Merge pull request #676 from Foundation-Devices/fix/change-verification-error-copy
What changed, and why it matters
This commit only changes the user-facing error message shown when the Passport hardware wallet cannot verify that a transaction's change address belongs to the wallet. The underlying security check and error handling remain exactly the same; only the wording is clearer and less technical. There is no security vulnerability being fixed.
No security action needed. This is a user-experience wording improvement.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The change is a string replacement in double_check_psbt_change_task.py and the corresponding unit test assertion. The previous message ‘Deception regarding change output. BIP32 path doesn’t match actual address.’ is replaced with ‘Transaction rejected. Passport could not verify that the change address belongs to this wallet.’ The same Error.PSBT_FRAUDULENT_CHANGE_ERROR code is still returned, and the verification logic is unchanged.
Changed components
ports/stm32/boards/Passport/modules/tasks/double_check_psbt_change_task.pyports/stm32/boards/Passport/modules/tests/unit/psbt_multisig_approval.pyInspect captured patch +5 / −2
### CHANGELOG.md
@@ -5,6 +5,7 @@ SPDX-License-Identifier: GPL-3.0-or-later
-->
## Head
+- Clarify the error when change-address ownership cannot be verified
- Complete change-address verification before transaction review
- Identify network fees from unverifiable PSBT inputs as unverified
- Validate the complete local xpub when importing multisig wallets
### ports/stm32/boards/Passport/modules/tasks/double_check_psbt_change_task.py
@@ -55,7 +55,8 @@ async def double_check_psbt_change_task(on_done, psbt):
if not good:
# print('double_check_psbt_change_task() Fraudulent Change Error')
- await on_done("Deception regarding change output. BIP32 path doesn't match actual address.",
+ await on_done('Transaction rejected. Passport could not verify that the change address '
+ 'belongs to this wallet.',
Error.PSBT_FRAUDULENT_CHANGE_ERROR)
return
### ports/stm32/boards/Passport/modules/tests/unit/psbt_multisig_approval.py
@@ -88,7 +88,8 @@ def derive_path(self, path):
class FakeErrorPage:
def __init__(self, text):
- assert "BIP32 path doesn't match" in text
+ assert text == ('Transaction rejected. Passport could not verify that the change address '
+ 'belongs to this wallet.')
async def show(self):
events.append('error')Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.