Skip to content

ci: Verify wallet fixtures against Bitcoin Core - #51

Open
BenWestgate wants to merge 1 commit into
3-remove-python-bip32-dependencyfrom
codex/9-core-fixture-ci
Open

BenWestgate wants to merge 1 commit into
3-remove-python-bip32-dependencyfrom
codex/9-core-fixture-ci

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Fixes #9.

Run the real Bitcoin Core regtest harness on relevant pull requests, weekly, and on demand against pinned v32.0rc2 binaries. The harness loads every frozen seed→fingerprint value from tests/data/wallet_fingerprints.json through tools/_wallet_test_vectors.py and checks it independently against Core, so a stale or wrong frozen value fails rather than merely agreeing with its unit-test fixture.

The workflow is path-filtered on the wallet/Core/fingerprint files, so unrelated pull requests do not pay the Core download cost. Merging this after #7 completes #6's independent real-Core coverage requirement.

The v32.0rc2 x86_64 archive SHA256 is pinned to the value published in the signed RC2 manifest. Rechecked 2026-09-30: the official Bitcoin Core v32.0 tag namespace still contains only v32.0rc1 and v32.0rc2; no final v32.0 tag exists. The annotated rc2 tag is cryptographically verified. Repin and rerun if a newer signed RC or final appears before release.

Review status

Current head 768bcba is the single workflow commit restacked directly onto #7's Core-native wallet setup at f9c3bc8. All inline review threads are resolved. The earlier trigger blocker remains fixed by the path-filtered pull_request trigger.

Current-head validation:

  • Bitcoin Core wallet-fixtures run 36732713815: success;
  • Python package run 36732713875: success;
  • the Core workflow therefore exercised the current Wallet: use Core for setup and remove test crypto deps #7 addhdkey / createwalletdescriptor account-0 path, including the frozen fingerprint verifier, against the pinned v32.0rc2 binary.

The workflow logic was previously agent-reviewed at 1038dfb; the restack changes only its parent and current validation confirms it composes with #7's new Core-native behavior.

After #7 is integrated into reviewability-v1, retarget/integrate this one-file follow-up before refreshing #57 onto the combined correction/Core tip.

Disclosure: AI tools were used while implementing and checking this user-requested branch-to-branch contribution.

Closes #6.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate added area: ci Continuous integration and workflow configuration. area: wallet/core Wallet integration and Bitcoin Core boundaries. enhancement New feature or request gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. labels Sep 24, 2026
@BenWestgate

Copy link
Copy Markdown
Owner Author

@claude review #51

@BenWestgate

Copy link
Copy Markdown
Owner Author

Fresh release-gate verification on 2026-09-25: v32.0rc1 and v32.0rc2 are both annotated Bitcoin Core tags with valid GitHub signature verification, no v32.0 final tag exists yet, and the pinned official rc2 binary still passes tools/bitcoin_core_regtest.py end-to-end ({"bitcoin_core": "/Satoshi:32.0.0/", "status": "pass"}). This remains pre-final evidence; #5/#52 must be repinned and rerun if a newer signed RC or final v32.0 appears before publication.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

Not ACKing f01a626 yet.

  • schedule and workflow_dispatch only fire for workflow files on the default branch (master). While this lives on #7 or reviewability-v1, it never runs.
  • Suggest adding pull_request with a paths: filter (tests/data/wallet_fingerprints.json, tools/_wallet_test_vectors.py, tools/bitcoin_core_regtest.py, src/codex32/_bitcoin_core.py). That fixes the trigger, and a changed fixture gets checked before merge instead of up to a week later.
  • Pin/download/checksum steps look right.

Comment thread .github/workflows/bitcoin-core-fixtures.yml

Copy link
Copy Markdown
Owner Author

Release-monitor refresh (2026-09-26): the upstream bitcoin/bitcoin tag namespace still has only v32.0rc1 and v32.0rc2 under v32.0; no final v32.0 tag exists yet. The rc2 pin therefore remains the newest signed v32 candidate for this CI gate. Keep the existing requirement to repin and rerun if rc3/final appears before publication.

Copy link
Copy Markdown
Owner Author

Release-monitor check (2026-09-26): the official Bitcoin Core 32.0 directory still exposes test.rc2/; that RC directory includes both SHA256SUMS and SHA256SUMS.asc dated 2026-09-22. No stable 32.0 artifact set is visible yet. The current v32.0rc2 pin therefore remains the newest signed release-candidate evidence; repin only when a newer signed RC or final appears.

@BenWestgate BenWestgate added the area: security Security invariants, hardening, and security-sensitive boundaries. label Sep 27, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Owner Author

Bitcoin Core release-monitor refresh (2026-09-27): the official bitcoin/bitcoin v32.0* tag namespace still contains only v32.0rc1 and v32.0rc2; there is still no final v32.0 tag. The v32.0rc2 annotated tag continues to have valid GitHub signature verification. No pin change is warranted today; keep the existing repin/rerun condition if a newer signed RC or final appears before publication.

Copy link
Copy Markdown
Owner Author

Release-gate review follow-up: the earlier trigger NACK is resolved. The current workflow includes the path-filtered pull_request trigger, the only review thread is resolved, and current head 0466510 has a passing real-Core verify job plus the full Python package matrix. Keep this PR stacked on #7 until #7 merges; then retarget to reviewability-v1 and preserve the one-workflow-file review delta. No code-review blocker remains from the trigger finding.

@BenWestgate

Copy link
Copy Markdown
Owner Author

Release-monitor refresh (2026-09-27/28): upstream bitcoin/bitcoin still exposes only v32.0rc1 and v32.0rc2 under v32.0*; both annotated tag objects report valid signature verification. The official Bitcoin Core 32.0 directory still exposes only test.rc2/, containing SHA256SUMS and SHA256SUMS.asc. There is no v32.0rc3 or final v32.0, so the current rc2 pin remains correct. Repin and rerun only when a newer signed RC or final appears before release.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review, posted at the maintainer's request.

ACK 1038dfb. The pull_request path trigger fixes the prior blocker.

@BenWestgate BenWestgate added the area: packaging/release Packaging, artifacts, compatibility, and release qualification. label Sep 30, 2026 — with ChatGPT Codex Connector
Run the pinned Bitcoin Core v32 fixture verifier on relevant pull requests, weekly, and on demand so frozen seed-to-fingerprint data cannot silently drift from Core.

Fixes #9
@BenWestgate
BenWestgate force-pushed the codex/9-core-fixture-ci branch from 1038dfb to 768bcba Compare September 30, 2026 14:54

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated release-gate review, posted at the maintainer's request.

ACK 768bcba.

This is the previously reviewed one-file Core fixture workflow restacked directly onto #7's current Core-native wallet head f9c3bc8. The workflow logic is unchanged. On this exact head, Bitcoin Core wallet-fixtures run 36732713815 passed against the pinned v32.0rc2 binary, and Python-package run 36732713875 passed. The real-Core check therefore covers #7's current addhdkey / createwalletdescriptor account-0 setup and the frozen fingerprint fixtures. All inline threads are resolved.

No remaining code blocker from this review. Integrate #7 first, then this one-file follow-up before refreshing #57.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci Continuous integration and workflow configuration. area: packaging/release Packaging, artifacts, compatibility, and release qualification. area: security Security invariants, hardening, and security-sensitive boundaries. area: wallet/core Wallet integration and Bitcoin Core boundaries. enhancement New feature or request gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant