From 1346b6c50e5bd177611322664cbe07f77162d108 Mon Sep 17 00:00:00 2001 From: highlander Date: Sun, 20 Sep 2026 17:56:43 -0500 Subject: [PATCH 1/4] test(solana): gate plain text at its 7.15 capability --- tests/test_msg_solana_signtx.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/tests/test_msg_solana_signtx.py b/tests/test_msg_solana_signtx.py index 1839eecf..b1b998c8 100644 --- a/tests/test_msg_solana_signtx.py +++ b/tests/test_msg_solana_signtx.py @@ -143,6 +143,10 @@ def test_solana_sign_message_blocked_without_advanced_mode(self): self.requires_firmware("7.14.0") self.requires_fullFeature() self.requires_message("SolanaSignMessage") + # AdvancedMode belongs to the live wallet session. Start this negative + # policy proof from factory state rather than relying on test order or + # on apply_policy(False) to revoke an already-authorized session. + self.client.wipe_device() self.setup_mnemonic_allallall() self.client.apply_policy('AdvancedMode', False) @@ -158,9 +162,10 @@ def test_solana_sign_plain_text_message_without_advanced_mode(self): AdvancedMode. Printable text that never contains the signer's key cannot authorize a transaction: a tx signature only verifies when the signer's key is in the message's account keys.""" - self.requires_firmware("7.16.0") + self.requires_firmware("7.15.0") self.requires_fullFeature() self.requires_message("SolanaSignMessage") + self.client.wipe_device() self.setup_mnemonic_allallall() self.client.apply_policy('AdvancedMode', False) From ede7ecb1423ce1dac30440728af1493e603744ed Mon Sep 17 00:00:00 2001 From: highlander Date: Sun, 20 Sep 2026 17:59:53 -0500 Subject: [PATCH 2/4] ci: restore canonical CircleCI smoke gate --- .circleci/config.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .circleci/config.yml diff --git a/.circleci/config.yml b/.circleci/config.yml new file mode 100644 index 00000000..97184bd3 --- /dev/null +++ b/.circleci/config.yml @@ -0,0 +1,22 @@ +version: 2.1 + +# The authoritative multi-release emulator matrix lives in GitHub Actions. +# Keep this smoke job while the legacy CircleCI project remains connected so +# its required status verifies the checkout instead of failing at config load. +jobs: + canonical-smoke: + docker: + - image: cimg/python:3.11 + steps: + - checkout + - run: + name: Validate canonical Python and EOS vector contracts + command: | + python -m py_compile keepkeylib/*.py tests/test_msg_solana_signtx.py + python -m pip install --quiet pytest + python -m pytest -q tests/unit/test_eos_updateauth_vector.py + +workflows: + canonical: + jobs: + - canonical-smoke From b80e128b4ec3e25a44387aa34177d2aa7ff540c1 Mon Sep 17 00:00:00 2001 From: highlander Date: Sun, 20 Sep 2026 18:01:09 -0500 Subject: [PATCH 3/4] ci: clone canonical branch over HTTPS --- .circleci/config.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.circleci/config.yml b/.circleci/config.yml index 97184bd3..bebe9441 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -8,7 +8,12 @@ jobs: docker: - image: cimg/python:3.11 steps: - - checkout + - run: + name: Checkout current branch over HTTPS + command: | + git clone --depth 1 -b "$CIRCLE_BRANCH" \ + https://github.com/keepkey/python-keepkey.git . + git submodule update --init --recursive - run: name: Validate canonical Python and EOS vector contracts command: | From b3836f9db99e90478a742d33cb4e3b592a98dde3 Mon Sep 17 00:00:00 2001 From: highlander Date: Sun, 20 Sep 2026 18:04:34 -0500 Subject: [PATCH 4/4] ci: install canonical smoke dependencies --- .circleci/config.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.circleci/config.yml b/.circleci/config.yml index bebe9441..95f8a880 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -18,7 +18,7 @@ jobs: name: Validate canonical Python and EOS vector contracts command: | python -m py_compile keepkeylib/*.py tests/test_msg_solana_signtx.py - python -m pip install --quiet pytest + python -m pip install --quiet pytest requests python -m pytest -q tests/unit/test_eos_updateauth_vector.py workflows: