Add the MuSig2 nonce pre-generation changes to the changelog
What changed, and why it matters
This commit only updates the changelog text. It documents a design change in the MuSig2 multi-signature feature: the random public nonces used during signing are no longer tied to a specific transaction, which lets them be generated ahead of time. It also notes a breaking behavior that only one signing session can be pending per wallet policy. There is no code change, no bug fix, and no security patch in this commit itself.
No action needed for this commit. Treat as routine documentation. If reviewing the broader MuSig2 feature, examine the actual implementation commits that changed nonce generation and session handling.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff adds two bullet points under a new ‘Changed’ section in CHANGELOG.md. The first states that MuSig2 pubnonces are now independent of the transaction, enabling pre-generation. The second states the breaking consequence: only one pending signing session per wallet policy, and re-running round 1 discards the prior session. No source code, build files, tests, or documentation beyond the changelog are modified.
Changed components
CHANGELOG.mdInspect captured patch +5 / −0
### CHANGELOG.md
@@ -13,6 +13,11 @@ Dates are in `dd-mm-yyyy` format.
- Support for [BIP-0322](https://github.com/bitcoin/bips/blob/master/bip-0322.mediawiki) (v2.0.0) generic signed messages: a PSBT carrying the `PSBT_GLOBAL_GENERIC_SIGNED_MESSAGE` global field (0x09) is now verified to have the exact BIP-322 *to_sign* structure and reviewed on-screen as a message signature (account, address and message), instead of being shown as a transaction with an `OP_RETURN` output and no fees. Proof-of-funds requests (additional inputs spending real coins of the account) are supported, with the total proven amount shown in the review. Works with any supported wallet policy, including multisig and miniscript.
+### Changed
+
+- MuSig2: the pubnonces no longer depend on the transaction, so they can be pre-generated before the transaction is known. See [doc/musig.md](doc/musig.md).
+- MuSig2 (breaking): as a consequence, at most one signing session can be pending for a given wallet policy; executing round 1 again for the same wallet policy discards the previous session, and round 2 with the old pubnonces fails.
+
### Fixed
- The transaction lock time is now determined as BIP-370 prescribes, from each input's `PSBT_IN_REQUIRED_TIME_LOCKTIME` / `PSBT_IN_REQUIRED_HEIGHT_LOCKTIME` together with `PSBT_GLOBAL_FALLBACK_LOCKTIME`, instead of always using the fallback verbatim. PSBTs not using the individual preferred locktime fields are unaffected, as they will keep depending on `PSBT_GLOBAL_FALLBACK_LOCKTIME` alone.Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.