Merge pull request #685 from Foundation-Devices/fix/errors-enum-missing-comma
What changed, and why it matters
This commit adds a regression test to make sure two specific error codes (NOT_BIP39_MODE and MULTISIG_STORAGE_IDX_ERROR) actually exist in the firmware's error list. The underlying bug was a missing comma in a tuple of error names, which silently merged the two names into one long, nonsense name. The commit only adds tests; it does not show the actual fix to the error list, though the branch name and message imply the fix happened elsewhere. Because the missing error codes would cause the device to crash with an AttributeError when those error conditions are hit, this is a real reliability/defensive issue, but it is not a remotely exploitable vulnerability.
Verify that the companion fix to the errors module (restoring the comma in the Error enum tuple) is present in the same release/branch, since this commit only adds the regression test. Run the new test and confirm both error codes are reachable. Review other enum/tuple definitions in the firmware for similar missing-comma issues.
Security signals we found
Regression test added for enum member integrity
Missing comma in string tuple could silently remove error codes
Runtime AttributeError risk when removed error codes are referenced
Firmware error-handling robustness issue
Evidence from the diff
The commit introduces a unit test file, error_codes.py, and registers it in test_unit.py. The test imports the Error class from errors and asserts that Error.MULTISIG_STORAGE_IDX_ERROR and Error.NOT_BIP39_MODE exist, are distinct, and that the concatenated name MULTISIG_STORAGE_IDX_ERRORNOT_BIP39_MODE does not exist. The comment explains that the Error enum is built from a tuple of strings and a missing comma silently concatenates adjacent string literals. The commit title and branch name indicate the fix restored the two missing error codes, but the diff itself only contains the test, not the enum definition change. The security relevance is indirect: if code paths raise Error.NOT_BIP39_MODE or Error.MULTISIG_STORAGE_IDX_ERROR, a missing enum member would turn a controlled error into an unhandled AttributeError, potentially aborting an operation or leaving the device in an inconsistent state.
Changed components
ports/stm32/boards/Passport/modules/tests/test_unit.pyports/stm32/boards/Passport/modules/tests/unit/error_codes.pyerrors.Error enum (not shown in diff)Inspect captured patch +23 / −0
### ports/stm32/boards/Passport/modules/tests/test_unit.py
@@ -16,6 +16,10 @@ def doit(file):
return doit
+def test_error_codes(test):
+ assert test('error_codes.py') == b'OK'
+
+
def test_ext_settings(test):
assert test('ext_settings.py') == b'OK'
### ports/stm32/boards/Passport/modules/tests/unit/error_codes.py
@@ -0,0 +1,19 @@
+# SPDX-FileCopyrightText: © 2026 Foundation Devices, Inc. <hello@foundation.xyz>
+# SPDX-License-Identifier: GPL-3.0-or-later
+#
+# Error codes are built from a tuple of names, so a missing comma silently
+# concatenates two of them into one member. The intended names then don't
+# exist, and every reference to them raises AttributeError at runtime.
+
+from errors import Error
+
+
+for name in ('MULTISIG_STORAGE_IDX_ERROR', 'NOT_BIP39_MODE'):
+ assert hasattr(Error, name), name
+
+assert Error.MULTISIG_STORAGE_IDX_ERROR != Error.NOT_BIP39_MODE
+
+# The exact symptom of the missing comma this test was added for.
+assert not hasattr(Error, 'MULTISIG_STORAGE_IDX_ERRORNOT_BIP39_MODE')
+
+return_value.write(b'OK')Why this scored 33/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.