Skip to content

BitWindow orchestrator: 3 fixes from a security review - #2139

Open
giaki3003 wants to merge 3 commits into
LayerTwo-Labs:masterfrom
giaki3003:fix/w5-area-orch-r2
Open

giaki3003 wants to merge 3 commits into
LayerTwo-Labs:masterfrom
giaki3003:fix/w5-area-orch-r2

Conversation

@giaki3003

Copy link
Copy Markdown
Contributor

A set of 3 independent fixes to the BitWindow orchestrator, stacked on one branch so they can be reviewed together and cherry-picked individually. Based on current master; the branch builds and its tests pass at the tip (9 files changed, 177 insertions(+), 24 deletions(-)).

Fixes (oldest first)

  • 156a894ea CoinShift typed Create Swap cannot create or broadcast a swap
  • cd777556d BIP47 reserved-byte aliases split state and reuse payment addresses
  • c75971e7d testnet startup panics while migrating a matching legacy enforcer wallet

Each commit is self-contained — git cherry-pick <sha> works for any of them. Happy to split, reorder, or drop any. Finding reports for individual fixes available on request.

giaki3003 and others added 3 commits August 30, 2026 22:44
Bug: w5-20260801-0433-kimiclaw-confirm-openclaw- (primary)
Finding: findings/20260801-0433-kimiclaw-confirm-openclaw-drivechain-frontends-coinshift-create-swap-wire-contract.md
Severity: R3-T4

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit d7aa814)
Bug: w5-20260810-0946-kimiclaw-confirm-openclaw- (primary)
Finding: findings/20260810-0946-kimiclaw-confirm-openclaw-drivechain-frontends-bip47-reserved-byte-state-split.md
Severity: R3-T4

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit 2d8c6df)
…r wallet

Bug: w5-20260829-0149-openclaw-confirm-glmclaw-d (primary)
Finding: findings/20260829-0149-openclaw-confirm-glmclaw-drivechain-frontends-testnet-enforcer-migration-panic.md
Severity: R3-T4

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit 87107b8)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant