release(7.15.0): RC19 audited firmware candidate - #452
Conversation
Add registry-backed clear signing, EIP-712 and EIP-7702 handling, ERC-20 policy checks, and regression coverage. Review lineage: keepkey#444.
Add the protocol flows, confirmations, serialization, and tests required for the 7.15 chain expansion. Review lineage: keepkey#445.
Add deterministic entropy export, BIP-39 recovery validation, fault-injection resistance, and focused tests. Review lineage: keepkey#446.
Add policy and display handling for TRON, Solana v0, TON, MayaChain, THORChain, and Tendermint-family requests. Review lineage: keepkey#447.
Introduce the 7.15 build matrix, seed-lock behavior, and version wiring. Review lineage: keepkey#448.
Integrate the full 7.15 feature set across firmware, emulator, protocol pins, storage migrations, and test infrastructure. Review lineage: #311.
Bind THORChain router policy per chain and apply the corresponding protocol, parsing, and test corrections. Review lineage: #313.
Report paced device progress during long Orchard signing operations and cover the display behavior. Review lineage: #314.
Apply the RC security review across display binding, parsers, persistent signer identities, signing policy, RNG handling, and regression tests. Review lineage: #317.
Make release-candidate tags first-class, keep artifacts draft-only, and fetch only the submodules required by each build. Review lineage: #318.
Finalize constant-time RedPallas signing, ARM and host leakage gates, emulator CSPRNG handling, immutable build inputs, signing progress, canonical crypto pinning, and the RC19 validation matrix. This tree is identical to v7.15.0-rc19.
40fa3b1 to
27e036d
Compare
|
Closing this consolidated candidate. A 168-file, +21,569/−1,888 single PR is not reviewable in practice — it sat 10 days with green CI and no review, and its 12 internal units were lineage bundles (largest 6,436 lines) rather than feature slices. The 7.15 content is being restaged from scratch as a stack of feature-sized review branches against BitHighlander/keepkey-firmware develop, which is now reset to this repository's develop tip (1af2ffe) so each branch is directly upstreamable. Every branch will carry its own CI run and Gate-3 evidence; a new RC will be cut from the restacked develop, and replacement upstream PRs will be opened per feature area. Nothing is lost: the exact content of this candidate is preserved at tag preserve/alpha-2026-08-05 (f1f99a5) plus release/7.15.0-rc19-upstream. #449 stays independent. |
Summary
This is the consolidated KeepKey firmware 7.15.0 candidate represented by the signed annotated tag v7.15.0-rc19.
Review shape
This single PR supersedes the closed #444–#448 stack and incorporates the later fork review, including BitHighlander#319 and #320. The history has been rebuilt as 12 ordered review units; snapshot commits and the temporary add/remove vendoring churn are gone.
The final source tree is identical to the RC19 reference tree f06cd8e87c71d96ad0c50f990e8cb5c7669f0772. The diff is 168 files, +21,569/−1,888; 7,273 added lines are test code. trezor-crypto is not vendored into this repository—it is pinned to the reviewed merge from keepkey/trezor-firmware#4 (62230ee620fa9ea2bdd2c8067be7fde3f9362248).
Validation
Merge gates