release: 7.14.3 bitcoin-only audited candidate - #475
Conversation
Squash the audited 7.14.3 delta onto the immutable 7.14.2 review base: Bitcoin-only product boundaries, Taproot signing, Dice entropy and RNG health, storage compatibility, disclosure and signing fixes, dependency pins, tests, and release evidence gates.
7.14.3 line audit — firmware deltaExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 117. 7143-BTC — Bitcoin, Taproot, signing and exact disclosure
7143-CI — CI, release provenance, artifacts and failure propagation
7143-DEP — dependency identity and build integration
7143-DOC — security contract and operator documentation
7143-ENT — Dice, RNG, setup, storage and secret lifecycle
7143-PROD — Bitcoin-only product boundary and link surface
7143-REG — cross-chain and regression validation
7143-REG — cross-chain, parser, UI and session hardening
|
7.14.3 line audit — trezor-crypto dependencyExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 57. DEP-CRYPTO-BTC — secp256k1, Schnorr and Taproot primitives
DEP-CRYPTO-CORE — shared hashes, encodings and build surface
DEP-CRYPTO-ED — Ed25519 API and callers
DEP-CRYPTO-TEST — dependency tests and vectors
DEP-CRYPTO-ZEC — Pallas, RedPallas and Orchard primitives
|
7.14.3 line audit — device-protocol dependencyExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 21. DEP-DP-BOUNDS — nanopb capacity and allocation bounds
DEP-DP-GEN — generators, documentation and repository wiring
DEP-DP-SCHEMA — protobuf message and wire-ID definitions
|
7.14.3 line audit — Python companion dependencyExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 81. DEP-PYK-CI — companion CI, catalogs and generation gates
DEP-PYK-DOC — packaging, fixtures and documentation
DEP-PYK-LIB — host API, protobuf bindings and transaction logic
DEP-PYK-TEST — device integration, vectors and report coverage
|
Audit index — 7.14.3 Bitcoin-onlyThis is the durable top-level ledger. Detailed checkboxes live in the commit-pinned line maps below. A checkbox means every listed base and candidate range in that file was reviewed; findings must cite the exact range and head. Immutable review identity
Canonical dependency identity
The direct firmware DP pin intentionally remains Line-addressable audit surfaces
Gates
Head-change log
No merge, tag, signing, publishing, release, or physical-test claim is made by this upstream audit vehicle. |
Review identity
This is the canonical upstream review of the exact fork-audited and exact-head-green 7.14.3 Bitcoin-only candidate.
review/7.14.2-pr458-current@3df4038f48a5c8d2656d71749e7f40a989f979c2release/7.14.3-bitcoin-only@abe29d1288638867dc64dfe04219b89f7a593133The immutable canonical review base is intentional. The active 7.14.2 release branch moved after this audit was frozen, and current
developalready contains the earlier 7.15 merge and later work. Retargeting either moving branch would change the reviewed bytes and invalidate the exact line ledger.Canonical dependency pins
keepkey/trezor-firmware@cdc05bebe9e6989cf711e1b5bea6324fd09f848ekeepkey/device-protocol@8545cd5b615f5832374afbf06387a3f28869285ekeepkey/python-keepkey@9c3982035664dbec44c6d1d60db6edb9fa59713cReview gates
Do not merge, tag, sign, publish, or release from this PR until every applicable gate is closed.