Restore why change candidacy ignores cosigners

Renaming _policy_shape_matches to _is_change_candidate dropped the
reason the candidacy test compares shape alone. Without it, adding the
cosigners to the comparison reads as a harmless tightening.

The old wording named a misannotated fingerprint as what breaks an
output's cosigner resolution. Since #1032, _get_cosigners matches each
key to a global xpub by derivation path alone and never reads the
fingerprint, so the restored note names a misannotated derivation path
instead.
This commit is contained in:
kdmukai
2026-09-30 15:21:32 -04:00
parent f04675e4a3
commit f5cbc18a3c
+10 -1
View File
@@ -728,7 +728,16 @@ class PSBTParser():
Note: A multisig's input or output policy can also include the cosigners if
they're supplied in the global xpubs. But this function does not take the
cosigners into account; cosigner information, if provided, is evaluated later.
cosigners into account; comparing the cosigners here would let a psbt decide which
of its own outputs get verified:
* One misannotated derivation path would make that output's cosigners fail
to resolve.
* The output's missing cosigners would mean that it would not match the inputs'
cosigners.
* End result: the output would not be considered a change candidate and would
not go through the same scrutiny that change candidates do.
Cosigner information, if provided, is evaluated later.
"""
# The outlier: a single sig p2sh output when the inputs are p2sh-p2wpkh.
if (