Skip to content

docs: Prepare the v1 review handoff #38

Description

@BenWestgate

Before freezing the v1 review candidate:

Field-test follow-ups #99–#104 now have a concrete v1 disposition. #99 removed the unrelated <5250 cap change, is below the authorized <5200 limit, has a current-head Codex ACK plus green Python/Core CI, and belongs in v1 because it closes the supplied adversarial audit's Bitcoin-Core-boundary UX gap. #100 is explicitly deferred to post-v1. #104 is also explicitly deferred: its recovery-identity delta has a focused security ACK, but the current implementation exceeds <5200 and is not required to close the supplied audit. #101 removed its cap change, is below <5200, and has a current-head Codex ACK plus green Python CI. #102 is docs-only, reviewed, and green. #103 is below <5200, has a complete focused security review with no reportable finding, a current-head follow-up ACK, and green exact-head CI. Before freeze, integrate or explicitly defer #101/#102/#103; no v1 decision depends on approving <5250.

The focused cleanup PRs are #115 (contributor guide), #116 (historical benchmark evidence), #117 (Core test-double signature), and #127 (all-report disposition ledger and remaining contract clarifications). #126 separately closes the previously missed existing-secret BIP32-root path from #125; merged #16 covered only raw bytes. The local ignored checklist docs/planning/v1-pre-review-cleanup.md records mechanical follow-ups for agents working in this checkout; verify each item on the frozen integration tip before the one-commit cleanup.

Post-audit release-gate fixes are #130 (#128, unauthenticated unused descriptor API) and #132 (#129, correction-edit default-rendering disclosure). Keep both in the frozen library candidate; they were found after the four supplied reports and are not retroactively attributed to those reviewers.

Human integration order

Use this order to avoid repeatedly invalidating reviewed stacks:

  1. Wallet: use Core for setup and remove test crypto deps #7 and its focused real-Core fixture follow-up ci: Verify wallet fixtures against Bitcoin Core #51 are merged into reviewability-v1.
  2. Already integrated into reviewability-v1: Wallet: use Core for setup and remove test crypto deps #7, correct: Interpret mixed-case damage #42, Define correction exit statuses #45, and Remove pre-review CLI dead code #46. Verify the current base tip, then begin the remaining restore stack at wallet: Require the recorded fingerprint before import #57; do not replay the historical correct: Interpret mixed-case damage #42 fixups.
  3. Integrate the refreshed library/CLI line in order wallet: Require the recorded fingerprint before import #57 → cli: Remove unreachable recovery and search paths #105 → cli: Name the real Bitcoin Core requirement when it is missing #99 → wallet: Distinguish unavailable Bails checks #80 → wallet: Check existing seed before sharing #81 → cli: Announce recovery secret switch #95. wallet: Require the recorded fingerprint before import #57 is replayed directly on current correct: Interpret mixed-case damage #42 with an unchanged reviewed patch-id. cli: Remove unreachable recovery and search paths #105 deliberately moves immediately after wallet: Require the recorded fingerprint before import #57 because its reviewed dead-code reduction keeps later tips below the authorized <5200 cap. cli: Name the real Bitcoin Core requirement when it is missing #99 is already based on cli: Remove unreachable recovery and search paths #105, has a current-head code ACK and green Python/Core CI, and closes the supplied audit's misleading hard-Core-boundary UX; place it before wallet: Distinguish unavailable Bails checks #80 because both cli: Name the real Bitcoin Core requirement when it is missing #99 and wallet: Distinguish unavailable Bails checks #80 touch the Core/CLI boundary. Then refresh wallet: Distinguish unavailable Bails checks #80 once onto cli: Name the real Bitcoin Core requirement when it is missing #99 and carry wallet: Check existing seed before sharing #81/cli: Announce recovery secret switch #95 forward without changing their reviewed behavior. Rerun the identity-mismatch regression, cli: Name the real Bitcoin Core requirement when it is missing #99 missing-Core/fallback regressions, wallet: Distinguish unavailable Bails checks #80 no-record/identifier regressions, wallet: Check existing seed before sharing #81 early-gate regressions, cli: Remove unreachable recovery and search paths #105 correction/CLI regressions, cli: Announce recovery secret switch #95 recovery-mode-switch regression, the real-Core fixture, and the final full suite on the resolved tip. cli: Remove unreachable recovery and search paths #105/cli: Name the real Bitcoin Core requirement when it is missing #99/wallet: Distinguish unavailable Bails checks #80/wallet: Check existing seed before sharing #81/cli: Announce recovery secret switch #95 contain agent-authored follow-ups and require the repository's responsible-human rewrite/squash policy before integration.
  4. Refresh onto that settled wallet: Require the recorded fingerprint before import #57 → cli: Remove unreachable recovery and search paths #105 → cli: Name the real Bitcoin Core requirement when it is missing #99 → wallet: Distinguish unavailable Bails checks #80 → wallet: Check existing seed before sharing #81 → cli: Announce recovery secret switch #95 tip, then integrate the small overlapping foundation fixes in dependency order: api: Remove unused public entry points #130 → wallet: Validate Bitcoin Core state types #12 → bip93: Reject non-ASCII normalized input #13 → bip93: reject HRPs longer than 83 characters #33 → correct: Redact correction edit characters #132. api: Remove unused public entry points #130 supersedes wallet: Privatize Core descriptor records #64 and should be replayed as its focused current API-removal patch, without restoring obsolete pre-Wallet: use Core for setup and remove test crypto deps #7 Core code. correct: Redact correction edit characters #132 follows bip93: reject HRPs longer than 83 characters #33 because both touch correction.py; preserve the reviewed bip93: reject HRPs longer than 83 characters #33 HRP behavior and apply the narrow correct: Redact correction edit characters #132 CorrectionEdit rendering change afterward. Where two overlap, preserve already-reviewed behavior and perform only the mechanical restack needed by the moved base.
  5. Integrate the audit/security/release support work that does not own runtime behavior: docs: Record security audit verdict #23, docs: Define trusted-computer boundary #59, and release: Qualify exact artifacts before publish #52.
  6. Refresh api: Expose reference-vector helpers #53 exactly once after bip93: Reject non-ASCII normalized input #13, bip93: reject HRPs longer than 83 characters #33, correct: Interpret mixed-case damage #42/wallet: Require the recorded fingerprint before import #57, api: Remove unused public entry points #130, and correct: Redact correction edit characters #132 are settled; Wallet: use Core for setup and remove test crypto deps #7 is already in the base. Preserve its supported module-level vector API and centralize the ASCII-only lower helper there. After api: Remove unused public entry points #130, package-level codex32.__all__ should contain 22 names; the api: Expose reference-vector helpers #53 module-level helper publication does not change that count. Rewrite/squash its Codex-authored follow-up under the responsible human author before merge. Then integrate focused generation: Validate roots before re-sharing #126 (existing-secret root validation; 953 normal and 953 optimized tests pass) and docs: Close adversarial audit tracking gaps #127 (complete finding dispositions and remaining API/user-guide clarifications). Both target the api: Expose reference-vector helpers #53 branch, not master. Their cleanup keeps the composed cli: Name the real Bitcoin Core requirement when it is missing #99 + root-validation proof below the existing library cap; no <5250 increase is needed.
  7. Refresh late user documentation on the settled runtime/API tip: docs: Trim offline signing to what Core's tutorial lacks #93 → docs: Size recovery cards to the backup length #96 → docs: Answer first-time questions in the user guide #97. docs: Trim offline signing to what Core's tutorial lacks #93's current bbf4daa defines the prepared Tails stick, shuts Core down before cloning Persistent Storage, separates the offline boot USB from transfer media, and requires unlocking storage with networking disabled. Its checks are completing. docs: Size recovery cards to the backup length #96 is reviewed and CI-green; both card print previews were verified at a77f83b. docs: Answer first-time questions in the user guide #97's 1cf1a17 is CI-green and fixes the two latest review findings: unshared identifier wording and the missing 256-bit card target. Record current-head review of these follow-ups, then apply the responsible-human rewrite/squash policy.
  8. Rebase the clean GUI stack onto the settled library/CLI tip and review it in order: gui: Add optional graphical interface #65 → gui: Refresh empty wallets automatically #66 → gui: Apply Tails field-test feedback #77 → gui: Let the home window choose its height #78 → test: Match GUI card walkthrough to responsive layout #119. test: Match GUI card walkthrough to responsive layout #119 updates the stale fixed-four-column Xvfb walkthrough and developer guide for gui: Apply Tails field-test feedback #77's intentional responsive card layout; its headless walkthrough passes, while the Tails visual resize pass remains required. Replay/squash the focused GUI restore-identity commit from draft gui: Require wallet identity before restore #118 after the clean GUI stack is on the settled library/CLI tip. gui: Require wallet identity before restore #118 uses a disposable gui: Let the home window choose its height #78 + bip93: reject HRPs longer than 83 characters #33 integration base only to make its diff testable; do not merge that staging base or gui: Require the recorded fingerprint before import #28's duplicated historical library snapshot as release commits. Resolve gui: Give home actions distinct artwork #76 from actual Tails visual evidence, then run the recorded Tails/manual GUI qualifications.
  9. Only after those tips are frozen, open the focused handoff-document PR required by this issue and pin the exact candidate commits.
  10. Run final artifact qualification and a fresh adversarial review over the frozen library, CLI, GUI, and user-facing recovery documentation before any human-authored master integration.

Keep planning notes out of the shipped documentation. This handoff is intentionally the last documentation change, after the implementation, packaging, security, GUI, and user-facing documentation integration stacks are settled; opening its PR earlier would make the required commit identifiers stale.

Refs #5.

The finished finding map is proposed in #127 at docs/security/adversarial-2026-10-04.md; it is not the final frozen-tip handoff. On 2026-10-04, a local #53/#126 proof with the reviewed #99 delta and #127's AST-equivalent cleanup passed 59 focused Core/CLI/disclosure tests and the official Core 32.0rc2 regtest fixture. These limited checks do not replace the final integrated full suite, artifact qualification, Tails visual pass, or GUI-to-Core qualification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: guiGraphical user interface behavior.area: packaging/releasePackaging, artifacts, compatibility, and release qualification.documentationImprovements or additions to documentationgate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions