" [unknown]
-```
-The previous command validates that aforementioned small text file was signed using the private key that matches the published public key associated with the project (an early timestamped record of this public/private key's creation can be found in this [tweet](https://twitter.com/SeedSigner/status/1389617642286329856?s=20)).
+On the *last* output line, look at your *rightmost* 16 characters (the 4 blocks of 4).
+**Crucially, we must now check WHO that Primary key fingerprint /ID belongs to.** We will start by looking at Keybase.io to see if it is the *SeedSigner project* 's public key or not.
+
+ About the warning message:
+ Since you are about to match the outputted fingerprint/ID against the proofs at Keybase.io/SeedSigner, and thereby confirm who the pubkey really belongs to-, you can safely ignore this warning message:
-The last step is to make sure the .zip file that you've downloaded, and that contains the released software, is a perfect match to the software that was published by the holder of the private key in the last step. The command for this step is:
```
-shasum -a 256 -c seedsigner_0_*_*.img.zip.sha256
+> WARNING: This key is not certified with a trusted signature!
+> There is no indication that the signature belongs to the owner.
+ ```
+
+
+
+
+ More about how the verify command works:
+
+The verify command will attempt to decrypt the signature file (sha256.sig) by trying each public key already imported into your computer. If the public key we just imported (via fetch-keys), manages to: (a) successfully decrypt the .sig file , and (b), that result matches exactly to the clear-text equivalent (.sha256) of the .sig file, then its "a good signature"!
+
+Crucially, we must still manually check who *exactly* owns the Key ID which gave us that "Good signature". Thats what the warning message means- Who does the matching key really belong to? We will start by looking at keybase.io to see if it is "The SeedSigner project"'s public Key or not.
+Note that it is the file hashes of .sig and .sha256 that *verify* compares, not their raw contents.
+
+
+
+
+
+Now to determine ***who*** the Public key ID belongs to: Goto [Keybase.io/SeedSigner](https://keybase.io/seedsigner)
+
+
+
+
+
+**You must now *manually* compare: The 16 character fingerprint ID (as circled in red above) to, those *rightmost* 16 characters from your *verify* command.**
+
+**If they match exactly, then you have successfully confirmed that your .sig file is authentically from the SeedSigner Project!**
+
+
+Learn more about how keybase.io helps you check that someone (online) is who they say they are:
+
+Keybase.io allows you to independently verify that the public key saved on Keybase.io, is both authentic and that it belongs to the organization it claims to represent.
+ Keybase has already checked the three pubkey file locations cryptographically when they were saved there. You can further verify the key publications if you would like:
+
+ - *via Keybase*: By clicking on any of the three blue badges to see that the "proof" was published at that location. (The blue badge marked as tweet, is in the most human-readable form and it is also a bi-directional link on Twitter)
+or,
+ - *without keybase (out-of-band)*: By using these 3 links directly: [Twitter](https://twitter.com/SeedSigner/status/1530555252373704707), [Github](https://gist.github.com/SeedSigner/5936fa1219b07e28a3672385b605b5d2) and [SeedSigner.com](https://seedsigner.com/keybase.txt). This method can be used if you would like to make an even deeper, independent inspection without relying on Keybase at all, or if the Keybase.io site is no longer valid or it is removed entirely.
+
+Once you have used one of these methods, you will know if the Public Key stored on Keybase, is genuinely from the SeedSinger Project or not.
+
+
+
+
+If the two ID's do *not* match, then you must stop here immediately. Do not continue. Contact us for assistance in the Telegram group address above.
+
+
+
+### Step 2. Verifying that the *software images/binaries* are genuine
+
+Now that you have confirmed that you do have the real SeedSigner Project's Public Key (ie the 16 characters match) - you can return to your terminal window. Running the *shasum* command, is the final verification step and will confirm (via file hashing) that the software code/image files, were also not altered since publication, or even during your download process.
+(Prior to version 0.6.0 , your verify command will check the .zip file which contains the binary files.)
+
+ **On Linux or OSX:** Run this command
```
-The reponse to this command should include the text:
-```
-seedsigner_0_4_6.img.zip: OK
+shasum -a 256 --ignore-missing --check seedsigner.0.6.*.sha256
```
-There are other steps you can take to verify the software, including examining the hash value in the .sha256 text file, but this one has been documented here because it seems the simplest for most people to follow. Please recognize that this process can only validate the software to the extent that the entity that first published the key is an honest actor, and assumes the private key has remained uncompromised and is not being used by a malicious actor.
+**On Windows (inside Powershell):** Run this command
+```
+CertUtil -hashfile seedsigner.0.6.0.sha256 SHA256 | findstr /v "hash"
+```
+On Windows, you must then manually compare the resulting file hash value to the corresponding hash value shown inside the .SHA256 cleartext file.
+
+
+Wait up to 30 seconds for the command to complete, and it should display:
+```
+seedsigner_os.0.6.x[Your_Pi_Model_For_Example:pi02w].img: OK
+```
+**If you receive the "OK" message** for your **seedsigner_os.0.6.x.[Your_Pi_Model_For_Example:pi02w].img file**, as shown above, then your verification is fully complete!
+**All of your downloaded files have now been confirmed as both authentic and unaltered!** You can proceed to create/write your MicroSD card😄😄 !!
+
+If your file result shows "FAILED", then you must stop here immediately. Do not continue. Contact us for assistance at the Telegram group address above.
+
+
+
+Please recognize that this process can only validate the software to the extent that the entity that first published the key is an honest actor, and their private key is not compromised or somehow being used by a malicious actor.
+
+
+
+
+## Writing the software onto your MicroSD card
+
+To write the SeedSigner software onto your MicroSD card, there are a few options available:
+| Application | Description | Platform and official Source |
+|--------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------|
+| Balena Etcher | The application is called Etcher, and the company that wrote it is called Balena. Hence *Etcher by Balena* or *Balena Etcher* | [Available for Windows, Mac and Linux](https://www.balena.io/etcher#download-etcher) |
+| Raspberry Pi Imager | Produced by the Raspberry Pi organization. | [Available for Windows, Mac and Linux](https://www.raspberrypi.com/software/) |
+| DD Command Line Utility | Built-in to Linux and MacOS, the DD (Data Duplicator) is a tool for advanced users. If not used carefully it can accidentally format the incorrect disk! | Built-in to Linux and MacOS |
+
+Be sure to download the software from the genuine publisher.
+Either of the Etcher or Pi Imager software is recommended. Some SeedSigner users have reported a better experience with one or the other. So, if the one application doesn’t work well for your particular machine, then please try the other one.
+
+### **General Considerations:**
+The writing and verify steps are very quick from version 0.6.0 upwards, so please pay close attention to your screen.
+Make sure to set any write-protection physical slider on the MicroSD Card Adapter to UN-locked.
+You also don’t need to pre-format the MicroSD beforehand. You *dont* need to unzip any .zip file beforehand.
+Current Etcher and Pi Imager software will perform a verify action (by default) to make sure the card was written successfully! Watching for that verify step to complete successfully can save you a lot of headaches if you later need to troubleshoot issues where your SeedSigner device doesn’t boot up at power on.
+Writing the MicroSd card is also known as flashing.
+It will overwrite everything on the MicroSD card.
+If the one application fails for you, then please try again using our other recommended application.
+Advanced users may want to try the Linux/MacOS *DD* command instead of using Etcher or Pi Imager, however, a reminder is given that DD can overwrite the wrong disk if you are not careful !
+#### **Specific considerations for Windows users:**
+Use the Pi imager software as your first choice on Windows. Windows can sometimes flag the writing of a MicroSD as risky behaviour and hence it may prevent this activity. If this happens, your writing/flashing will fail, hang or wont even begin, in which case you should to try to run the Etcher/Pi-Imager app "As administrator", (right-click and choose that option). It can also be blocked by windows security in some cases, so If you have the (non-default) *Controlled Folder Access* option set to active, try turning that *off* temporarily.
+
+
+
---------------
@@ -160,7 +280,7 @@ The upper and lower portions of the enclosure can be printed using a standard FD
* [Lil Pill](https://cults3d.com/en/3d-model/gadget/lil-pill-seedsigner-case) by @_CyberNomad
* [OrangeSurf Case](https://github.com/orangesurf/orangesurf-seedsigner-case) by @OrangeSurfBTC
-* [PS4 Seedsigner](https://www.thingiverse.com/thing:5363525) by @Silexperience
+* [PS4 SeedSigner](https://www.thingiverse.com/thing:5363525) by @Silexperience
* [OpenPill Faceplate](https://www.printables.com/en/model/179924-seedsigner-open-pill-cover-plates-digital-cross-jo) by @Revetuzo
* [Waveshare CoverPlate](https://cults3d.com/en/3d-model/various/seedsigner-coverplate-for-waveshare-1-3-inch-lcd-hat-with-240x240-pixel-display) by @Adathome1
@@ -190,6 +310,21 @@ CompactSeedQR templates:
* [Baseball card template: 12-word Compact SeedQR (21x21)](docs/seed_qr/printable_templates/trading_card_21x21_w12words.pdf)
* [Baseball card template: 24-word Compact SeedQR (25x25)](docs/seed_qr/printable_templates/trading_card_25x25_w24words.pdf)
+
+
+2-sided SeedQR templates - 8 per sheet
+Printing settings - (2-sided)("flip on long edge")("Actual Size")
+If printing on cardstock, adjust your printer settings via its control panel
+
+A4 templates(210mm * 297mm):
+* [21x21 - stores 12-word seeds ONLY in CompactSeedQR format ONLY](docs/seed_qr/printable_templates/21x21_A4_trading_card_2sided.pdf)
+* [25x25 - stores 12-word or 24 word seeds depending on SeedQR format](docs/seed_qr/printable_templates/25x25_A4_trading_card_2sided.pdf)
+* [29x29 - stores 24-word seeds ONLY as plaintext SeedQR format ONLY](docs/seed_qr/printable_templates/29x29_A4_trading_card_2sided.pdf)
+
+Letter templates(8.5in * 11in):
+* [21x21 - stores 12-word seeds ONLY in CompactSeedQR format ONLY](docs/seed_qr/printable_templates/21x21_letter_trading_card_2sided.pdf)
+* [25x25 - stores 12-word or 24 word seeds depending on format](docs/seed_qr/printable_templates/25x25_letter_trading_card_2sided.pdf)
+* [29x29 - stores 24-word seeds ONLY as plaintext SeedQR format ONLY](docs/seed_qr/printable_templates/29x29_letter_trading_card_2sided.pdf)
---------------
# Manual Installation Instructions
diff --git a/docs/seed_qr/printable_templates/21x21_A4_trading_card_2sided.pdf b/docs/seed_qr/printable_templates/21x21_A4_trading_card_2sided.pdf
new file mode 100644
index 00000000..01946eea
Binary files /dev/null and b/docs/seed_qr/printable_templates/21x21_A4_trading_card_2sided.pdf differ
diff --git a/docs/seed_qr/printable_templates/21x21_letter_trading_card_2sided.pdf b/docs/seed_qr/printable_templates/21x21_letter_trading_card_2sided.pdf
new file mode 100644
index 00000000..40e1d647
Binary files /dev/null and b/docs/seed_qr/printable_templates/21x21_letter_trading_card_2sided.pdf differ
diff --git a/docs/seed_qr/printable_templates/25x25_A4_trading_card_2sided.pdf b/docs/seed_qr/printable_templates/25x25_A4_trading_card_2sided.pdf
new file mode 100644
index 00000000..4340c517
Binary files /dev/null and b/docs/seed_qr/printable_templates/25x25_A4_trading_card_2sided.pdf differ
diff --git a/docs/seed_qr/printable_templates/25x25_letter_trading_card_2sided.pdf b/docs/seed_qr/printable_templates/25x25_letter_trading_card_2sided.pdf
new file mode 100644
index 00000000..60691b58
Binary files /dev/null and b/docs/seed_qr/printable_templates/25x25_letter_trading_card_2sided.pdf differ
diff --git a/docs/seed_qr/printable_templates/29x29_A4_trading_card_2sided.pdf b/docs/seed_qr/printable_templates/29x29_A4_trading_card_2sided.pdf
new file mode 100644
index 00000000..c84ffbdd
Binary files /dev/null and b/docs/seed_qr/printable_templates/29x29_A4_trading_card_2sided.pdf differ
diff --git a/docs/seed_qr/printable_templates/29x29_letter_trading_card_2sided.pdf b/docs/seed_qr/printable_templates/29x29_letter_trading_card_2sided.pdf
new file mode 100644
index 00000000..7731f967
Binary files /dev/null and b/docs/seed_qr/printable_templates/29x29_letter_trading_card_2sided.pdf differ
diff --git a/tests/README.md b/tests/README.md
index aa79d2a7..ae8679c6 100644
--- a/tests/README.md
+++ b/tests/README.md
@@ -24,3 +24,19 @@ Run a specific test:
```
pytest tests/test_this_file.py::test_this_specific_test
```
+
+### Test Coverage
+Run tests and generate test coverage
+```
+coverage run -m pytest
+```
+
+Show the resulting test coverage details:
+```
+coverage report
+```
+
+Generate the html overview:
+```
+coverage html
+```
diff --git a/tests/requirements.txt b/tests/requirements.txt
index 6643e54e..5bdf1466 100644
--- a/tests/requirements.txt
+++ b/tests/requirements.txt
@@ -1,3 +1,4 @@
attrs==21.4.0
+coverage==7.2.1
+mock==4.0.3
pytest==6.2.4
-mock==4.0.3
\ No newline at end of file
diff --git a/tests/test_mnemonic_generation.py b/tests/test_mnemonic_generation.py
index a0c04ed8..76298d34 100644
--- a/tests/test_mnemonic_generation.py
+++ b/tests/test_mnemonic_generation.py
@@ -1,3 +1,4 @@
+import pytest
import random
from embit import bip39
@@ -42,6 +43,35 @@ def test_calculate_checksum():
assert bip39.mnemonic_is_valid(" ".join(mnemonic))
+def test_calculate_checksum_invalid_mnemonics():
+ """
+ Should raise an Exception on a mnemonic that is invalid due to length or using invalid words.
+ """
+ with pytest.raises(Exception) as e:
+ # Mnemonic is too short: 10 words instead of 11
+ partial_mnemonic = "abandon " * 9 + "about"
+ mnemonic_generation.calculate_checksum(partial_mnemonic.split(" "), wordlist_language_code=SettingsConstants.WORDLIST_LANGUAGE__ENGLISH)
+ assert "12- or 24-word" in str(e)
+
+ with pytest.raises(Exception) as e:
+ # Valid mnemonic but unsupported length
+ mnemonic = "devote myth base logic dust horse nut collect buddy element eyebrow visit empty dress jungle"
+ mnemonic_generation.calculate_checksum(mnemonic.split(" "), wordlist_language_code=SettingsConstants.WORDLIST_LANGUAGE__ENGLISH)
+ assert "12- or 24-word" in str(e)
+
+ with pytest.raises(Exception) as e:
+ # Mnemonic is too short: 22 words instead of 23
+ partial_mnemonic = "abandon " * 21 + "about"
+ mnemonic_generation.calculate_checksum(partial_mnemonic.split(" "), wordlist_language_code=SettingsConstants.WORDLIST_LANGUAGE__ENGLISH)
+ assert "12- or 24-word" in str(e)
+
+ with pytest.raises(ValueError) as e:
+ # Invalid BIP-39 word
+ partial_mnemonic = "foobar " * 11 + "about"
+ mnemonic_generation.calculate_checksum(partial_mnemonic.split(" "), wordlist_language_code=SettingsConstants.WORDLIST_LANGUAGE__ENGLISH)
+ assert "not in the dictionary" in str(e)
+
+
def test_calculate_checksum_with_default_final_word():
""" 11-word and 23-word mnemonics use word `0000` as a temp final word to complete
@@ -62,6 +92,22 @@ def test_calculate_checksum_with_default_final_word():
assert mnemonic1 == mnemonic2
+def test_generate_mnemonic_from_bytes():
+ """
+ Should generate a valid BIP-39 mnemonic from entropy bytes
+ """
+ # From iancoleman.io
+ entropy = "3350f6ac9eeb07d2c6209932808aa7f6"
+ expected_mnemonic = "crew marble private differ race truly blush basket crater affair prepare unique".split()
+ mnemonic = mnemonic_generation.generate_mnemonic_from_bytes(bytes.fromhex(entropy))
+ assert mnemonic == expected_mnemonic
+
+ entropy = "5bf41629fce815c3570955e8f45422abd7e2234141bd4d7ec63b741043b98cad"
+ expected_mnemonic = "fossil pass media what life ticket found click trophy pencil anger fish lawsuit balance agree dash estate wage mom trial aerobic system crawl review".split()
+ mnemonic = mnemonic_generation.generate_mnemonic_from_bytes(bytes.fromhex(entropy))
+ assert mnemonic == expected_mnemonic
+
+
def test_verify_against_coldcard_sample():
""" https://coldcard.com/docs/verifying-dice-roll-math """