AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 38 Bitcoin

Merge pull request #710 from Foundation-Devices/SFT-8207-bound-provisioning-rng

Public commit record

What the developer wrote

Authored by mjg-foundation

73/100 · Adequate
Merge pull request #710 from Foundation-Devices/SFT-8207-bound-provisioning-rng

SFT-8207: bounded pairing secret retries
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a safety cap to how many times the Passport bootloader can retry picking a random pairing secret if the first word keeps looking like erased flash. It also adds tests that simulate hardware random-number-generator failures. The change is defensive: it prevents an unlucky or faulty RNG from causing an infinite loop during factory provisioning, and makes the bootloader call a fatal error handler instead of hanging or continuing with bad entropy. The commit notes this only affects future provisioning/source reuse, not bootloaders already deployed in the field.

Recommended action

Treat this as a hardening/defensive fix. Review whether the 8-retry bound and `rng_fatal_error()` behavior are sufficient for provisioning workflows, and ensure factory provisioning tooling handles fatal RNG errors safely. No immediate end-user action is required because deployed bootloaders are not field-upgradeable.

Security signals we found

01

Bounded retry loop prevents potential denial-of-service/infinite loop during provisioning

02

Fatal error on RNG exhaustion stops provisioning before flash writes or secure-element setup

03

Tests added/expanded to verify retry bound and RNG failure handling

04

Comment acknowledges production bootloader lacks independent entropy source and retains MCU RNG

05

Change is explicitly scoped to future provisioning, not field-upgradable deployed bootloaders

Risk score

Why this scored 38/100

Our methodology →
Potential impact 12/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 4/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.