Copy go-bip39 into internal/bip39 (closes #122) #130

Merged
clawbot merged 1 commits from issue-122-vendor-bip39 into next 2026-10-07 12:56:11 +02:00
Collaborator

Closes #122 as ruled there: the part of github.com/tyler-smith/go-bip39 v1.1.0 that secret uses now lives in internal/bip39, with upstream's LICENSE beside it byte for byte, and every import moves there. Done the way keyfunc did it (sneak/keyfunc#69); the copy matches keyfunc's apart from NewEntropy, which only secret uses. No derived key or mnemonic changes.

Not visible in the diff:

  • Kept: NewEntropy, NewMnemonic, NewSeed, IsMnemonicValid and what they call, including EntropyFromMnemonic, plus the English word list only. Upstream's start-up check of the list's checksum is now TestEnglishChecksum.
  • Upstream's tests of the kept code come along with every test vector unchanged; its tests of the functions left out go with them. TestMnemonicToByteArrayForZeroLeadingSeeds keeps its upstream name but reads each mnemonic back with EntropyFromMnemonic in place of the removed MnemonicToByteArray, as in keyfunc.
  • Beyond the trimming, only what the linter asked for changed: package-level variables moved into the functions that use them, the three error strings are lower-case, and the unknown-word error wraps ErrInvalidMnemonic; the rest is blank lines, any, range loops, t.Parallel() and t.Helper().

Disclosures:

  • Rule suppressed: mnd across bip39.go; naming BIP-39's numbers would mean inventing constants upstream does not have.
  • Rule suppressed: gosec on converting a word's index, always below 2048, to uint16.
  • Rule suppressed: lll, dupword and funlen on the test functions holding upstream's vectors, so they stay exactly as written.
  • Judgement call: pkg/bip85/README.md still names go-bip39 in its usage example, because code outside secret cannot import internal/bip39.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/secret/issues/122 as ruled there: the part of `github.com/tyler-smith/go-bip39` v1.1.0 that `secret` uses now lives in `internal/bip39`, with upstream's `LICENSE` beside it byte for byte, and every import moves there. Done the way keyfunc did it (https://git.eeqj.de/sneak/keyfunc/pulls/69); the copy matches keyfunc's apart from `NewEntropy`, which only `secret` uses. No derived key or mnemonic changes. Not visible in the diff: - Kept: `NewEntropy`, `NewMnemonic`, `NewSeed`, `IsMnemonicValid` and what they call, including `EntropyFromMnemonic`, plus the English word list only. Upstream's start-up check of the list's checksum is now `TestEnglishChecksum`. - Upstream's tests of the kept code come along with every test vector unchanged; its tests of the functions left out go with them. `TestMnemonicToByteArrayForZeroLeadingSeeds` keeps its upstream name but reads each mnemonic back with `EntropyFromMnemonic` in place of the removed `MnemonicToByteArray`, as in keyfunc. - Beyond the trimming, only what the linter asked for changed: package-level variables moved into the functions that use them, the three error strings are lower-case, and the unknown-word error wraps `ErrInvalidMnemonic`; the rest is blank lines, `any`, `range` loops, `t.Parallel()` and `t.Helper()`. Disclosures: - Rule suppressed: `mnd` across `bip39.go`; naming BIP-39's numbers would mean inventing constants upstream does not have. - Rule suppressed: `gosec` on converting a word's index, always below 2048, to `uint16`. - Rule suppressed: `lll`, `dupword` and `funlen` on the test functions holding upstream's vectors, so they stay exactly as written. - Judgement call: `pkg/bip85/README.md` still names go-bip39 in its usage example, because code outside `secret` cannot import `internal/bip39`. Model: opus-5-5
clawbot added the needs-review label 2026-10-07 12:04:50 +02:00
clawbot self-assigned this 2026-10-07 12:04:50 +02:00
clawbot added 1 commit 2026-10-07 12:04:50 +02:00
go-bip39's repository no longer exists. The part of v1.1.0 that secret
uses (NewEntropy, NewMnemonic, NewSeed, IsMnemonicValid and what they
call; English word list only) now lives in internal/bip39 with
upstream's LICENSE beside it, along with upstream's tests of that code
and their vectors unchanged. Every import moves there, and the module
leaves go.mod and go.sum. Beyond the trimming, only what the linter
asked for changed. No derived key or mnemonic changes.

Model: opus-5-5
Author
Collaborator

PASS: internal/bip39 is a faithful trimmed copy of go-bip39 v1.1.0 with its licence and word list unchanged, every import has moved to it, and the disclosed lint suppressions and the pkg/bip85/README.md judgement call are sound.

Model: opus-5-5

PASS: `internal/bip39` is a faithful trimmed copy of go-bip39 v1.1.0 with its licence and word list unchanged, every import has moved to it, and the disclosed lint suppressions and the `pkg/bip85/README.md` judgement call are sound. Model: opus-5-5
clawbot merged commit ef0ae90768 into next 2026-10-07 12:56:11 +02:00
clawbot deleted branch issue-122-vendor-bip39 2026-10-07 12:56:11 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#130