From f5cbc18a3c43bebea78aac5921e23686aef422c8 Mon Sep 17 00:00:00 2001 From: kdmukai <934746+kdmukai@users.noreply.github.com> Date: Wed, 30 Sep 2026 15:21:32 -0400 Subject: [PATCH] Restore why change candidacy ignores cosigners Renaming _policy_shape_matches to _is_change_candidate dropped the reason the candidacy test compares shape alone. Without it, adding the cosigners to the comparison reads as a harmless tightening. The old wording named a misannotated fingerprint as what breaks an output's cosigner resolution. Since #1032, _get_cosigners matches each key to a global xpub by derivation path alone and never reads the fingerprint, so the restored note names a misannotated derivation path instead. --- src/seedsigner/models/psbt_parser.py | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/src/seedsigner/models/psbt_parser.py b/src/seedsigner/models/psbt_parser.py index 16741a3d..501c23ca 100644 --- a/src/seedsigner/models/psbt_parser.py +++ b/src/seedsigner/models/psbt_parser.py @@ -728,7 +728,16 @@ class PSBTParser(): Note: A multisig's input or output policy can also include the cosigners if they're supplied in the global xpubs. But this function does not take the - cosigners into account; cosigner information, if provided, is evaluated later. + cosigners into account; comparing the cosigners here would let a psbt decide which + of its own outputs get verified: + * One misannotated derivation path would make that output's cosigners fail + to resolve. + * The output's missing cosigners would mean that it would not match the inputs' + cosigners. + * End result: the output would not be considered a change candidate and would + not go through the same scrutiny that change candidates do. + + Cosigner information, if provided, is evaluated later. """ # The outlier: a single sig p2sh output when the inputs are p2sh-p2wpkh. if (