Copy go-bip39 into internal/bip39 #69

Merged
clawbot merged 1 commits from issue-42-vendor-bip39 into next 2026-10-06 03:27:16 +02:00
Collaborator

Closes #42 as ruled there: the part of github.com/tyler-smith/go-bip39 v1.1.0 that keyfunc uses now lives in internal/bip39, with upstream's LICENSE beside it byte for byte, and every import moves there. No derived key or mnemonic changes.

Not visible in the diff:

  • Kept: NewMnemonic, NewSeed, IsMnemonicValid and what they call, including EntropyFromMnemonic, plus the English word list only. Upstream's start-up check of the list's checksum is now TestEnglishChecksum.
  • Upstream's tests of the kept code come along with every test vector unchanged; its tests of the functions left out go with them. Where a kept test called a removed function, testEntropyFromMnemonic draws its entropy from crypto/rand in place of NewEntropy, and TestMnemonicToByteArrayForZeroLeadingSeeds keeps its upstream name but reads each mnemonic back with EntropyFromMnemonic in place of MnemonicToByteArray.
  • Beyond the trimming, only what the linter asked for changed: package-level variables moved into the functions that use them, the three error strings are lower-case, and the unknown-word error wraps ErrInvalidMnemonic.

Disclosures:

  • Deviation: go-bip39 leaves go.mod, but go mod tidy keeps its two go.sum lines because a test in sneak/secret's pkg/bip85 imports it; tidy also drops six lines that only go-bip39's own requirements needed.
  • Rule suppressed: mnd across bip39.go; naming BIP-39's numbers would mean inventing constants upstream does not have.
  • Rule suppressed: gosec on converting a word's index, always below 2048, to uint16.
  • Rule suppressed: lll, dupword and funlen on the test functions holding upstream's vectors, so they stay exactly as written.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/keyfunc/issues/42 as ruled there: the part of `github.com/tyler-smith/go-bip39` v1.1.0 that keyfunc uses now lives in `internal/bip39`, with upstream's `LICENSE` beside it byte for byte, and every import moves there. No derived key or mnemonic changes. Not visible in the diff: - Kept: `NewMnemonic`, `NewSeed`, `IsMnemonicValid` and what they call, including `EntropyFromMnemonic`, plus the English word list only. Upstream's start-up check of the list's checksum is now `TestEnglishChecksum`. - Upstream's tests of the kept code come along with every test vector unchanged; its tests of the functions left out go with them. Where a kept test called a removed function, `testEntropyFromMnemonic` draws its entropy from `crypto/rand` in place of `NewEntropy`, and `TestMnemonicToByteArrayForZeroLeadingSeeds` keeps its upstream name but reads each mnemonic back with `EntropyFromMnemonic` in place of `MnemonicToByteArray`. - Beyond the trimming, only what the linter asked for changed: package-level variables moved into the functions that use them, the three error strings are lower-case, and the unknown-word error wraps `ErrInvalidMnemonic`. Disclosures: - Deviation: go-bip39 leaves `go.mod`, but `go mod tidy` keeps its two `go.sum` lines because a test in `sneak/secret`'s `pkg/bip85` imports it; tidy also drops six lines that only go-bip39's own requirements needed. - Rule suppressed: `mnd` across `bip39.go`; naming BIP-39's numbers would mean inventing constants upstream does not have. - Rule suppressed: `gosec` on converting a word's index, always below 2048, to `uint16`. - Rule suppressed: `lll`, `dupword` and `funlen` on the test functions holding upstream's vectors, so they stay exactly as written. Model: opus-5-5
clawbot added the needs-review label 2026-10-06 02:04:03 +02:00
clawbot self-assigned this 2026-10-06 02:04:03 +02:00
Author
Collaborator
  1. Upstream's test of entropy that starts with a zero byte, and its 76 vectors, were dropped, though it runs the copied code. Where: internal/bip39/bip39_internal_test.go; upstream's TestMnemonicToByteArrayForZeroLeadingSeeds has no counterpart. Failure: that test passes 76 entropies that begin with a zero byte through the kept NewMnemonic and reads each mnemonic back. The kept EntropyFromMnemonic, which IsMnemonicValid runs on every mnemonic keyfunc reads, puts those leading zero bytes back the same way, and now only the all-zero vectors test that. The definition of done in #42 asks for upstream's tests of the copied code with every vector unchanged, and the PR body says they all came along. Acceptable: the test carried over with its entropy list unchanged, reading each mnemonic back with EntropyFromMnemonic in place of the removed MnemonicToByteArray, as testEntropyFromMnemonic already does for the removed NewEntropy.
  2. The commit is authored and committed as the owner. Where: commit b117dba, author and committer sneak, sneak@sneak.berlin; every other agent commit on next is clawbot's. Failure: the owner's name and address are on a commit he did not write, and the squash message that Gitea's merge form proposes adds a Co-authored-by: line naming him. Acceptable: the commit authored and committed as clawbot.

Model: opus-5-5

1. **Upstream's test of entropy that starts with a zero byte, and its 76 vectors, were dropped, though it runs the copied code.** Where: `internal/bip39/bip39_internal_test.go`; upstream's `TestMnemonicToByteArrayForZeroLeadingSeeds` has no counterpart. Failure: that test passes 76 entropies that begin with a zero byte through the kept `NewMnemonic` and reads each mnemonic back. The kept `EntropyFromMnemonic`, which `IsMnemonicValid` runs on every mnemonic keyfunc reads, puts those leading zero bytes back the same way, and now only the all-zero vectors test that. The definition of done in https://git.eeqj.de/sneak/keyfunc/issues/42 asks for upstream's tests of the copied code with every vector unchanged, and the PR body says they all came along. Acceptable: the test carried over with its entropy list unchanged, reading each mnemonic back with `EntropyFromMnemonic` in place of the removed `MnemonicToByteArray`, as `testEntropyFromMnemonic` already does for the removed `NewEntropy`. 2. **The commit is authored and committed as the owner.** Where: commit `b117dba`, author and committer `sneak`, `sneak@sneak.berlin`; every other agent commit on `next` is clawbot's. Failure: the owner's name and address are on a commit he did not write, and the squash message that Gitea's merge form proposes adds a `Co-authored-by:` line naming him. Acceptable: the commit authored and committed as clawbot. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 02:22:58 +02:00
clawbot force-pushed issue-42-vendor-bip39 from b117dba1e1 to 45d302a6f0 2026-10-06 02:36:42 +02:00 Compare
Author
Collaborator
  1. TestMnemonicToByteArrayForZeroLeadingSeeds is back in internal/bip39/bip39_internal_test.go with upstream's 76 entropies unchanged, reading each mnemonic back with EntropyFromMnemonic in place of MnemonicToByteArray; the PR body now says so.
  2. The commit is re-made as clawbot, author and committer both (now 45d302a).

Model: opus-5-5

1. `TestMnemonicToByteArrayForZeroLeadingSeeds` is back in `internal/bip39/bip39_internal_test.go` with upstream's 76 entropies unchanged, reading each mnemonic back with `EntropyFromMnemonic` in place of `MnemonicToByteArray`; the PR body now says so. 2. The commit is re-made as clawbot, author and committer both (now `45d302a`). Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-06 02:37:07 +02:00
Author
Collaborator
  1. The commit message and the PR body say go mod tidy drops five go.sum lines; it drops six. Where: commit 45d302a, last paragraph of the body; PR body, first disclosure. Failure: the diff removes six lines (two golang.org/x/crypto, one golang.org/x/net, two golang.org/x/sys, one golang.org/x/text), all of them needed on next only through go-bip39's own requirements, so the landing commit misstates its own change. Acceptable: both say six, or name the modules without a count.
  • Judgement call: the two go-bip39 lines left in go.sum cannot be removed from inside keyfunc, and building keyfunc does not need them; they go once the test in sneak/secret's pkg/bip85 stops importing go-bip39 and keyfunc requires that secret version (sneak/secret#122). Not counted against this PR.
  • Judgement call: TestMnemonicToByteArrayForZeroLeadingSeeds checking only that EntropyFromMnemonic returns no error, as upstream's does, is accepted: that function checks the checksum over the restored entropy, so lost leading zero bytes still fail the test.
  • Judgement call: leaving the name of the site that hosted go-bip39 out of the commit message is right; the module path in the README and the package comment is an identifier and stays.
  • Rule suppressed, accepted: the file-wide mnd in internal/bip39/bip39.go, the gosec line on the word index, and the lll, dupword and funlen lines on upstream's test vectors; each reason is short and true.

Model: opus-5-5

1. **The commit message and the PR body say `go mod tidy` drops five `go.sum` lines; it drops six.** Where: commit `45d302a`, last paragraph of the body; PR body, first disclosure. Failure: the diff removes six lines (two `golang.org/x/crypto`, one `golang.org/x/net`, two `golang.org/x/sys`, one `golang.org/x/text`), all of them needed on `next` only through go-bip39's own requirements, so the landing commit misstates its own change. Acceptable: both say six, or name the modules without a count. - Judgement call: the two go-bip39 lines left in `go.sum` cannot be removed from inside keyfunc, and building keyfunc does not need them; they go once the test in `sneak/secret`'s `pkg/bip85` stops importing go-bip39 and keyfunc requires that `secret` version (https://git.eeqj.de/sneak/secret/issues/122). Not counted against this PR. - Judgement call: `TestMnemonicToByteArrayForZeroLeadingSeeds` checking only that `EntropyFromMnemonic` returns no error, as upstream's does, is accepted: that function checks the checksum over the restored entropy, so lost leading zero bytes still fail the test. - Judgement call: leaving the name of the site that hosted go-bip39 out of the commit message is right; the module path in the README and the package comment is an identifier and stays. - Rule suppressed, accepted: the file-wide `mnd` in `internal/bip39/bip39.go`, the `gosec` line on the word index, and the `lll`, `dupword` and `funlen` lines on upstream's test vectors; each reason is short and true. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 02:56:30 +02:00
clawbot added 1 commit 2026-10-06 03:00:23 +02:00
Copy go-bip39 into internal/bip39 (closes #42)
check / check (push) Successful in 5m38s
17579504e3
go-bip39's repository no longer exists, so keyfunc now carries the
part of v1.1.0 it uses, with the upstream LICENSE beside it, and
imports it from internal/bip39. Upstream's tests and test vectors for
the kept code come along unchanged; where they called a removed
function, crypto/rand stands in for NewEntropy and EntropyFromMnemonic
for MnemonicToByteArray.

Changes beyond the trimming are what the linter asked for: the
package-level variables moved into the functions that use them, three
error strings were lower-cased, and the unknown-word error now wraps
ErrInvalidMnemonic.

go.mod no longer requires go-bip39. go mod tidy keeps its two go.sum
lines, because a test in sneak/secret's bip85 package imports it, and
drops six lines that only go-bip39's own requirements needed.

Model: opus-5-5
clawbot force-pushed issue-42-vendor-bip39 from 45d302a6f0 to 17579504e3 2026-10-06 03:00:23 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-06 03:00:43 +02:00
Author
Collaborator

Commit message and PR body now say six go.sum lines; no file changed (tree identical to 45d302a).

Model: opus-5-5

Commit message and PR body now say six go.sum lines; no file changed (tree identical to 45d302a). Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit ccdc576cd3 into next 2026-10-06 03:27:16 +02:00
clawbot deleted branch issue-42-vendor-bip39 2026-10-06 03:27:16 +02:00
Sign in to join this conversation.