Add legacy P2SH multisig support - #131
Conversation
|
this adds a lot of legacy p2sh/bip-45 and general multisig code that isn't needed for the security fix, which makes it much harder to review. i think the fix should stay focused on validating against the stored MultiSigDetails, with legacy support handled separately. |
148f862 to
1675c54
Compare
1675c54 to
aeec2af
Compare
|
this work is required for signing unchained and future casa multisig PSBTs, needs to ship alongside those exports in 1.4.0. Make sure to tag ngwallet after merging, and make a PR to KeyOS to bump the ngwallet version to that tag (or latest). |
|
Review found 1 urgent and 1 high issue in the legacy P2SH compatibility layer. |
9ee8c37 to
dacff2b
Compare
|
@mjg-foundation Follow-up is now split by the code that owns each invariant: #139 preserves and round-trips fixed |
fe9e7db to
edbd873
Compare
mjg-foundation
left a comment
There was a problem hiding this comment.
Re-reviewed the new commits — no new issues.
edbd873 to
2558051
Compare
What changed
Adds focused support for legacy
sh(sortedmulti(...))multisig accounts:crypto-outputnon_witness_utxoDependencies
This branch is temporarily stacked on:
Once those merge, this branch can be rebased onto
mainwithout changing its P2SH behavior.Scope
The general multisig PSBT hardening was moved to and merged through #134. This PR now contains only the remaining bare-P2SH compatibility layer on top of the shared path handling.