Skip to content

api/firmware: support host passphrase entry - #188

Open
benma-agent wants to merge 2 commits into
BitBoxSwiss:masterfrom
benma-agent:benma-agent/host-passphrase
Open

benma-agent wants to merge 2 commits into
BitBoxSwiss:masterfrom
benma-agent:benma-agent/host-passphrase

Conversation

@benma-agent

@benma-agent benma-agent commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Support host entry of the optional BIP39 passphrase on firmware 9.28.0 and later. Device entry remains available while the host can request approval to enter the passphrase. Invoke host input only after device consent, and let the device confirm the submitted value before unlocking.

Keep polling and protocol handling in the library. Withdraw host-entry availability during consent and confirmation, notify clients when device entry finishes, and handle cancellation, retries and reconnects without reusing stale requests. Preserve the legacy unlock flow on older firmware.

Includes the session-reset prerequisite from #187.

Related PRs:

Disconnecting after an intermediate signing response leaves the firmware
waiting for a continuation while the device stays powered. On reconnect,
the old workflow consumes the first attestation request and returns an
encrypted error, causing the attestation check to fail.

Send HWW_REQ_RESET (0x03) after version discovery and before attestation,
unlock, and Noise pairing on firmware v9.28.0 or newer. Keep the helper
private, retry BUSY responses once per second, and require an ACK without
a payload. Older firmware keeps its existing connection flow.

Add a simulator regression that disconnects with signing unfinished,
reconnects to the same running process, checks the real attestation
response, pairs, and reads the root fingerprint. Older simulator versions
exercise ordinary reconnects. The regression uses the locally built
v9.28.0 C simulator and fails if the reset call is disabled.

Firmware counterpart: BitBoxSwiss/bitbox02-firmware#2111
Unlock through the paired Noise channel on firmware 9.28.0 and later,
keeping the legacy unlock command for older firmware. The new workflow
starts device entry when the optional passphrase feature is enabled and
lets the host request device consent to enter the passphrase on the host.
Uninitialized and already unlocked devices finish immediately.

Expose two callbacks through PassphraseConfig. The availability callback
receives a callable that queues a host-entry request and wakes the polling
loop without doing transport I/O. Notify once per entry phase, withdraw
when consent starts or device entry finishes, and offer a fresh callable
on retry. Separate buffered channels keep delayed or duplicate clicks
from affecting later phases. Without an availability callback, request
host entry once automatically and fall back to device entry on rejection
or cancellation.

Call the blocking input callback only after device approval. A string,
including the empty string, submits input; nil cancels and resumes device
entry. The device confirms the actual passphrase. Keep protocol handling
and device-entry polling inside the library, holding the API lock for the
entire unlock so other queries cannot interrupt its continuations.

Notify clients when device passphrase entry finishes, before confirmation starts. This lets the
app show the confirmation prompt even when device entry wins a simultaneous host-entry request.

Use the device lifetime context to release host input on Close, and make
Close idempotent because disconnect handling and unlock cancellation can
both close the transport. Ignore repeated pairing approvals to avoid
starting duplicate unlocks. Clear temporary protobuf plaintext buffers
after each query. On local failure, withdraw availability, attempt RESET
and close the connection; reconnect uses the preceding session-reset
commit. Keep resetSession's explicit firmware version check independent
of host-passphrase support.

Add simulator coverage for initialization, device passphrase entry, disabled passphrases,
simultaneous host requests, stale clicks, repeated unlocks and repeated closes.
@benma-agent
benma-agent force-pushed the benma-agent/host-passphrase branch from 00d8217 to 3a80376 Compare September 20, 2026 09:00
@benma
benma requested a review from Beerosagos September 25, 2026 15:48
@benma
benma marked this pull request as ready for review September 25, 2026 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant