret switch #95's explicit mid-recovery secret-switch notice. The GUI candidate must include gui: Add optional graphical interface #65 plus gui: Refresh empty wallets automatically #66, Tails field-test PR gui: Apply Tails field-test feedback #77 (closing gui: Keep card-count choices neutral #71–gui: Fit the finished wallet identity on one screen #74), gui: Let the home window choose its height #78 (closing gui: Size the home window to its content #75), and the reviewed restore-authentication behavior. gui: Refresh empty wallets automatically #66's automatic wallet refresh must preserve an explicit selection when possible, disable Continue if that wallet disappears, retry transient read-only refresh failures, and allow read-only poll workers to end with the process while mutation/relocking workers remain non-daemon. gui: Apply Tails field-test feedback #77/gui: Let the home window choose its height #78 still require the supported Tails guest-resolution visual checks before the candidate is frozen. gui: Give home actions distinct artwork #76 is explicitly deferred until that Tails visual pass identifies which already-distinct bundled book graphics are being confused; do not guess an asset replacement from source filenames alone.Human integration order
Use this order to avoid repeatedly invalidating reviewed stacks:
reviewability-v1.reviewability-v1: Wallet: use Core for setup and remove test crypto deps #7, correct: Interpret mixed-case damage #42, Define correction exit statuses #45, and Remove pre-review CLI dead code #46. Verify the current base tip, then begin the remaining restore stack at wallet: Require the recorded fingerprint before import #57; do not replay the historical correct: Interpret mixed-case damage #42 fixups.<5200cap. cli: Name the real Bitcoin Core requirement when it is missing #99 is already based on cli: Remove unreachable recovery and search paths #105, has a current-head code ACK and green Python/Core CI, and closes the supplied audit's misleading hard-Core-boundary UX; place it before wallet: Distinguish unavailable Bails checks #80 because both cli: Name the real Bitcoin Core requirement when it is missing #99 and wallet: Distinguish unavailable Bails checks #80 touch the Core/CLI boundary. Then refresh wallet: Distinguish unavailable Bails checks #80 once onto cli: Name the real Bitcoin Core requirement when it is missing #99 and carry wallet: Check existing seed before sharing #81/cli: Announce recovery secret switch #95 forward without changing their reviewed behavior. Rerun the identity-mismatch regression, cli: Name the real Bitcoin Core requirement when it is missing #99 missing-Core/fallback regressions, wallet: Distinguish unavailable Bails checks #80 no-record/identifier regressions, wallet: Check existing seed before sharing #81 early-gate regressions, cli: Remove unreachable recovery and search paths #105 correction/CLI regressions, cli: Announce recovery secret switch #95 recovery-mode-switch regression, the real-Core fixture, and the final full suite on the resolved tip. cli: Remove unreachable recovery and search paths #105/cli: Name the real Bitcoin Core requirement when it is missing #99/wallet: Distinguish unavailable Bails checks #80/wallet: Check existing seed before sharing #81/cli: Announce recovery secret switch #95 contain agent-authored follow-ups and require the repository's responsible-human rewrite/squash policy before integration.correction.py; preserve the reviewed bip93: reject HRPs longer than 83 characters #33 HRP behavior and apply the narrow correct: Redact correction edit characters #132CorrectionEditrendering change afterward. Where two overlap, preserve already-reviewed behavior and perform only the mechanical restack needed by the moved base.codex32.__all__should contain 22 names; the api: Expose reference-vector helpers #53 module-level helper publication does not change that count. Rewrite/squash its Codex-authored follow-up under the responsible human author before merge. Then integrate focused generation: Validate roots before re-sharing #126 (existing-secret root validation; 953 normal and 953 optimized tests pass) and docs: Close adversarial audit tracking gaps #127 (complete finding dispositions and remaining API/user-guide clarifications). Both target the api: Expose reference-vector helpers #53 branch, not master. Their cleanup keeps the composed cli: Name the real Bitcoin Core requirement when it is missing #99 + root-validation proof below the existing library cap; no<5250increase is needed.bbf4daadefines the prepared Tails stick, shuts Core down before cloning Persistent Storage, separates the offline boot USB from transfer media, and requires unlocking storage with networking disabled. Its checks are completing. docs: Size recovery cards to the backup length #96 is reviewed and CI-green; both card print previews were verified ata77f83b. docs: Answer first-time questions in the user guide #97's1cf1a17is CI-green and fixes the two latest review findings: unshared identifier wording and the missing 256-bit card target. Record current-head review of these follow-ups, then apply the responsible-human rewrite/squash policy.Keep planning notes out of the shipped documentation. This handoff is intentionally the last documentation change, after the implementation, packaging, security, GUI, and user-facing documentation integration stacks are settled; opening its PR earlier would make the required commit identifiers stale.
Refs #5.
The finished finding map is proposed in #127 at
docs/security/adversarial-2026-10-04.md; it is not the final frozen-tip handoff. On 2026-10-04, a local #53/#126 proof with the reviewed #99 delta and #127's AST-equivalent cleanup passed 59 focused Core/CLI/disclosure tests and the official Core 32.0rc2 regtest fixture. These limited checks do not replace the final integrated full suite, artifact qualification, Tails visual pass, or GUI-to-Core qualification.