Skip to content

Upgrade btcd and migrate to btcec/v2 - #21

Merged
piotr-roslaniec merged 2 commits into
devfrom
codex/deps-btcd
Sep 29, 2026
Merged

piotr-roslaniec merged 2 commits into
devfrom
codex/deps-btcd

Conversation

@mswilkison

@mswilkison mswilkison commented Sep 14, 2026 •

Copy link
Copy Markdown

The current btcd version is covered by three published Dependabot advisories. Upgrade it to v0.24.2 and migrate the removed legacy btcec and btcutil imports to btcd/btcec/v2 v2.2.0 and btcd/btcutil v1.1.5. This covers GHSA-2chg-86hq-7w38, GHSA-3jgf-r68h-xfqm, and GHSA-27vh-h6mc-q6g8.

Stacked on #20; merge #19, then #20, then this PR. The combined stack selects versions at or above the fixed versions for all 30 current Dependabot alerts. Dependency selection was checked against each alert's published affected range; this is not a claim that all affected dependency paths are reachable in tss-lib.

The migration preserves compressed public-key parsing, the caller-supplied curve instance in derived keys, the registered secp256k1 name, and coordinate-based JSON/Gob persistence. Compatibility tests use fixed legacy encodings, synthetic save data with no signing secrets, ordinary point arithmetic, BIP32 vectors, hierarchy deltas, and curve registry controls. No legacy btcec or btcutil packages remain in the compiled library/test dependency closure.

Downstream integration review remains required before adoption. Exported elliptic.Curve signatures remain the same, but the concrete curve implementation changes from legacy btcec to Decred secp256k1/v4 through btcec/v2. Callers using legacy imports or concrete type assertions need adaptation. The selected btcd/btcec/btcutil versions match the public keep-core dependency set referenced by keep-core #4312; that PR also supplies the Go baseline used by #20. This does not establish keep-core integration compatibility, and Go module version selection in consumers can choose a higher btcec/v2 version.

Validation on the final stacked commit with Go 1.26.8:

  • Full tss, crypto, crypto/ckd, crypto/schnorr, crypto/vss, and ecdsa/signing package suites passed, including ordinary and HD signing end to end (signing: 67.601s).
  • Legacy save-data compatibility and bounded existing keygen controls passed (9.959s). Full repository CI, including keygen, subsequently passed at the current head.
  • Legacy compatibility goldens passed on both the original dependency and the migrated implementation.
  • go build -mod=readonly -p 1 ./..., go vet -mod=readonly -p 1 ./..., go mod verify, module tidiness, and whitespace checks passed.
  • An independent review passed focused serialization, derivation, registry, and signing controls on the migration candidate; migration source/tests/fixtures are unchanged by stacking.

The exact minimum Go toolchain was not exercised locally. Full repository test CI and formatting CI passed at the current head 66aaeca3344b1977d2d2c20f6fd98c521bc58bbe. These workflows were dispatched explicitly because this stacked PR targets a branch other than master.

@mswilkison
mswilkison marked this pull request as ready for review September 18, 2026 14:38
Keep btcd v0.24.2, btcec/v2 v2.2.0 and btcutil v1.1.5 from this PR and add
filippo.io/bigmod v0.1.0 from dev. go mod tidy under go1.26.8 (also
records the go.sum hashes that were missing on the previous head).
@piotr-roslaniec
piotr-roslaniec changed the base branch from codex/deps-go-crypto to dev September 29, 2026 11:31
@piotr-roslaniec
piotr-roslaniec merged commit 5b46ba9 into dev Sep 29, 2026
2 checks passed
@piotr-roslaniec

Copy link
Copy Markdown

Merged into dev.

Before merging, the merged #20 head was merged into this branch (1062fd6). Conflict was go.mod only: kept btcd v0.24.2, btcec/v2 v2.2.0, and btcutil v1.1.5, and added bigmod. After go mod tidy under go1.26.8, go.sum is tidy-clean. The previous head was missing 6 /go.mod hash lines. CI is green on the merged head.

Checks run:

  • Differential test, legacy btcec vs btcec/v2: 245 point vectors and 7 round-trips. One expected difference: legacy IsOnCurve panicked when y >= P, and v2 returns false. That is a hardening, and tss-lib's call paths already guard it.
  • All 20 keygen fixtures, pinned legacy JSON/Gob save data, and BIP32 xpub/delta vectors are byte-identical under btcec/v2. Same result with decred secp256k1/v4 at v4.0.1 and at v4.3.0, the version keep-core's module resolution picks.
  • 11-party TestE2EConcurrent passes, with signatures checked by stdlib ecdsa.Verify. TestE2EWithHDKeyDerivation passes.
  • keep-core main with replace pointing at this branch: go build ./... succeeds, and no concrete-type assertions on tss-lib output break.

Follow-ups, not blocking: CI does not test at keep-core's secp256k1 v4.3.0 resolution. gogo/protobuf v1.2.1 (GO-2021-0053, import-only) was already there before this PR and needs its own dependency bump.

Full report: agent-docs/pr-integration/21.md (local).

piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Merge origin/dev (contains #18/#20/#21) into the input-guards branch.
Auto-merged cleanly (no textual conflicts); key choices:
- go.mod/go.sum: adopt origin/dev toolchain and dependencies
  (go 1.25.7, toolchain go1.26.8, x/crypto v0.52.0, x/sys v0.45.0,
  protobuf v1.33.0, btcd v0.24.2, btcec/v2 v2.2.0, btcutil v1.1.5,
  bigmod v0.1.0) per the integration contract.
- crypto/mta/proofs.go: keep #12 decoder guards (ProofBobWC 12-part
  arity, Bytes nil-receiver panics) plus dev's CT/sampling changes;
  changes were in disjoint regions and both survived.
piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Merge current origin/dev (includes #18/#20/#21) into the PR #14 branch.

Conflict choices:
- No textual conflicts; clean automatic merge.
- Go toolchain/deps kept from origin/dev (go 1.25.7, toolchain go1.26.8,
  x/crypto v0.52.0, x/sys v0.45.0, protobuf v1.33.0, btcd v0.24.2,
  btcec/v2 v2.2.0, btcutil v1.1.5, bigmod v0.1.0).
- Preserved PR #14 changes on top of dev: BaseParty fatal-error latch
  (abort/abortedWith) and keygen unmarshalVSSCommitment part-count guard
  in ecdsa/keygen/round_3.go.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants