Skip to content

release: 7.15 audited candidate - #476

Open
BitHighlander wants to merge 1 commit into
release/7.14.3-bitcoin-onlyfrom
release/7.15
Open

release: 7.15 audited candidate#476
BitHighlander wants to merge 1 commit into
release/7.14.3-bitcoin-onlyfrom
release/7.15

Conversation

@BitHighlander

@BitHighlander BitHighlander commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator

Review identity

This is the canonical upstream stacked review of the exact fork-audited and exact-head-green 7.15 candidate.

Item Exact identity
Base / inherited release release/7.14.3-bitcoin-only @ abe29d1288638867dc64dfe04219b89f7a593133
Candidate release/7.15 @ a56fb3e88d7dbbe31a321179c10a8fd2023d8f0c
History One squashed 7.15 commit directly on 7.14.3
Firmware surface 181 files, +29,480 / -4,536
Fork audit PR #629
Fork exact-head CI Fully green; all three fork triggers passed

Canonical dependency pins

  • keepkey/trezor-firmware @ merged upstream PR #11, merge commit 8a392f70a5d5575ece3dfb35f115d4a4b27f497c
  • keepkey/device-protocol @ 8545cd5b615f5832374afbf06387a3f28869285e
  • keepkey/python-keepkey @ 9c3982035664dbec44c6d1d60db6edb9fa59713c
  • all committed submodule URLs point to canonical upstream repositories

The 7.14.3 audit is inherited only for unchanged bytes. Every 7.15 hunk touching an inherited invariant remains present in the line ledger.

Review gates

  • Exact-head fork and both canonical upstream CI executions are fully green.
  • Complete the 186 commit-pinned firmware and trezor-crypto line checks posted below.
  • Link every finding to a fix or explicit technical disposition.
  • Obtain a fresh exact-head automated review and human approval.
  • Complete RC1 physical signing, display, migration, RNG, and product-boundary testing.
  • Merge canonical device-protocol webusb-friendly labelling #112 and python-keepkey docs: add note about Cosmos paths #197; keep both firmware branches on the same final Python pin and rerun CI if the merge object changes.

Do not merge, tag, sign, publish, or release from this PR until every applicable gate is closed.

Squash the 7.15 delta onto the finalized 7.14.3 candidate: core UI and transport work, chain signing and clear-sign metadata, Zcash Orchard support, storage and RNG hardening, dependency updates, tests, documentation, and release evidence gates. Keep every dependency on its canonical upstream URL.
@BitHighlander

Copy link
Copy Markdown
Collaborator Author

7.15 line audit — core, build, EVM and Solana

Exact range: abe29d1288638867dc64dfe04219b89f7a593133a56fb3e8. Every link is commit-pinned.

Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code.

Changed files represented in this checklist: 81.

715-BUILD — product composition, platform and memory layout

715-CORE — board, confirmation UI, transport and emulator

715-DEP — dependency identity, crypto and build integration

715-EVM — EVM and clear-sign metadata

715-SOL — Solana instruction and metadata disclosure

  • include/keepkey/firmware/solana.h — base: base: L159-L162, L194-L198; candidate: candidate: L34-L38, L164-L175, L197-L288, L303-L365
  • lib/firmware/fsm_msg_solana.h — base: —; candidate: candidate: L462-L586, L728-L812
  • lib/firmware/solana.c — base: base: L128, L138-L140, L148, L160, L172, L179-L214, L278-L284, L294-L295, L308-L311, L320, L331-L334, L342-L343, L356-L359, L372-L374, L432, L475, L510, L518-L522, L611, L629, L660, L687-L700, L705-L707, L712-L717, L722-L726, L746, L751-L759, L802-L868, L881-L887; candidate: candidate: L22-L25, L79-L90, L140-L150, L158-L159, L169-L173, L185-L188, L200, L205-L229, L293-L299, L309-L328, L338-L346, L354-L355, L373-L377, L390-L392, L405, L520-L524, L544-L552, L648-L649, L667, L698-L699, L706-L711, L732-L755, L760, L765-L767, L772-L937, L948-L1027, L1037, L1081-L1236, L1247-L1252, L1257-L1268
  • unittests/firmware/solana.cpp — base: base: L4, L26-L29, L65-L77, L161-L314, L441, L448-L450, L455-L473, L478-L611, L618-L629, L634-L638, L644-L667, L699-L715, L736-L738, L747-L753, L761-L819, L1030, L1038, L1080-L1084; candidate: candidate: L22-L91, L338-L341, L349-L352, L357-L372, L377-L396, L403-L414, L419-L423, L429-L471, L525-L527, L536-L537, L755-L762, L767-L775, L816-L923, L971-L1027, L1033-L1092, L1122-L1553

@BitHighlander

Copy link
Copy Markdown
Collaborator Author

7.15 line audit — signing, Zcash and state security

Exact range: abe29d1288638867dc64dfe04219b89f7a593133a56fb3e8. Every link is commit-pinned.

Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code.

Changed files represented in this checklist: 56.

715-CHAIN — other chain signing and disclosure

715-CHAIN — other chain signing and regression coverage

715-STATE — storage, RNG and secret/session lifecycle

715-ZEC — Zcash, Orchard, Pallas and RedPallas

@BitHighlander

Copy link
Copy Markdown
Collaborator Author

7.15 line audit — CI, release evidence and documentation

Exact range: abe29d1288638867dc64dfe04219b89f7a593133a56fb3e8. Every link is commit-pinned.

Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code.

Changed files represented in this checklist: 44.

715-CI — CI, release evidence, manifests and static gates

715-DOC — shipping requirements, audit guidance and non-shipping designs

@BitHighlander

Copy link
Copy Markdown
Collaborator Author

7.15 line audit — trezor-crypto dependency delta

Exact range: cdc05bebe9e6989cf711e1b5bea6324fd09f848e8a392f70a5d5575ece3dfb35f115d4a4b27f497c. Every link is commit-pinned.

Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code.

Changed files represented in this checklist: 5.

DEP-CRYPTO-ZEC — Pallas, RedPallas and Orchard primitives

@BitHighlander

BitHighlander commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator Author

Audit index — 7.15 stacked delta

This is the durable top-level ledger. Detailed checkboxes live in the commit-pinned line maps below. A checkbox means every listed base and candidate range in that file was reviewed; findings must cite the exact range and head.

Immutable review identity

Item Exact identity
Base / inherited release release/7.14.3-bitcoin-only @ abe29d1288638867dc64dfe04219b89f7a593133
Candidate release/7.15 @ a56fb3e88d7dbbe31a321179c10a8fd2023d8f0c
History shape one squashed 7.15 delta directly on the squashed 7.14.3 candidate
Pre-squash preservation preserve/release-7.15-pre-upstream-squash-20260828 @ fb3e3389
Firmware delta 181 files, +29,480 / −4,536

The 7.14.3 audit is inherited only for unchanged bytes. Any 7.15 hunk touching an inherited invariant is explicitly present in the line maps below.

Canonical dependency identity

Dependency Base pin Candidate pin Internal line map
keepkey/trezor-firmware cdc05beb merged upstream PR #11 @ 8a392f70 5 files / checkboxes
keepkey/device-protocol 8545cd5b unchanged 8545cd5b inherited from PR #627
keepkey/python-keepkey 9c398203 unchanged 9c398203 inherited from PR #627 / upstream PR #197
Python's canonical DP 27d3fa1f unchanged 27d3fa1f upstream PR #112

Every committed submodule URL is canonical upstream. The stale BitHighlander/trezor-firmware URL was removed during the squash without changing the canonical 8a392f70 gitlink.

Line-addressable audit surfaces

The firmware maps cover all 181 changed files exactly once. Roadmaps and RFCs are audit inputs, not claims that their future mechanisms ship in 7.15.

Gates

  • All 186 line-map checkboxes have an identified reviewer and are complete.
  • Findings are linked to fixes or explicit technical dispositions.
  • Canonical upstream exact-head CI is fully green for a56fb3e8: push run 33203810212 and PR run 33203844031. All three fork preflight runs also passed.
  • Fresh exact-head Copilot review converges after the squash.
  • RC1 physical signing, display, migration, RNG and product-boundary testing is complete.
  • Canonical DP/Python human reviews and merges are complete; both firmware branches share the final upstream Python pin.

Head-change log

Old → new Surfaces Disposition
fb3e3389a56fb3e8 all audit identities; dependency URL History squashed into one delta; old head preserved. Candidate tree differs from the old head only by changing the trezor-firmware URL from the fork to canonical upstream; the gitlink remains 8a392f70. All line links and exact-head gates were regenerated.

No merge, tag, signing, publishing, release, or physical-test claim is made by this upstream audit vehicle.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant