Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
a08dbd9
test(7.15): consolidated Python harness, bindings, and device coverage
BitHighlander Aug 22, 2026
d58dc63
fix: address review on the 7.15 harness
BitHighlander Aug 22, 2026
e60ce4f
ci(circleci): stop gating python-keepkey on the firmware's C++ suite
BitHighlander Aug 23, 2026
c73750c
fix(thorchain): expose version-gated send denoms
BitHighlander Aug 23, 2026
55adaad
test(thorchain): defer denom emulator coverage
BitHighlander Aug 23, 2026
be1975c
docs(osmosis): correct the uosmo restriction rationale
pastaghost Aug 23, 2026
70f3055
fix(zcash): validate the transparent signature list
pastaghost Aug 23, 2026
44d82ef
ci(bitcoin-only): actually run the product-boundary suite
pastaghost Aug 23, 2026
73f96be
fix(clearsign-abi): reject Solidity types that do not exist
pastaghost Aug 23, 2026
d469ea6
test(ethereum): bind the signing-guard tests to the signed pre-image
pastaghost Aug 23, 2026
9d64a07
ci(tokens): gate the firmware token-table generators
pastaghost Aug 23, 2026
f01c36d
ci(firmware): pin the emulator build to an immutable revision
pastaghost Aug 23, 2026
2663fd5
fix(tests): use py3.6-compatible subprocess.run kwargs
BitHighlander Aug 23, 2026
5f872cc
fix(tests): the display-disclosure suite was passing vacuously
BitHighlander Aug 23, 2026
34a1c6c
fix(tests): a v6 fixture must use the real empty-Orchard-bundle digest
BitHighlander Aug 23, 2026
b91d87b
test: an oversized multisig signature must be refused
BitHighlander Aug 23, 2026
e68a877
fix(tests): end-anchor the token-table row pattern
pastaghost Aug 23, 2026
d46a985
fix(clearsign): point the Aave fixtures at the V3 Pool
pastaghost Aug 23, 2026
f275388
fix(metadata): make signing preconditions survive python -O
pastaghost Aug 23, 2026
bc7eecf
fix(tokens): key deduplication on (chain_id, address)
pastaghost Aug 23, 2026
63484ad
fix(tests): resolve the emulator path before killing it
pastaghost Aug 23, 2026
4e4374b
fix(udp): let the emulator timeout reach the caller
pastaghost Aug 23, 2026
65f69f7
fix(osmosis): version-gate the denom restriction
pastaghost Aug 23, 2026
1db9da2
ci(rc18): run the suite against the release target, non-blocking
pastaghost Aug 23, 2026
7ab558b
fix(tests): follow through on the Aave and precondition changes
pastaghost Aug 23, 2026
c477e72
ci(rc18): make the non-blocking job able to report red
pastaghost Aug 23, 2026
3305b80
fix(signing): cover ZIP-229 and ambiguous message acks
BitHighlander Aug 23, 2026
700c36d
ci(rc18): gate post-candidate firmware behavior
BitHighlander Aug 23, 2026
e7e39ba
ci(rc18): promote compatibility run to a release gate
BitHighlander Aug 23, 2026
9aaaa84
test(reset): run dice and re-entry coverage from firmware 7.14.3
BitHighlander Aug 26, 2026
85c4d20
test(bitcoin-only): exercise the 7.14.3 product
BitHighlander Aug 26, 2026
e353ce5
test(bitcoin-only): skip Maya-only memo coverage
BitHighlander Aug 26, 2026
cef50e5
test: cover signing session security boundaries
BitHighlander Aug 26, 2026
84d0213
test: cover authenticator authorization boundaries
BitHighlander Aug 26, 2026
7e39fd5
ci: checkout fork branches from current project
BitHighlander Aug 26, 2026
758f20c
ci: bind companion tests to firmware PR 604
BitHighlander Aug 26, 2026
e79c6b8
test(bitcoin-only): gate unsupported 7.15 handlers
BitHighlander Aug 26, 2026
c697a25
test(report): respect Bitcoin-only feature boundaries
BitHighlander Aug 26, 2026
b532d98
Merge pull request #220 from keepkey/fix/7.15-bitcoin-only-capability…
BitHighlander Aug 26, 2026
621c3dd
merge: carry 7.14.2 regressions into 7.14.3 companion
BitHighlander Aug 27, 2026
fc12c6d
test(fixtures): drop noncanonical unused taproot prevtx
BitHighlander Aug 27, 2026
ef41fc9
ci: install hermetic fixture network dependency
BitHighlander Aug 27, 2026
4e8f3b5
ci: exercise the 7.14.3 bitcoin-only product
BitHighlander Aug 27, 2026
9a4af72
ci: surface integration test hangs
BitHighlander Aug 27, 2026
5b03b26
merge: reconcile 7.15 tests after 7.14.3 gate
BitHighlander Aug 27, 2026
86831be
ci: permit emulator UDP through offline gate
BitHighlander Aug 27, 2026
29e47e9
Merge commit '86831be' into prepare/715-pyk-reconcile
BitHighlander Aug 27, 2026
7d32a39
ci: run reconciliation branches
BitHighlander Aug 27, 2026
2771e17
fix(report): restore exact screenshot selector CLI
BitHighlander Aug 27, 2026
c9cc7d3
merge: carry 7.14.3 report selector fix into 7.15
BitHighlander Aug 27, 2026
3ddc544
test(solana): build canonical stake authorize accounts
BitHighlander Aug 27, 2026
1067497
merge: carry canonical Solana stake authorize test into 7.15
BitHighlander Aug 27, 2026
0014cfb
test(report): align screenshot audit with fail-closed flows
BitHighlander Aug 27, 2026
32b7216
merge: carry screenshot audit fixes into 7.15
BitHighlander Aug 27, 2026
9d69038
fix(report): gate 7.15 storage tests by version
BitHighlander Aug 27, 2026
ba2f86f
merge: carry versioned report catalog into 7.15
BitHighlander Aug 27, 2026
34b45fa
feat(report): accept exact evidence provenance
BitHighlander Aug 27, 2026
eb26dcb
merge: carry report provenance inputs into 7.15
BitHighlander Aug 27, 2026
68173d8
fix(7.15): preserve session policy and valid auth fixtures
BitHighlander Aug 27, 2026
96c5805
test(7.15): align Solana wire case and OLED baselines
BitHighlander Aug 27, 2026
57642ad
ci(7.15): test against the matching firmware branch
BitHighlander Aug 27, 2026
c4fb8bf
test(7.15): assert fail-closed signing contracts
BitHighlander Aug 27, 2026
7598628
Merge audited release Python fixes into upstream sync
BitHighlander Aug 28, 2026
146f341
chore(deps): pin upstream device protocol release head
BitHighlander Aug 28, 2026
004e33a
test(7.14.3): preserve legacy Osmosis release control
BitHighlander Aug 28, 2026
9c39820
fix(report): require Solana LUT coverage from 7.16
BitHighlander Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 54 additions & 9 deletions .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,12 @@ jobs:
- run:
name: Clone python-keepkey (current branch)
command: |
git clone --depth 1 -b "$CIRCLE_BRANCH" https://github.com/keepkey/python-keepkey.git .pykk
# Fork-only PR branches do not exist in keepkey/python-keepkey.
# Clone the repository that triggered this CircleCI project so the
# exact CIRCLE_SHA1 under review is available and verifiable.
git clone --depth 1 -b "$CIRCLE_BRANCH" \
"https://github.com/${CIRCLE_PROJECT_USERNAME}/${CIRCLE_PROJECT_REPONAME}.git" .pykk
test "$(git -C .pykk rev-parse HEAD)" = "$CIRCLE_SHA1"
cd .pykk && git submodule update --init --recursive

# ────────────────────────────────────────────────────────────────
Expand All @@ -27,11 +32,24 @@ jobs:
# Move python-keepkey out of the way
mv .pykk ../

# Clone firmware repository (expects $FIRMWARE_REPO env var)
git clone --depth 1 -b master "$FIRMWARE_REPO" .
# Gate the immutable fork 7.15 candidate, then replace its pinned
# Python submodule with the exact CIRCLE_SHA1 under review.
git init .
git remote add origin \
https://github.com/BitHighlander/keepkey-firmware.git
git fetch --depth 1 origin \
d0a494a805533f02387f58d89dbb6f1fb09a621a
git checkout --detach FETCH_HEAD
test "$(git rev-parse HEAD)" = \
d0a494a805533f02387f58d89dbb6f1fb09a621a

# Initialise firmware submodules
git submodule update --init --recursive
# Match firmware CI's build set. A recursive init reaches optional
# trezor-firmware vendors that do not support shallow HTTPS clones.
git submodule update --init --depth 1 deps/crypto/trezor-firmware
git submodule update --init --depth 1 deps/device-protocol
git submodule update --init --depth 1 deps/googletest
git submodule update --init --depth 1 deps/qrenc/QR-Code-generator
git submodule update --init --depth 1 deps/sca-hardening/SecAESSTM32

# Replace the vendor copy with our PR branch python-keepkey
rm -rf deps/python-keepkey
Expand All @@ -56,18 +74,45 @@ jobs:
command: |
pushd ./scripts/emulator
set +e # don’t exit on first failure
docker-compose up --build firmware-unit
docker-compose up --build python-keepkey
set -e

# Collect JUnit / pytest XML results
mkdir -p ../../test-reports
docker cp "$(docker-compose ps -q firmware-unit)":/kkemu/test-reports/. ../../test-reports/
docker cp "$(docker-compose ps -q python-keepkey)":/kkemu/test-reports/. ../../test-reports/
popd

# Fail job if either container reported non-zero status
[ "$(cat test-reports/python-keepkey/status)$(cat test-reports/firmware-unit/status)" = "00" ] || exit 1
# Fail the job on this repo's OWN result.
#
# The firmware's C++ firmware-unit suite used to run here and gated
# this job. It was dropped because it failed python-keepkey for
# reasons no python change caused: a token-table change cannot go
# green here until the matching firmware change reaches the branch
# this clones, which is a release away. The firmware repo runs that
# suite in its own CI.
#
# This repo IS in the firmware's build graph, though, so dropping
# the suite is not free. keepkey-firmware's lib/firmware/CMakeLists.txt
# generates ethereum_tokens.def and uniswap_tokens.def by running
# deps/python-keepkey/keepkeylib/eth/{ethereum,uniswap}_tokens.py,
# and kkfirmware depends on that target -- so a change here can
# break the firmware C++ BUILD, and tokens[] is what
# unittests/firmware/coins.cpp reads.
#
# tests/test_token_table_generators.py is the replacement gate for
# exactly that coupling: it runs both generators and asserts the
# emitted table is well-formed, budget-conforming and
# deterministic. Do not remove it without restoring firmware-unit.
#
# Read the status file defensively -- it is written by the container,
# and a crash before it exists must FAIL rather than silently pass an
# empty-string comparison.
STATUS_FILE=test-reports/python-keepkey/status
if [ ! -f "$STATUS_FILE" ]; then
echo "no status file at $STATUS_FILE -- the suite did not finish"
exit 1
fi
[ "$(cat "$STATUS_FILE")" = "0" ] || exit 1

- store_test_results:
path: test-reports
Expand Down
Loading
Loading