All checks were successful
check / check (push) Successful in 23s
Every element of the derivation path is hardened, so an index above 2147483647 has no child to derive: the hardened offset wrapped around and the tool silently produced a non-hardened key that no other implementation reading the path as written would reproduce. Such an index is now refused with a message before anything is derived, and tests pin the refusal at both the derivation and the command level. Also use the hook path variable in script/install-precommit instead of repeating the literal beside it. Model: opus-5
72 lines
2.0 KiB
Go
72 lines
2.0 KiB
Go
// Package derive turns a mnemonic into the bytes a key is made from.
|
|
package derive
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
|
|
"git.eeqj.de/sneak/secret/pkg/bip85"
|
|
"github.com/btcsuite/btcd/btcutil/hdkeychain"
|
|
"github.com/btcsuite/btcd/chaincfg"
|
|
bip39 "github.com/tyler-smith/go-bip39"
|
|
)
|
|
|
|
const (
|
|
// purpose is the number BIP-85 reserves for itself.
|
|
purpose = 83696968
|
|
|
|
// Size is how many bytes every key type is given.
|
|
Size = 32
|
|
|
|
// MaxIndex is the largest key index there is. Every element of
|
|
// the path is hardened, and a hardened BIP-32 child index stops
|
|
// here.
|
|
MaxIndex = 1<<31 - 1
|
|
)
|
|
|
|
// ErrIndexTooLarge is returned for a key index above MaxIndex. Such an
|
|
// index has no hardened child to derive, so there is no key to give
|
|
// back rather than a key nobody else would reproduce.
|
|
var ErrIndexTooLarge = errors.New("the key index is too large")
|
|
|
|
// Path returns the derivation path for an application number and a key
|
|
// index.
|
|
func Path(application, index uint32) string {
|
|
return fmt.Sprintf("m/%d'/%d'/%d'", purpose, application, index)
|
|
}
|
|
|
|
// Bytes returns the bytes for an application number and a key index.
|
|
// The mnemonic becomes a seed with an empty passphrase, the seed
|
|
// becomes a master key, the master key gives BIP-85 entropy at the
|
|
// path, and the entropy seeds the generator the bytes are read from.
|
|
// An index above MaxIndex is refused before any of that happens.
|
|
func Bytes(words string, application, index uint32) ([]byte, error) {
|
|
if index > MaxIndex {
|
|
return nil, fmt.Errorf(
|
|
"%w: %d is above %d",
|
|
ErrIndexTooLarge, index, MaxIndex,
|
|
)
|
|
}
|
|
|
|
seed := bip39.NewSeed(words, "")
|
|
|
|
master, err := hdkeychain.NewMaster(seed, &chaincfg.MainNetParams)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("making the master key: %w", err)
|
|
}
|
|
|
|
entropy, err := bip85.DeriveBIP85Entropy(master, Path(application, index))
|
|
if err != nil {
|
|
return nil, fmt.Errorf("deriving entropy: %w", err)
|
|
}
|
|
|
|
out := make([]byte, Size)
|
|
|
|
_, err = bip85.NewBIP85DRNG(entropy).Read(out)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("reading derived bytes: %w", err)
|
|
}
|
|
|
|
return out, nil
|
|
}
|