Skip to content

generation: Validate existing Bitcoin roots before sharing #125

Description

@BenWestgate

CreationCeremony.from_secret() accepts a Bitcoin MasterSeed without calling
the existing stdlib BIP32 root validator. It can emit recovery cards for a seed
whose BIP32 root is invalid. Kimi F7 / consolidated M8 reported this path as well
as the supplied-byte path; merged #16 fixes only the latter.

Reproduction on #53 (cde312b): construct a synthetic MasterSeed, force
codex32.generation._valid_root to return False, then call from_secret()
and next_share(). A share is returned and the validator is never called.
The forced validator models the extremely rare zero/out-of-range HMAC scalar;
this is a correctness failure, not evidence of a practical attack.

Reject before identifier randomness or any share output. Preserve valid Bitcoin
re-sharing, codex32 format parsing, and Core Lightning behavior. Refs #20, #16.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiPublic and supported Python API boundaries.area: bip93BIP93 encoding, checksum, parsing, and format rules.bugSomething isn't workinggate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions