AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 55 Bitcoin

Merge pull request #659 from Foundation-Devices/fix/unicode-settings-save

Public commit record

What the developer wrote

Authored by Jacksper13

58/100 · Thin
Merge pull request #659 from Foundation-Devices/fix/unicode-settings-save

Fix Unicode values in external settings
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This update fixes a bug in how the Passport hardware wallet saves user settings that contain non-English characters (Unicode). Previously, the code measured text size in characters instead of encoded bytes, so a setting that looked small could actually exceed the storage slot and either be written past its boundary or silently truncated. The patch now encodes the data to UTF-8 bytes before checking size, rejects oversized saves cleanly, and reports a proper error instead of silently failing. It also adds tests for these edge cases.

Recommended action

Treat this as a security-reliability fix and include it in the next firmware release. Review other settings-backed features for similar character-vs-byte length assumptions. Run the new unit tests (ext_settings.py and multisig_save_task.py) in CI to prevent regressions.

Security signals we found

01

Buffer size check used character length instead of encoded byte length, leading to potential slot overflow with Unicode data

02

Oversized settings could previously be partially written or silently ignored instead of failing atomically

03

Multisig wallet save task now rolls back in-memory state on any save failure and reports distinct errors

04

New SettingsOutOfSpace exception and USER_SETTINGS_SAVE_FAILED error code added for clearer failure handling

05

Unit tests added to verify Unicode round-trip, exact-size payload, oversized rejection, and rollback behavior

Risk score

Why this scored 55/100

Our methodology →
Potential impact 18/30
Exploitability 8/25
Stealth signal 7/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.