mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-10-06 07:28:24 +00:00
An output counted as change when its policy matched the inputs' and its rebuilt scriptPubKey matched what the output committed to. Neither step established that the key involved was ours. The policy comparison included cosigners resolved from the coordinator's own global xpubs, so one misannotated fingerprint made an output stop matching and skip verification altogether, and multisig never checked our key against the committed script at all. Outputs now compare on script shape alone, and every candidate proves ownership: single sig by rebuilding from the claimed derivation path, multisig by finding this seed's key in the committed script. Where the psbt's account of an output contradicts what the output commits to, the parse refuses rather than quietly reclassifying. A claim set too malformed to answer that question, one populating both derivation path maps or claiming more keys than its script uses, is refused as well. change_data now carries the verified derivation path in place of the coordinator's claimed fingerprints and paths, so the views no longer re-derive trust from strings the parse has already settled. Taproot mismatches stay exempt. A script tree tweaks the internal key, so honest taproot change fails the rebuild too, and embit leaves PSBT_OUT_TAP_TREE unparsed, which is what would tell the two apart.
Screenshot Generator
From the project root, run:
# Generate screenshots for a specific locale
pytest tests/screenshot_generator/generator.py --locale es
# Generate screenshots for all supported locales
pytest tests/screenshot_generator/generator.py
You can also run a coverage report to see exactly what the screenshots are and are not hitting:
coverage erase
coverage run -m pytest tests/screenshot_generator/generator.py --locale es && coverage combine && coverage report
# Generate the interactive html report
coverage html
Writes the screenshots to a dir in the project root: seedsigner-screenshots.