Merge branch 'fix/bb02-empty-passphrase-scroll'
What changed, and why it matters
This commit changes the on-screen confirmation text from "Use empty passphrase?" to "Use empty\npassphrase?" — adding a line break so the message fits properly on the device's small display. It appears to be a UI layout fix, not a security fix. There is no indication in the commit that this resolves a security vulnerability.
No security action required. Treat as a normal UI/layout fix. If reviewing for release notes, note it as a minor display improvement.
Security signals we found
No security-relevant code paths modified
No input validation, authentication, or cryptographic changes
UI string formatting change only
No vendor disclosure of security relevance in commit message or diff
Evidence from the diff
The patch modifies two Rust files to insert a newline into the body of a confirmation dialog shown when a user proceeds with an empty BIP39 passphrase. The change is purely presentational: the string “Use empty passphrase?” becomes “Use empty\npassphrase?”. A test is updated to match the new expected string. No logic, validation, or cryptographic behavior is altered.
Changed components
BitBox02 firmware unlock workflow UIPassphrase confirmation dialog textInspect captured patch +2 / −2
### src/rust/bitbox02-rust/src/hww/api/unlock/tests.rs
@@ -250,7 +250,7 @@ async fn test_process_host_requires_actual_confirmation() {
));
assert!(screens.iter().any(|s| matches!(s, Screen::PrintScreen { message, .. } if message == "Enter passphrase\non host")));
let expected = if value.is_empty() {
- "Use empty passphrase?"
+ "Use empty\npassphrase?"
} else {
value
};
### src/rust/bitbox02-rust/src/workflow/unlock.rs
@@ -22,7 +22,7 @@ pub(crate) async fn confirm_mnemonic_passphrase(
.ui()
.confirm(&ConfirmParams {
title: "Confirm",
- body: "Use empty passphrase?",
+ body: "Use empty\npassphrase?",
longtouch: true,
..Default::default()
})Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.