Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit adds an optional feature to the HWI tool that lets users pass previously registered Bitcoin wallet policies (BIP388) when signing transactions. It is a feature addition, not a fix for a known vulnerability. The change extends t…
New CLI argument `--registration` is appended to `signtx` and deserialized before being passed to hardware wallet clientsSeveral backends now accept and use `registered_descriptors` during PSBT signingBackends without BIP388 support raise `UnavailableActionError` when registrations are supplied
This is a code-quality and type-safety patch. It adds the psbt.py file to the project's automated type-checking workflow and fixes two small logic issues where a value was assigned to an object field before being validated. The changes mak…
Validation moved before state mutation (defensive coding)Type annotations added to public methodsFile added to CI type-check coverage
This commit turns on automated type checking for one more source file (hwilib/psbt.py) and makes small code changes so the file passes the type checker. The actual code changes move two integer assignments slightly later so validation happ…
Type checking enabled for PSBT moduleValidation ordering tightened for locktime fieldsExplicit type annotations added to PSBT methods
This commit is a simple code cleanup in the test suite. It pulls out two small blocks of test code into reusable helper functions for signing and finalizing PSBTs, and for setting global xpubs in PSBTs. There is no change to production cod…
This commit simply reorganizes the Coldcard hardware wallet signing code in HWI by moving existing logic into two new helper methods. There is no change to what the code actually does; it is a pure refactoring (code cleanup) with no securi…
This commit adds two helper methods to the PSBT (Partially Signed Bitcoin Transaction) handling code that let the library check whether a specific hardware wallet's fingerprint appears in a transaction input, and whether that fingerprint h…
Adds fingerprint-based key/signature detection in PSBT input parsingIncludes unit tests covering legacy BIP32, Taproot key path, and Taproot script path casesNo caller or usage of new methods shown in the diff
This commit updates the Ledger hardware wallet support in HWI so that newer Ledger devices can sign Bitcoin transactions using registered BIP388 wallet policies. Previously, any attempt to use registered descriptors with a Ledger was block…
Change removes an explicit error path for registered descriptors, increasing supported functionalityAdds reconstruction of registered wallet policies and propagation of registration HMACs during PSBT signingTouches hardware-wallet signing path where incorrect policy handling could lead to signing unintended transactions
This is a routine feature-and-testing update for the Coldcard hardware wallet support in Bitcoin Core's HWI tool. It adds support for Coldcard's 'Edge' experimental firmware, lets users display single-signature Taproot addresses on Edge, a…
PSBT version downgrade logic moved from per-pass to once-per-signing; intended to preserve v2 when supported and downgrade when notNew firmware version parsing heuristic treats Q/X suffixes and Edge/simulator as PSBTv2 capableTaproot singlesig address display enabled only for Coldcard Edge firmware
This commit adds a new command called `registerdescriptor` to the HWI tool, which lets users register Bitcoin output descriptors with supported hardware wallets (Ledger, BitBox02, Jade, Coldcard). It also rewrites how descriptors are parse…
New command registers user-supplied descriptors with hardware walletsHWI explicitly does not validate descriptors before passing them to the device; device errors are propagatedDescriptor parser changed from string-based derivation paths to structured list-of-lists, affecting all descriptor handling
This commit tightens how the Bitcoin hardware wallet interface library reads PSBT files. It now rejects PSBTv0 files that contain fields only allowed in the newer PSBTv2 format, enforces sensible locktime ranges, and fixes several bugs whe…
Strict PSBT version field validationNew locktime bound enforcementWitness-stripped unsigned tx parsing
This commit adds support for signing Bitcoin transactions with registered wallet policies (BIP388) on the BitBox02 hardware wallet. Previously this feature was rejected with an error. The change translates a registered wallet descriptor in…
Removal of an explicit unsupported-action error for BIP388 policy signingNew xpub and fingerprint comparison logic to identify the device's key in a policyNew policy script config construction passed to hardware signing routines
This change removes an error that previously blocked Bitcoin signing for a specific type of wallet policy (BIP388) on the Blockstream Jade hardware wallet. The device now supports these policies, so the software no longer needs to reject t…
Removal of an explicit unsupported-action errorNo new cryptographic operations introducedNo input validation changes observed
This commit adds support for signing Bitcoin transactions with named wallet policies (BIP388) on newer Coldcard hardware wallets. It is a feature addition, not a fix for a known security flaw. The change removes an error that previously bl…
Feature addition for BIP388 policy signingRemoval of UnavailableActionError guard for registered_descriptorsNew miniscript_name parameter length-bounded to 1-32 ASCII bytes
This commit adds a new command-line option and API parameter for BIP388 registered descriptor policies to the transaction-signing flow. It does not implement actual signing support in any hardware wallet driver; every device implementation…
New API surface added for BIP388 policy registrationAll device implementations explicitly reject BIP388 policy signing with UnavailableActionErrorNo existing signing path is modified; default behavior unchanged
This is a routine maintenance merge for the Bitcoin Core Hardware Wallet Interface (HWI). It drops support for the end-of-life Python 3.9, switches deterministic builds and CI to Python 3.10, updates Ledger test firmware/simulator versions…
Dependency/toolchain version bump (Python 3.9 EOL removal, Python 3.10 adoption)Ledger firmware/app and Speculos simulator version bump in CI/testsTest automation rules updated for new Ledger UI prompts
This commit removes an unused test automation rule that automatically pressed a button when a Ledger hardware wallet simulator showed 'Cancel' or 'Reject' on screen. It only affects test data, not the actual wallet interface code users rel…
This commit only re-enables automated tests for Ledger Nano X hardware wallets. It removes code that was skipping certain tests, but makes no changes to the actual wallet-interaction code that users rely on. There is no security fix or vul…
This change adjusts the build script so that the graphical hwi-qt program is only bundled into release archives for 64-bit x86 (Intel/AMD) systems. On other CPU architectures, only the command-line hwi tool is packaged. This is a build/pac…
This commit only changes a test timeout from 60 seconds to 120 seconds so that automated tests can complete when a Ledger hardware wallet running newer firmware takes longer to sign a large test transaction. It does not change any producti…
This commit updates the versions of testing tools and Ledger Bitcoin app used in HWI's automated test environment. It does not change the actual HWI wallet-interaction code that users run. The changes are purely to keep CI/test simulations…
This adds optional registered BIP388 descriptor policy information to `signtx`. Existing `signtx` usage remains unchanged when no registration is supplied.
`signtx` accepts `--registration`, containing the serialized `RegisteredDescriptor` returned by the `registerdescriptor` command from #842. The registration contains the policy name, descriptor, device type, and any device-specific registration data, so separate `--policy-desc` and `--policy-name` arguments are not needed.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet pathparser or protocol pathmerge-commit duplicate discount
AI analysis · Low 29/100
This commit adds an optional feature to the HWI tool that lets users pass previously registered Bitcoin wallet policies (BIP388) when signing transactions. It is a feature addition, not a fix for a known vulnerability. The change extends the command-line interface and several hardware wallet backends to accept an optional `--registration` argument during signing. Existing behavior is preserved when the argument is not provided. There is no direct evidence in the commit that this introduces a security bug, but any code that handles cryptographic signing and parses external data deserves careful review.
Security candidateMerge bitcoin-core/HWI#853: psbt: enable type checkingby Ava Chow · 390d9f84 · Aug 25, 2026 · 2 filesMessage 81 · StrongInformational 18Details
Commit message · Ava Chow
Merge bitcoin-core/HWI#853: psbt: enable type checking
37643bd8e4f86324b75723525149eb945275395c psbt: enable type checking (Sjors Provoost)
Pull request description:
ACKs for top commit: achow101: ACK 37643bd8e4f86324b75723525149eb945275395c
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet pathmerge-commit duplicate discount
AI analysis · Informational 18/100
This is a code-quality and type-safety patch. It adds the psbt.py file to the project's automated type-checking workflow and fixes two small logic issues where a value was assigned to an object field before being validated. The changes make the code safer and cleaner, but they do not appear to fix an active security vulnerability that could be exploited.
Handle the paginated To heading and From section shown while reviewing registered-descriptor transactions.
82/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Security candidatepsbt: enable type checkingby Sjors Provoost · 37643bd8 · Aug 24, 2026 · 2 filesMessage 35 · OpaqueInformational 18Details
Commit message · Sjors Provoost
psbt: enable type checking
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
signing boundarysigning or wallet path
AI analysis · Informational 18/100
This commit turns on automated type checking for one more source file (hwilib/psbt.py) and makes small code changes so the file passes the type checker. The actual code changes move two integer assignments slightly later so validation happens before storing the value, and add explicit type annotations to two methods. There is no direct evidence this fixes a security vulnerability; it is primarily a code-quality and type-safety improvement.
Support addresses display for registered BIP388 descriptor policies.
`displayaddress` accepts: - the `RegisteredDescriptor` registration returned by `registerdescriptor` (introduced by #842) - an address index - receive/change selection (multipath index)
A generic device test registers the simple multisig policy introduced by #842 and then displays address index 7. Device support is added one device per commit.
ACKs for top commit: achow101: ACK 458a92009f5f7244863f0e3def070f9212d8b479
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Create a transaction with two registered policies and an inferred single-sig policy, and sign it in one call.
82/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Informational 15/100
This commit is a simple code cleanup in the test suite. It pulls out two small blocks of test code into reusable helper functions for signing and finalizing PSBTs, and for setting global xpubs in PSBTs. There is no change to production code, no security fix, and no behavior change.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Informational 15/100
This commit simply reorganizes the Coldcard hardware wallet signing code in HWI by moving existing logic into two new helper methods. There is no change to what the code actually does; it is a pure refactoring (code cleanup) with no security-relevant behavior change visible in the diff.
Security candidatepsbt: detect keys and signatures by fingerprintby Sjors Provoost · 3cc34937 · Aug 21, 2026 · 2 filesMessage 45 · ThinInformational 24Details
Commit message · Sjors Provoost
psbt: detect keys and signatures by fingerprint
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundarysigning or wallet path
AI analysis · Informational 24/100
This commit adds two helper methods to the PSBT (Partially Signed Bitcoin Transaction) handling code that let the library check whether a specific hardware wallet's fingerprint appears in a transaction input, and whether that fingerprint has already provided a signature. The change is purely additive and includes tests. There is no direct evidence in the commit that this fixes an active security vulnerability; it appears to be a defensive or feature-oriented improvement to support better transaction signing workflows.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
The automation models a simultaneous left-and-right press as four separate events. If the app redraws between events, Speculos can apply the remaining input on a different screen. In the observed failure this advanced to "Reject transaction" and confirmed it.
Use button mask 3 for one combined press and release for all two-button approvals, keeping them atomic across redraws.
90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Reconstruct each registered wallet policy and pass its registration HMAC when signing the PSBT. Inferred policies continue to be signed alongside registered policies.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing boundary
AI analysis · Low 31/100
This commit updates the Ledger hardware wallet support in HWI so that newer Ledger devices can sign Bitcoin transactions using registered BIP388 wallet policies. Previously, any attempt to use registered descriptors with a Ledger was blocked with an error. The change removes that blanket block for modern Ledger apps and adds logic to reconstruct each registered wallet policy and include its registration proof when signing. Inferred policies still work as before. This is a feature addition, not a fix for an active vulnerability, but it touches security-sensitive signing code.
The Edge firmware supports displaying taproot single sig addresses, and more importantly MuSig2.
Rather than blowing up the CI matrix, this PR only adds it for Python 3.14. It can be easily be dropped again if all Edge features we care about land in their regular firmware.
The first commit re-enables `test_signtx`, which was already possible. It achieves this by dropping multisig for ColdCard in that these. This can be re-introduced by #792.
The multisig patch is adjusted or Edge. Alternatively after #847 it could be dropped entirely. It builds, but CI won't cover it until #792. I did test it locally.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarymerge-commit duplicate discount
AI analysis · Low 25/100
This is a routine feature-and-testing update for the Coldcard hardware wallet support in Bitcoin Core's HWI tool. It adds support for Coldcard's 'Edge' experimental firmware, lets users display single-signature Taproot addresses on Edge, and re-enables transaction-signing tests by dropping multisig cases for Coldcard. It also changes how PSBT version 2 is handled: newer Coldcard firmware keeps PSBTv2, while older firmware is downgraded to PSBTv0 before signing. There is no obvious security bug in the diff, but the PSBT version handling and new firmware support are worth a careful look because mistakes there could affect transaction validity or compatibility.
Lower-priorityMerge bitcoin-core/HWI#846: errors: fix UNKNWON_DEVICE_TYPE misspelling, keep it as a compat aliasby Ava Chow · bbbc8a65 · Aug 20, 2026 · 1 fileMessage 81 · StrongTriage 0Details
Commit message · Ava Chow
Merge bitcoin-core/HWI#846: errors: fix UNKNWON_DEVICE_TYPE misspelling, keep it as a compat alias
6e8cecafadd78d3f78ef1eaad353725b0c21348f errors: fix UNKNWON_DEVICE_TYPE misspelling, keep it as a compat alias (Ferdinando Ametrano)
Pull request description:
Fixes #845.
`UNKNWON_DEVICE_TYPE` (error code -4, in `hwilib/errors.py`) is a transposition of "UNKNOWN". This adds the correctly-spelled `UNKNOWN_DEVICE_TYPE` and aliases the old name to it, rather than renaming outright: it's a public, documented module-level name (the module is `automodule`'d), so an external importer of the misspelled name should not break.
`UnknownDeviceError` now raises with the correct spelling. Its docstring's `:data:`DEVICE_TYPE`` cross-reference is also fixed — it pointed at a name that didn't exist under either spelling, so the Sphinx `:data:` role couldn't have resolved it before this either.
Out of scope for this PR: `hwilib/devices/ledger_bitcoin/errors.py` carries the same misspelling in a comment-credited copy of this file ("Original version: https://github.com/bitcoin-core/HWI"), vendored as part of the `ledger_bitcoin` client subpackage. I didn't touch it, since it's a separate vendored copy and not literally this file; flagging it here in case maintainers want it addressed too, either in this PR or separately.
No behavioural change: both names resolve to the same value, `UnknownDeviceError().get_code()` still returns -4.
ACKs for top commit: achow101: ACK 6e8cecafadd78d3f78ef1eaad353725b0c21348f
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Security candidateMerge bitcoin-core/HWI#842: Add `registerdescriptors` command for registering a descriptor with a deviceby Ava Chow · d928dae5 · Aug 18, 2026 · 20 filesMessage 91 · StrongLow 32Details
Commit message · Ava Chow
Merge bitcoin-core/HWI#842: Add `registerdescriptors` command for registering a descriptor with a device
50f5781e70552cca094cba23d0d301f46d364306 test: Add basic test for register_descriptor (Ava Chow) 8fc30319af2fc7f20417be594164f73c596723ad jade: Implement register_descriptor (Ava Chow) 3fc07a6ced1aa1c43d8265ef245c303b5cd385b9 coldcard: Implement register_descriptor (Ava Chow) 9f91e1a61c10ed13782407eac7a0bfb67933d2e2 bitbox02: Implement register_descriptor (Ava Chow) 1d6361bb32332eabcc78862bbcdc0de8e7c504e5 ledger: Implement register_descriptor (Ava Chow) 24ca3c64536b5ff71639b6dab614803edf4c8432 Implement register_descriptors for devices that don't support it (Ava Chow) da7aa3f32178b1028069d71dfbc45fb070ded063 CLI command and boilerplate for registerdescriptor (Ava Chow) 875d7b6ee4142d9b57c90417ef768b0b80f1b934 descriptor: Add RegisteredDescriptor for holding registration data (Ava Chow) 50a6e78dd6e5dc39bbf964fa52f22f07f9c24ba4 descriptor: Add functions for making BIP 388 wallet policies (Ava Chow) 3cfc210e6fb2f28b37eaad527d96f1932f9da9ab descriptor: Parse multipath path specifiers (Ava Chow) e2bd86e88c736e51dc36b6ad7c1de2baae37e78e descriptors: Actually parse the derivation path (Ava Chow) 1f5d85a4f3b520983cf1d646b2481bf82d3a80cf descriptor: Track key expression index (Ava Chow) 447991ffcbdeb05762ae81a2e20d204ec0d0c72d descriptor: Don't sort PubkeyProviders in sortedmulti (Ava Chow)
Pull request description:
The Ledger, BitBox02, Jade, and Coldcard all support registering descriptors with the device to enable signing txs involving complex scripts. This PR adds a `registerdescriptor` command which takes a name and the descriptor to register. The command returns a `registration` which may contain data that must be provided to the device at a later time to remind it of the registered descriptor.
For the BiBox02, Jade, and Coldcard, this command returns an empty string for the registration as these devices store the registration and do not need a reminder.
For the Ledger, the `registration` is the HMAC that the device returns.
Some devices take a descriptor, others take a BIP 388 policy that is stuffed into their protocol. The `Descriptor` and `PubkeyProvider` classes are modified to allow produce BIP 388 compatible strings that can be provided as needed.
Each device does different validation of the descriptor it is provided. We will not do any validation - the user may provide a descriptor that a device refuses to register and any such registration errors will be propagated from the device.
The test case includes a descriptor that should work on all devices.
ACKs for top commit: Sjors: re-ACK 50f5781e70552cca094cba23d0d301f46d364306
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarymerge-commit duplicate discount
AI analysis · Low 32/100
This commit adds a new command called `registerdescriptor` to the HWI tool, which lets users register Bitcoin output descriptors with supported hardware wallets (Ledger, BitBox02, Jade, Coldcard). It also rewrites how descriptors are parsed and stored internally to support newer multi-path descriptor formats and to convert descriptors into BIP 388 wallet policies where needed. The change is a feature addition, not a bug fix, and the commit message and code do not describe any security vulnerability. The main security-relevant aspect is that the tool now passes user-supplied descriptors directly to the device without extra validation, relying on each device's own checks.
The new app renders the "Fees" title at y=3, while the legacy app renders it at y=7. Match both positions explicitly so an address line such as "Fee3bWhy6jMv2rzbRs" does not trigger the fee-screen action.
90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Lower-priorityMerge bitcoin-core/HWI#843: Bump dependencies and modernize pyproject.tomlby Ava Chow · d4687a25 · Aug 12, 2026 · 16 filesMessage 81 · StrongTriage 0Details
Commit message · Ava Chow
Merge bitcoin-core/HWI#843: Bump dependencies and modernize pyproject.toml
d26304f0640e85413f68fa3ff4407e9a12bb0ad2 ci: Add Python 3.13 and 3.14 jobs (Ava Chow) 01da910f54df5d0da6e1027d98bf6ce6f6da1b51 ci, ledger: Bump speculos to ed952a54801f59a71399462b5422976d84c817bb (Ava Chow) 95c580090f3e7cce3dfdc52968f40b5f263b59e8 ci: Remove unused scripts and containers (Ava Chow) 7625779b09078a48221833363762114bd24169dd Remove legacy setup.py (Ava Chow) 1226f4cb61a4ec7ce5ebcc98dea58e98aeba6cf1 pyproject: Modernize to modern pyproject.toml (Ava Chow) 4b019344d5750b6a6422cf2aaf25f4afc4c85961 deps: Convert caret and tilde requirements to inequality requirements (Ava Chow) ec8a4a521a6723fde5a3e5b397011d77bd5a7faf deps: Update pinned deps in poetry.lock to latest (Ava Chow) 07d6dff0df379e440f90c13e1efbe532efeb7ba6 deps: Bump cbor2 to at 5.9.0 (Ava Chow) b43207f181af5f0b65489565db9dc02609b0b9f0 pyproject: Bump maximal python version to 3.16 (Ava Chow)
All other dependencies should have the same minimum and maximums.
typing-extensions is dropped as we aren't using it anymore.
Ran `poetry update` to update all locked dependencies to latest version.
The pyproject.toml file is also modernized to follow PEP 517. Additionally, given that PEP 517 is in use in our minimum python version, we can safely drop the setup.py.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Security candidateMerge bitcoin-core/HWI#839: psbt: misc fixes and add remaining BIP 174 and BIP 370 test vectorsby Ava Chow · 695c731b · Aug 10, 2026 · 4 filesMessage 91 · StrongModerate 60Details
Commit message · Ava Chow
Merge bitcoin-core/HWI#839: psbt: misc fixes and add remaining BIP 174 and BIP 370 test vectors
df8c3f5d4b7e6c6b4856af8bde50c6fc9cf7431c test: add remaining BIP 174 and BIP 370 test vectors (Sjors Provoost) 1ff27e0262f1bffe969ebd68038903930955b20e test: add BIP 370 timelock determination vectors (Sjors Provoost) 498e85a7b31237b57eb110620f62e6bef64fb52e psbt: enforce required locktime bounds (Sjors Provoost) 2a431b8819652473893b0e5dba7feb58ad08a5a5 psbt: reject PSBTv2 input and output fields in PSBTv0 (Sjors Provoost) 8a4052300772adefaf034e498375bd0ccfa18708 psbt: track whether an unsigned tx key was seen (Sjors Provoost) b34f94a6d5648cf9f4dbce73bfe385fc076cd322 psbt: parse the global unsigned tx without witness data (Sjors Provoost) f0520e7e813a4a93a617456a82ae39f0e52213d4 psbt: assume final sequence when PSBT_IN_SEQUENCE is omitted (Sjors Provoost) 2db24a2a0839218843db65b0deeb858676c2a186 psbt: set locktime on the transaction, not the PSBT (Sjors Provoost)
Pull request description:
Each fix / hardening commit introduces the test vectors that cover it.
Mostly straight-forward, but `psbt: parse the global unsigned tx without witness data` is worth a closer look. IIUC it catches up with https://github.com/bitcoin/bips/pull/1099.
ACKs for top commit: achow101: ACK df8c3f5d4b7e6c6b4856af8bde50c6fc9cf7431c
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarydefensive validationfuzzing or regression evidencesigning or wallet pathmerge-commit duplicate discount
AI analysis · Moderate 60/100
This commit tightens how the Bitcoin hardware wallet interface library reads PSBT files. It now rejects PSBTv0 files that contain fields only allowed in the newer PSBTv2 format, enforces sensible locktime ranges, and fixes several bugs where the library could build a transaction with the wrong sequence number or locktime. These are defensive correctness fixes rather than a single obvious remote exploit, but they close paths where a malformed or malicious PSBT could confuse a hardware wallet or downstream software.
Translate the registered descriptor into the policy script configuration and use it for transaction inputs and change outputs.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing boundary
AI analysis · Low 32/100
This commit adds support for signing Bitcoin transactions with registered wallet policies (BIP388) on the BitBox02 hardware wallet. Previously this feature was rejected with an error. The change translates a registered wallet descriptor into a format the BitBox02 understands and uses it when signing transaction inputs and change outputs. It is a feature addition rather than a fix for a known vulnerability, but it touches security-critical signing logic.
Sign with the existing PSBT flow after registerdescriptor has stored the policy on the device.
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing boundary
AI analysis · Informational 22/100
This change removes an error that previously blocked Bitcoin signing for a specific type of wallet policy (BIP388) on the Blockstream Jade hardware wallet. The device now supports these policies, so the software no longer needs to reject them. There is no obvious security bug being fixed; it appears to be a feature-enablement patch.