gui: Ask for cards, a record and marked look-alikes - #113
BenWestgate wants to merge 6 commits into
Conversation
A tester made a 2-of-3 wallet through Bails without ever seeing the printable recovery card or wallet-verification record. The create flow went straight from choosing a layout to the first card, yet its last page and every restore depend on that record. Add a "Before you start" page between the layout choice and the first card. It names how many blank cards to get, explains what the wallet record is for, and opens either printable form with Gtk.FileLauncher. If a form does not open, the page shows where it is. Move both forms into the codex32_gui package so an installed GUI can find them, and update the links. Raise the GUI size budget from 2000 to 2050 lines for the new page. Refs BenWestgate/Bails#314
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7181c7b70e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Gtk.FileLauncher only exists from GTK 4.10, and the install notes accept any GTK 4. On an older GTK the form buttons now say where the form is instead of raising AttributeError. The security model and the GUI claims said the window starts no process of its own. The form buttons ask the desktop to open a bundled blank form, so say so, and check that _ready_page is the only place that hands a file to the desktop. Refs BenWestgate/Bails#314
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4d53a4a426
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
On Tails, Tor Browser may only read ~/Tor Browser and its persistent twin, so it shows an error page for a form inside the Persistent Storage checkout. FileLauncher reports only that an application started, so the path fallback never appears. Read CODEX32_FORMS_DIR, if set, as the folder holding the forms. Bails can copy them under ~/Tor Browser before starting the GUI and set it. Refs BenWestgate/Bails#314
Three testers misread their own cards: 5 and S, 6 and G, and 0 against the letter O. 5, S, 6, G, 2 and Z are all in the bech32 alphabet, so read-back cannot tell them apart the way it flags O, B, I and 1. Show a handwriting key on the page where each card is written, and repeat it on the printable recovery card: slash 0, cross 7 and Z, draw S like $ (the Codex32 book's marks) and dot the loop of 6, which the book leaves open. Refs BenWestgate/Bails#314
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c1863df760
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ) | ||
| CORE_ADAPTER = "codex32._bitcoin_core" | ||
| BUDGET = 2000 | ||
| BUDGET = 2050 |
There was a problem hiding this comment.
Keep the GUI budget aligned with its contract
Raising this guard to 2,050 lets the new 2,037-line GUI pass even though docs/developer/gui.md still defines a 2,000-line budget, while docs/developer/api.md requires any budget change to receive explicit authorization and a matching documentation update. This makes the test stop enforcing the documented reviewability boundary; either keep the package below 2,000 lines or update the documented budget as part of an authorized change.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
4d65adc updates the budget in both docs/developer/gui.md and docs/developer/api.md, the latter of which still said 1,800. The raise still needs the maintainer's authorization, as the PR description says. If it isn't approved, the page gets cut back instead.
Generated by Claude Code
The guard in tests/test_gui_boundaries.py moved to 2,050 for the new page, but gui.md still said 2,000 and api.md still said 1,800. api.md requires a budget change to land with its documentation, so update both. The raise itself still needs the maintainer's approval. Refs BenWestgate/Bails#314
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4d65adc189
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The launch tests replaced Gtk.FileLauncher but left the real Gtk.check_version in charge, so on GTK before 4.10 they would raise or take the fallback branch. Pin check_version to a modern GTK and allow adding the attribute where it is missing. Refs BenWestgate/Bails#314
Requested by Ben · project thread
Before: after you choose how many cards you want, the GUI shows the first card straight away. Nothing asks for blank cards or a wallet record, and nothing shows the printable forms. Yet the last page says "Copy these onto your wallet record", and restore asks for the fingerprint from that record. A Bails tester finished a 2-of-3 wallet without ever seeing either form (BenWestgate/Bails#314). Three testers also misread their own handwriting: 5/S, 6/G and 0/O.
After: a Before you start page comes between the layout choice and the first card. It says how many blank recovery cards to get, explains what the wallet record is for, and has buttons that open the recovery card and wallet record forms. Each Write it down page, and the printable card, also carries a handwriting key: slash every 0, cross 7 and Z, draw S like $, and put a dot inside the loop of 6.
How
pages._ready_pageis pushed from_layout_pageinstead of calling_begin_cardsdirectly. Each button opens a form withGtk.FileLauncher. If the launch fails, or GTK is older than 4.10, the page shows the form's path instead.CODEX32_FORMS_DIR, when set, names the folder to open the forms from. On Tails, Tor Browser may only read~/Tor Browser, so Bails will copy the forms there and set this variable.recovery-card.htmlandwallet-verification-record.htmlmove fromdocs/user/tosrc/codex32_gui/forms/and ship as package data. The links in README.md, guide.md and gui.md are updated, and gui.md describes the new page and the handwriting key.docs/security/model.mdanddocs/developer/gui.mdnow say the window can ask the desktop to open a bundled blank form. A boundary test checks that_ready_pageis the only place that does.BUDGETgoes from 2000 to 2050. gui: Show every mismatch when a card is read back #109 adds a few more lines. This is your call: if you'd rather keep 2000, the page can shrink to text only, without the buttons.Not verified on Tails
Until the Bails launcher sets
CODEX32_FORMS_DIR, Tor Browser on Tails probably shows an error page for the forms.launch_finish()only reports that an application started, so the path fallback wouldn't show either. Please press both buttons on Tails once the Bails side lands.Validation
tests/test_gui_before_you_start.py. A layout choice now leads to the checklist, not a card, and cards begin only after I have them ready. It also checks the one-card wording, that each button launches its shipped form, the fallback on old GTK, and theCODEX32_FORMS_DIRoverride. Runs under Xvfb, and also underpython -O.bip32couldn't be collected (its GitHub archive is blocked in my environment), andtest_generic_hrp::test_cli_share_is_generic_and_ms32_share_is_scopedfails the same way without this change.src/codex32,src/codex32_gui) are clean. A built wheel containscodex32_gui/forms/*.html.github-advanced-securitycheck fails because Copilot is over its monthly quota ("You have exceeded your monthly quota", HTTP 402). It never reaches the diff.After this merges, tag it like
bails-recovery-1938b60, repin Bails'sinstall-codex32, and have Bails'sopen-codex32copy the forms under~/Tor Browserand setCODEX32_FORMS_DIR.Written by Claude at Ben's request; needs review by a responsible human per
docs/developer/AI_POLICY.md.🤖 Generated with Claude Code
https://claude.ai/code/session_01T4RnVngvFFCw3U93bJWLTp