share: Show the master fingerprint after the threshold - #100
BenWestgate wants to merge 3 commits into
Conversation
054e8d9 to
115f2c2
Compare
`ms32 secret` shows the master fingerprint with the recovered secret, but `ms32 share` never did, so the operator couldn't compare it with the wallet record before writing a new card. Print it above the derived share on a terminal, whether every input is a share or one of them is the secret. `--plain` and redirected output stay unchanged. Closes #86 Claude-Session: https://claude.ai/code/session_015CuLXqAvAovfoVcUmmogwa
eb37865 to
8aaf0fa
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
1 similar comment
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Codex), posted at the maintainer's request.
Not ACKing a3a27b0 yet: this raises the installed-code budget from 5,200 to 5,250 without the explicit authorization AGENTS.md requires. The fingerprint-after-threshold behavior itself looks sound.
a3a27b0 to
8aaf0fa
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated current-head follow-up review (Codex), posted at the maintainer's request.
ACK 8aaf0facce2d now that the unrelated <5250 cap commit has been removed.
The change displays the master fingerprint only on the interactive ms32 share path after a threshold-capable basis is available. --plain and redirected output remain unchanged, and the derivation/recovery validation that establishes the seed is unchanged. No security or correctness blocker found in this focused diff.
The PR is stacked on #105 and preserves <5200; run final CI on the actual integrated #105 + #100 tip before freeze. Responsible-human authorship/review policy still applies.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head review at 13fef0f: no findings. Since the prior ACK, the only new commit brings in #105’s already exact-head-reviewed behavior-preserving cleanup; the fingerprint-after-threshold behavior is unchanged and remains confined to interactive output.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated current-head stack review (Codex), posted at the maintainer's request.
Code ACK 13fef0f39ec9 for the actual #105 + #100 head. #105 is now an ancestor of this branch; comparing #105 (361feb7) to the head yields only the focused cli.py and test_cli.py fingerprint-after-threshold changes. The unrelated <5250 cap change is absent.
The behavior remains scoped to interactive ms32 share: the fingerprint is available only after a threshold-capable basis is recovered, while --plain and redirected output remain unchanged.
Fresh current-head Python-package run #752 is still queued at the time of this review. Treat this as an exact-head code ACK with CI pending. Responsible-human authorship/review still applies before integration.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
V1 disposition (Codex, 2026-10-04): defer this post-audit enhancement from the v1 candidate. The focused behavior is reviewed and the current branch is cleanly stacked after #99, but the feature is not required by any validated DeepSeek/GLM/Kimi/consolidated audit finding. Attempting to carry #100 and #101 together exposed an actual overlap conflict in the late CLI stack. Resolve that after v1 rather than expanding the frozen-candidate review scope. Keep this PR open for post-v1; its current-head code ACK remains useful. Human authorship/review is still required when integrated. |
Requested by Ben · project thread
Problem
ms32 secretshows the recovered master fingerprint, butms32 sharedid not, so an operator deriving a new card could not compare the recovered seed with the separate wallet record before writing that card.Change
On an interactive terminal,
ms32 shareprintsMaster fingerprint: XXXXXXXXabove the derived share whether the threshold was entered as ordinary shares or includedS.--plainand redirected output stay unchanged. The fingerprint is derived only after a threshold-capable basis is present.Review stack
This post-v1 branch currently contains #99 as an ancestor after stack-maintenance PR #123. The unrelated
<5250cap commit was removed and its old tip is preserved onarchive/100-pre-restack-20261004.The focused #100 delta remains the reviewed
cli.py/test_cli.pyfingerprint-after-threshold change. It is intentionally outside the v1 candidate; rebase it onto the eventual post-v1 runtime before integration.Validation
The focused behavior has a Codex ACK. Prior validation passed 926 tests plus Ruff and strict mypy. Existing share/recovery validation still requires a threshold-capable compatible basis before a fingerprint can be recovered; redirected and
--plainoutput behavior is covered by tests.Closes #86.
AI-assisted stack maintenance and review. Responsible-human review/authorship policy still applies before integration.