compare rewritten keystore derivation paths when checking for a single derivation path in the terminal receive dialog
What changed, and why it matters
This is a small UI consistency fix in Sparrow Wallet's terminal (command-line) receive dialog. It changes how the wallet checks whether all key storage locations (keystores) use the same derivation path. Previously the comparison used raw string paths, which could differ in format even when logically identical. Now it compares rewritten/normalized paths. The effect is mostly cosmetic: it determines whether the terminal receive screen shows one derivation path or multiple. There is no direct evidence this enables theft of funds or unauthorized transactions.
No urgent action required. Treat as a routine bugfix/UI consistency improvement. Reviewers may verify that KeyDerivation.writePath produces the expected canonical form and that no other dialogs rely on the old raw-string comparison.
Security signals we found
Normalization of derivation-path comparison
UI-only terminal receive dialog change
No cryptographic or signing logic modified
Evidence from the diff
ReceiveDialog.isSingleDerivationPath() decides if all keystores share a single derivation path. The old code compared firstDerivation.getDerivationPath() (a string) against each keystore’s getDerivationPath(). The new code calls KeyDerivation.writePath(firstDerivation.getDerivation()) and compares normalized string forms. This avoids false negatives where semantically equivalent paths are formatted differently, which could cause the terminal UI to display multiple derivation paths when only one logical path is in use. The change is defensive and UI-only; it does not alter key derivation, signing, or wallet logic.
Changed components
src/main/java/com/sparrowwallet/sparrow/terminal/wallet/ReceiveDialog.javaInspect captured patch +2 / −1
### src/main/java/com/sparrowwallet/sparrow/terminal/wallet/ReceiveDialog.java
@@ -129,8 +129,9 @@ protected String getDerivationPath(WalletNode node) {
protected boolean isSingleDerivationPath() {
KeyDerivation firstDerivation = getWalletForm().getWallet().getKeystores().get(0).getKeyDerivation();
+ String firstDerivationPath = KeyDerivation.writePath(firstDerivation.getDerivation());
for(Keystore keystore : getWalletForm().getWallet().getKeystores()) {
- if(!keystore.getKeyDerivation().getDerivationPath().equals(firstDerivation.getDerivationPath())) {
+ if(!KeyDerivation.writePath(keystore.getKeyDerivation().getDerivation()).equals(firstDerivationPath)) {
return false;
}
}Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.