AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 25 Bitcoin

Merge rust-bitcoin/rust-bitcoin#6955: key_expression: preserve master-key invariants in Xpub Arbitrary

Public commit record

What the developer wrote

Authored by Andrew Poelstra

91/100 · Strong
Merge rust-bitcoin/rust-bitcoin#6955: key_expression: preserve master-key invariants in Xpub Arbitrary

cf90d73d43935a7efea1c92807f46f82cfde17ce key_expression: preserve master-key invariants in Xpub Arbitrary (myetcd)

Pull request description:

`Xpub::arbitrary` samples the parent fingerprint and child number independently of depth. When depth is zero, it can generate a master Xpub that is rejected by `Xpub::decode` after encoding.

Generate depth first and set the parent fingerprint and child number to zero for master keys, matching the existing `Xpriv::arbitrary` implementation. Non-master keys continue to generate both fields from the input.

Add deterministic regression tests for master and non-master Xpubs, including binary encoding/decoding round trips. The master-key regression test fails before the fix.

Validation:
- `cargo test -p bitcoin-key-expression --features arbitrary`
- `cargo test -p bitcoin-key-expression --all-features`
- `cargo test -p bitcoin-key-expression --no-default-features --features alloc,arbitrary`
- `cargo rbmt -p bitcoin-key-expression fmt --check`
- `just lint` — successful, with existing removed-lint and dependency-check warnings.


ACKs for top commit:
apoelstra:
ACK cf90d73d43935a7efea1c92807f46f82cfde17ce; successfully ran local tests


Tree-SHA512: 2df6949bce9202723545b5e767c1f0ae2fb269a3c065cfd678072c6c03aae5977f2b4d9cb0a519e9a985cef1253defa09150370a8fc742a90fa9e81b222f0c89
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This change fixes a bug in test-only code that generates random fake Bitcoin extended public keys (xpubs). Previously, when generating a master xpub (depth 0), the code could pick random values for the parent fingerprint and child number, which violates the BIP32 rule that master keys must have those fields set to zero. That caused some generated xpubs to fail a round-trip encode/decode check. The fix makes depth-zero xpubs always use zero for those two fields, matching how private master keys were already generated. It only affects fuzzing/property tests, not normal wallet operations.

Recommended action

No urgent action needed for production deployments; the change is test-only. Reviewers should verify that the new regression tests pass under all feature combinations and that no other Arbitrary implementations in the crate have similar invariant issues.

Security signals we found

01

BIP32 master-key invariant violation in generated test data

02

Encode/decode round-trip failure for generated master xpubs

03

Fix aligns Xpub::arbitrary with existing Xpriv::arbitrary behavior

04

Only reachable under the arbitrary feature (fuzzing/property testing)

Risk score

Why this scored 25/100

Our methodology →
Potential impact 4/30
Exploitability 2/25
Stealth signal 3/15
Affected reach 4/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.