Skip to content

Release 0.7.0: v1 library, CLI and docs in 9 reviewable commits - #142

Draft
BenWestgate wants to merge 9 commits into
masterfrom
claude/v1-rebuild-from-ack-xcgtlk
Draft

BenWestgate wants to merge 9 commits into
masterfrom
claude/v1-rebuild-from-ack-xcgtlk

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Requested by Ben · project thread

Before: master has the v0.6 library only (PyPI 0.6.1). The v1 work lives on reviewability-v1 as 88 commits with plans, gates and add-then-remove churn, so it's hard to review from the ACKed code.

After: master gets the v1 library, the codex32/ms32 CLI and the new README as 0.7.0, in 9 atomic commits (about +18k lines). Each commit passes ruff, ruff format, strict mypy and its tests on its own.

The final tree equals reviewability-v1 + #143 (drop raw benchmark data) at e976c8c except for two differences. The version is 0.7.0 instead of 1.0.0rc1, and master's FUNDING.yml, scorecard.yml and stale.yml are kept.

Provenance. BlockstreamResearch/codex32#74 commit 4857e18 (ACKed by apoelstra) contains src/ and tests/ that are byte-identical to 4bb90c0 (tag v0.6.1) and to the PyPI 0.6.1 sdist and wheel. Master descends from 4bb90c0 through 14 small CI, README and version commits. So git diff 4bb90c0 HEAD reviews everything since the ACKed code.

# Commit Tests passing
1 codex32: Replace the v0.6 core with typed v1 primitives 142
2 wallet: Derive the BIP32 root key for master seeds 155
3 generation: Create master seeds and shares with read-back checks 196
4 correction: Add bounded substitution and indel correction 388
5 correction: Rank competing interpretations within a deadline 434
6 core: Hand master seeds to Bitcoin Core v32 wallets 483
7 cli: Add the codex32 and ms32 commands 894
8 docs: Document the v1 library, CLI and security model 894
9 release: Prepare 0.7.0 907 (also with -O), constants, differential, build and wheel checks

How: a script takes each commit's files from the target verbatim. Only hub files get intermediate versions: __init__.py exports, pyproject.toml, the CI workflow, a step-1 README usage example, and indel.py without the competitor hook until commit 5. The script, its overlays and the verification log are in the project files under v1-rebuild/.

Notes for the reviewer:

  • This would replace Add comprehensive codex32 CLI, correction, and wallet integration #94 (reviewability-v1 → master). It doesn't rewrite master or reviewability-v1.
  • Share generation, recovery and checksum code changes here, so it needs the security review before it's marked ready.
  • Commits keep Ben as author. Their contents are his reviewability-v1 work, unchanged.

🤖 Generated with Claude Code

https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K

@BenWestgate BenWestgate self-assigned this Oct 8, 2026
Comment thread tools/bitcoin_core_main_smoke.py Fixed
Comment thread tools/bitcoin_core_regtest.py Fixed

Copy link
Copy Markdown
Owner Author

CodeQL is red, and this PR doesn't add the code it flags.

The two py/command-line-injection alerts point at tools/bitcoin_core_regtest.py:44 and tools/bitcoin_core_main_smoke.py:40. Both files are byte-identical to reviewability-v1, where the same alerts were already raised. They are developer-only fixture scripts that run the bitcoind/bitcoin-cli path given on the operator's own command line; CI passes fixed paths. No untrusted input crosses a boundary there, so I'm not changing the code. Changing it would also break the "tree equals reviewability-v1" property of this PR.

Clearing the check needs a maintainer decision on those two alerts in code scanning, which I can't do from here.


Generated by Claude Code

Comment thread tools/bitcoin_core_main_smoke.py Fixed
Comment thread tools/bitcoin_core_regtest.py Fixed
Rewrite the BIP93 encoding, checksum, sharing and profile layers of the
v0.6.1 code (byte-identical to 4857e18, ACKed in
BlockstreamResearch/codex32#74) as frozen, typed values with no
third-party dependency.

- gf32/checksums/bech32: immutable checksum specs, GF(32) tables and
  strict single-case Bech32 parsing; drop the unused segwit_addr module.
- bip93: Header/Share/Secret values, parse_codex32, derive_share and
  recover_secret.  There is no public encoder from raw (padded) bytes to
  a share; shares come only from interpolation.
- profiles: ms (BIP32 master seed), cl (Core Lightning hsm_secret, unshared
  only) and bip39 entropy.
- Tooling: drop mypy.ini, requirements.txt and the pylint job; add
  ruff, strict mypy and a hash-pinned setuptools build dependency.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add master_xprv(), backed by a minimal private BIP32 root derivation that
stops at the root; child derivation is left to Bitcoin Core.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add generate_master_seed() and CreationCeremony, which issues shares one at
a time and only finishes after each one has been read back correctly.
Fresh seeds use CRC padding and the BIP32 fingerprint identifier.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add correct() and correct_worksheet_residue().  Substitutions and erasures
are decoded within the BCH bounds; insertions and deletions use a bounded
alignment search.  Every candidate is untrusted and carries its capture
volume.  Constants are checked against the frozen PR #70 corpus.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add the deadline-bounded scheduler that proves which competing alignments
cannot outrank a found candidate, so interactive callers get a ranked
answer quickly.  Include the alignment benchmark tool and its summary.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add the Bitcoin Core v32 adapter used by the CLI to import a master xprv
and let Core derive descriptors, plus a regtest fixture job that checks
every frozen wallet fingerprint against a pinned Core release.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Add the command-line interface: argument parsing, protected terminal input
with group-by-group correction, and the create, share, recover, correct
and wallet commands.  The production code stays within a 5200-line budget.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Rewrite the README and add the user guide, printable cards, API reference,
security model and invariants, contribution guide, security policy and AI
policy.  Replace the Copilot instructions with AGENTS.md.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K
Bump the version, replace the publish workflow with a reproducible,
hash-pinned build that attaches distributions to the GitHub release, and
verify the installed wheel in CI.

Claude-Session: https://claude.ai/code/session_01MDsbGqZmvVThoJrs4vzc4K

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted current-head review: Concept ACK to the nine-commit 0.7.0 split. Current 24 checks are green (including CodeQL); nine commits have verified signatures. Targeted security review found no immediate issue in fingerprint-before-wallet selection, no-shell Core RPC, or OS entropy. Still draft: complete an independent security review of generation, correction and wallet import; verify final artifacts and the Tails/Core restore path before release. No full security-scan ACK yet.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants