Restore why change candidacy ignores cosigners

Renaming _policy_shape_matches to _is_change_candidate dropped the
reason the candidacy test compares shape alone. Without it, adding the
cosigners to the comparison reads as a harmless tightening.

The old wording named a misannotated fingerprint as what breaks an
output's cosigner resolution. Since #1032, _get_cosigners matches each
key to a global xpub by derivation path alone and never reads the
fingerprint, so the restored note names a misannotated derivation path
instead.
This commit is contained in:
kdmukai
2026-09-30 15:21:32 -04:00
parent f04675e4a3
commit f5cbc18a3c
+10 -1
View File
@@ -728,7 +728,16 @@ class PSBTParser():
Note: A multisig's input or output policy can also include the cosigners if Note: A multisig's input or output policy can also include the cosigners if
they're supplied in the global xpubs. But this function does not take the they're supplied in the global xpubs. But this function does not take the
cosigners into account; cosigner information, if provided, is evaluated later. cosigners into account; comparing the cosigners here would let a psbt decide which
of its own outputs get verified:
* One misannotated derivation path would make that output's cosigners fail
to resolve.
* The output's missing cosigners would mean that it would not match the inputs'
cosigners.
* End result: the output would not be considered a change candidate and would
not go through the same scrutiny that change candidates do.
Cosigner information, if provided, is evaluated later.
""" """
# The outlier: a single sig p2sh output when the inputs are p2sh-p2wpkh. # The outlier: a single sig p2sh output when the inputs are p2sh-p2wpkh.
if ( if (