Thanks for considering a contribution. KDK aims to be a provable amnesic firmware for Bitcoin signing — secrets must be wiped after use, enforced at the type-system and test-suite level.
-
No
unwrap()orexpect()inpub fnbodies. Propagate errors viaResult,?,match,ok_or(...),map_err(...). Tests and examples may useunwrapfreely. -
No
println!/eprintln!/dbg!/log::*/tracing::*in library code. never logs — errors propagate, the caller decides what to display. -
Tests live under
crates/<crate>/tests/, organised by topic -
Shared fixtures
tests/common/mod.rs. Repetitive spec-vector tables use#[macro_export]macros. -
No new dependencies without discussion. Approved baseline:
kdk-zeroizehas zero external deps — it's the foundation; adding a dep here requires an explicit security review.bitcoin,bip39,secp256k1(rust-bitcoin org)bip322,psbt-v2(BIP support)aes-gcm,pbkdf2,sha2,hmac(KEF crypto)hex(dev-dep only)
-
Format + lint clean before pushing:
cargo fmt --all cargo clippy --workspace --all-targets -- -D warnings cargo test --workspaceCI runs the same three checks.
Every type that owns secret material must zeroize on drop. Use
kdk-zeroize primitives. We aim to be less dependency possible.
SensitiveBytes<N, O>— fixed-size buffer with const-generic length and a phantomOorigin marker.enum Bip39Seed {}) to distinguish secret kinds at the type level.wipe_in_place<T>/wipe_in_place_mut<T>— generic primitives for wiping non-SensitiveBytestypes.- Custom
Debugimpl that redacts for every secret-bearing type. Neverderive(Debug)on a struct with aSensitiveBytes. - No
derive(Clone)on wallet types — cloning a secret duplicates it, defeating the amnesic guarantee. std::error::Error::source()returnsNonefor variants that wrap external errors (bip32::Error,bip39::Error). UpstreamDisplay/Debugimpls can leak user bytes (a bad mnemonic word, raw key material) — never chain through them.- Validate at every API boundary. Hardened-index rejection, range checks, policy compatibility — typed errors, never panic.
- Every variant has a
///doc comment. - Manual
Display+Fromimpls. - Error enums implement
std::error::Errorwithsource()returningNonefor any variant that wraps an upstream error containing user bytes.
Each crate carries its own examples/ and tests/ directories.
# Format + lint + test (mirrors CI)
cargo fmt --all
cargo clippy --workspace --all-targets -- -D warnings
cargo test --workspaceOverall, have fun :)