Repository navigation
Release 0.7.0: v1 library, CLI and docs in 9 reviewable commits - #142
BenWestgate wants to merge 9 commits into
Conversation
|
CodeQL is red, and this PR doesn't add the code it flags. The two Clearing the check needs a maintainer decision on those two alerts in code scanning, which I can't do from here. Generated by Claude Code |
c4d8e63 to
04d7362
Compare
Rewrite the BIP93 encoding, checksum, sharing and profile layers of the v0.6.1 code (byte-identical to 4857e18, ACKed in BlockstreamResearch/codex32#74) as frozen, typed values with no third-party dependency. - gf32/checksums/bech32: immutable checksum specs, GF(32) tables and strict single-case Bech32 parsing; drop the unused segwit_addr module. - bip93: Header/Share/Secret values, parse_codex32, derive_share and recover_secret. There is no public encoder from raw (padded) bytes to a share; shares come only from interpolation. - profiles: ms (BIP32 master seed), cl (Core Lightning hsm_secret, unshared only) and bip39 entropy. - Tooling: drop mypy.ini, requirements.txt and the pylint job; add ruff, strict mypy and a hash-pinned setuptools build dependency. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add master_xprv(), backed by a minimal private BIP32 root derivation that stops at the root; child derivation is left to Bitcoin Core. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add generate_master_seed() and CreationCeremony, which issues shares one at a time and only finishes after each one has been read back correctly. Fresh seeds use CRC padding and the BIP32 fingerprint identifier. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add correct() and correct_worksheet_residue(). Substitutions and erasures are decoded within the BCH bounds; insertions and deletions use a bounded alignment search. Every candidate is untrusted and carries its capture volume. Constants are checked against the frozen PR #70 corpus. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add the deadline-bounded scheduler that proves which competing alignments cannot outrank a found candidate, so interactive callers get a ranked answer quickly. Include the alignment benchmark tool and its summary. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add the Bitcoin Core v32 adapter used by the CLI to import a master xprv and let Core derive descriptors, plus a regtest fixture job that checks every frozen wallet fingerprint against a pinned Core release. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add the command-line interface: argument parsing, protected terminal input with group-by-group correction, and the create, share, recover, correct and wallet commands. The production code stays within a 5200-line budget. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Rewrite the README and add the user guide, printable cards, API reference, security model and invariants, contribution guide, security policy and AI policy. Replace the Copilot instructions with AGENTS.md. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Bump the version, replace the publish workflow with a reproducible, hash-pinned build that attaches distributions to the GitHub release, and verify the installed wheel in CI. Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
04d7362 to
51c0794
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head review: Concept ACK to the nine-commit 0.7.0 split. Current 24 checks are green (including CodeQL); nine commits have verified signatures. Targeted security review found no immediate issue in fingerprint-before-wallet selection, no-shell Core RPC, or OS entropy. Still draft: complete an independent security review of generation, correction and wallet import; verify final artifacts and the Tails/Core restore path before release. No full security-scan ACK yet.
Requested by Ben · project thread
Before: master has the v0.6 library only (PyPI 0.6.1). The v1 work lives on
reviewability-v1as 88 commits with plans, gates and add-then-remove churn, so it's hard to review from the ACKed code.After: master gets the v1 library, the
codex32/ms32CLI and the new README as 0.7.0, in 9 atomic commits (about +18k lines). Each commit passes ruff, ruff format, strict mypy and its tests on its own.The final tree equals
reviewability-v1+ #143 (drop raw benchmark data) at e976c8c except for two differences. The version is0.7.0instead of1.0.0rc1, and master's FUNDING.yml, scorecard.yml and stale.yml are kept.Provenance. BlockstreamResearch/codex32#74 commit 4857e18 (ACKed by apoelstra) contains
src/andtests/that are byte-identical to4bb90c0(tag v0.6.1) and to the PyPI 0.6.1 sdist and wheel. Master descends from4bb90c0through 14 small CI, README and version commits. Sogit diff 4bb90c0 HEADreviews everything since the ACKed code.-O), constants, differential, build and wheel checksHow: a script takes each commit's files from the target verbatim. Only hub files get intermediate versions:
__init__.pyexports,pyproject.toml, the CI workflow, a step-1 README usage example, andindel.pywithout the competitor hook until commit 5. The script, its overlays and the verification log are in the project files underv1-rebuild/.Notes for the reviewer:
reviewability-v1.reviewability-v1work, unchanged.🤖 Generated with Claude Code
https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K