release: review 7.15 after finalized 7.14.3 - #629
Conversation
Audit index — 7.15 stacked deltaThis is the durable top-level ledger. Detailed checkboxes live in the commit-pinned line maps below. A checkbox means every listed base and candidate range in that file was reviewed; findings must cite the exact range and head. Immutable review identity
The 7.14.3 audit is inherited only for unchanged bytes. Any 7.15 hunk touching an inherited invariant is explicitly present in the line maps below. Canonical dependency identity
Every committed submodule URL is canonical upstream. The stale Line-addressable audit surfaces
The firmware maps cover all 181 changed files exactly once. Roadmaps and RFCs are audit inputs, not claims that their future mechanisms ship in 7.15. Gates
Head-change log
Copilot delivery status
No merge, tag, signing, publishing, release, upstream firmware PR, or physical-test claim is made by this fork audit vehicle. |
Squash the 7.15 delta onto the finalized 7.14.3 candidate: core UI and transport work, chain signing and clear-sign metadata, Zcash Orchard support, storage and RNG hardening, dependency updates, tests, documentation, and release evidence gates. Keep every dependency on its canonical upstream URL.
c636edf to
abe29d1
Compare
fb3e338 to
a56fb3e
Compare
7.15 line audit — core, build, EVM and SolanaExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 81. 715-BUILD — product composition, platform and memory layout
715-CORE — board, confirmation UI, transport and emulator
715-DEP — dependency identity, crypto and build integration
715-EVM — EVM and clear-sign metadata
715-SOL — Solana instruction and metadata disclosure
|
7.15 line audit — signing, Zcash and state securityExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 56. 715-CHAIN — other chain signing and disclosure
715-CHAIN — other chain signing and regression coverage
715-STATE — storage, RNG and secret/session lifecycle
715-ZEC — Zcash, Orchard, Pallas and RedPallas
|
7.15 line audit — CI, release evidence and documentationExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 44. 715-CI — CI, release evidence, manifests and static gates
715-DOC — shipping requirements, audit guidance and non-shipping designs
|
7.15 line audit — trezor-crypto dependency deltaExact range: Checkbox rule: mark a file complete only after reviewing every listed base and candidate range, including removed/replaced base lines. Findings must cite the surface, path, range, and exact head. Generated files and tests are reviewable evidence, not substitutes for reviewing runtime code. Changed files represented in this checklist: 5. DEP-CRYPTO-ZEC — Pallas, RedPallas and Orchard primitives
|
Review target
Fork-only stacked audit PR for the squashed 7.15 release candidate.
release/7.14.3-bitcoin-only@abe29d1288638867dc64dfe04219b89f7a593133release/7.15@a56fb3e88d7dbbe31a321179c10a8fd2023d8f0cfb3e3389is preserved atpreserve/release-7.15-pre-upstream-squash-20260828The audit ledger links checkable, commit-pinned file/line maps for all 181 firmware files plus the five-file canonical trezor-crypto delta. Every dependency URL is canonical upstream; the trezor gitlink is merged upstream PR #11 at
8a392f70.Current gates
No merge, signing, tagging, publishing, release, upstream firmware PR, or upstream firmware comment is authorized by this fork review.