AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 30 Bitcoin

SFT-8169: remove dead witness iterator branch and reject witness serialized unsigned txns clearly

Public commit record

What the developer wrote

Authored by Jack

73/100 · Adequate
SFT-8169: remove dead witness iterator branch and reject witness serialized unsigned txns clearly

input_witness_iter() had a branch referencing fd and num_in, neither of
which exists in its scope. It is unreachable: had_witness can only be
true for a witness serialized unsigned transaction, and parse_txn()
already fails on those when _skip_n_objs() hits an unknown 'CTxInWitness'
and raises a bare ValueError.

BIP-174 requires the unsigned transaction to carry no witness data, so
keep rejecting it, but raise FatalPSBTIssue with a message the PSBT tasks
already know how to surface. had_witness and wit_start are then always
false and None, so drop them along with the branch that read them.

No validation is relaxed: the same inputs are rejected at the same point,
with a better message.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit cleans up how the Passport hardware wallet handles Bitcoin transactions that incorrectly include witness data. It removes a dead, broken code branch that referenced non-existent variables and replaces a confusing low-level error with a clear user-facing message. The same invalid transactions were already being rejected; this change just makes the rejection clearer and safer, and adds tests to prove it.

Recommended action

No urgent action required. This is a defensive cleanup that improves robustness and error clarity. Users and integrators should ensure firmware is updated to include this change, and continue to follow BIP-174 compliant PSBT serialization.

Security signals we found

01

Removes unreachable branch referencing undefined variables (`fd`, `num_in`), eliminating a latent crash or confusion risk

02

Replaces a bare ValueError with a structured FatalPSBTIssue, improving error handling and user messaging

03

Maintains existing rejection policy for BIP-174 non-compliant PSBTs (no validation relaxation)

04

Adds unit tests covering witness-serialized unsigned transaction rejection and edge cases

Risk score

Why this scored 30/100

Our methodology →
Potential impact 5/30
Exploitability 3/25
Stealth signal 4/15
Affected reach 6/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.