Derive from the mnemonic's words joined by single spaces (closes #49) #53

Merged
clawbot merged 1 commits from issue-49-mnemonic-single-spaces into next 2026-10-04 07:08:47 +02:00
Collaborator

Implements #49 (finding 2 of #28 (comment)).

The BIP-39 seed is computed over the mnemonic string as given, and only its ends were trimmed. The same twelve words one per line, tab-separated or double-spaced passed the checksum but gave different keys, with no warning. checked in internal/mnemonic/mnemonic.go now joins the words with single spaces before the checksum and the seed. That covers every source: the mnemonic command, both environment variables and the prompt.

A new test in internal/cli/cli_test.go sets the README mnemonic one word per line, double-spaced and tab-separated, and checks that ssh pub prints the README index-0 vector for each. Without the fix, all three fail. No README vector changes.

The README section on giving the mnemonic now says this in one sentence.

  • Judgement call: I removed the README sentence "Whitespace around the output is dropped" from the --mnemonic-command item, because the new sentence covers it for every source.
  • Judgement call: the test checks the SSH vector only. The age vectors come from the same seed.
  • Anything derived from unevenly spaced input before this change now gives different keys. Nothing keeps the old behaviour (pre-1.0).
  • #48 may change ask in the same file. This change touches only checked.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/keyfunc/issues/49 (finding 2 of https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217). The BIP-39 seed is computed over the mnemonic string as given, and only its ends were trimmed. The same twelve words one per line, tab-separated or double-spaced passed the checksum but gave different keys, with no warning. `checked` in `internal/mnemonic/mnemonic.go` now joins the words with single spaces before the checksum and the seed. That covers every source: the mnemonic command, both environment variables and the prompt. A new test in `internal/cli/cli_test.go` sets the README mnemonic one word per line, double-spaced and tab-separated, and checks that `ssh pub` prints the README index-0 vector for each. Without the fix, all three fail. No README vector changes. The README section on giving the mnemonic now says this in one sentence. - Judgement call: I removed the README sentence "Whitespace around the output is dropped" from the `--mnemonic-command` item, because the new sentence covers it for every source. - Judgement call: the test checks the SSH vector only. The age vectors come from the same seed. - Anything derived from unevenly spaced input before this change now gives different keys. Nothing keeps the old behaviour (pre-1.0). - https://git.eeqj.de/sneak/keyfunc/issues/48 may change `ask` in the same file. This change touches only `checked`. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 06:34:08 +02:00
clawbot self-assigned this 2026-10-04 06:34:08 +02:00
clawbot added 1 commit 2026-10-04 06:34:08 +02:00
The seed is computed over the mnemonic string itself, and only its ends
were trimmed, so the same words one per line, tab-separated or
double-spaced passed the checksum but gave different keys. The words
are now joined with single spaces before the checksum and the seed. A
test shows each of those three spacings gives the README SSH vector,
and the README section on giving the mnemonic says so.

Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 897b43a206 into next 2026-10-04 07:08:47 +02:00
clawbot deleted branch issue-49-mnemonic-single-spaces 2026-10-04 07:08:47 +02:00
Sign in to join this conversation.