You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+12-5Lines changed: 12 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ The original webcam/audio/mouse implementation is preserved unchanged under `leg
12
12
13
13
## Release Status
14
14
15
-
Current project version: **2.3.0**
15
+
Current project version: **2.3.1**
16
16
17
17
The maintained CLI is tested on Windows and Linux with Python 3.11, 3.12, and 3.13 through GitHub Actions.
18
18
@@ -25,7 +25,6 @@ Python 3.11 or newer is recommended.
25
25
Install the CLI from a local checkout:
26
26
27
27
```bash
28
-
python -m pip install -r requirements.txt
29
28
python -m pip install .
30
29
entropyseed --self-test
31
30
```
@@ -42,19 +41,25 @@ The base install has no runtime dependency beyond Python's standard library. Ins
42
41
python -m pip install '.[qr]'
43
42
```
44
43
44
+
For development and test runs, install the test dependencies:
45
+
46
+
```bash
47
+
python -m pip install -r requirements.txt
48
+
python -m pytest -q
49
+
```
50
+
45
51
---
46
52
47
53
## Running From The Repository
48
54
49
55
You can also run the repository entry point directly:
50
56
51
57
```bash
52
-
python -m pip install -r requirements.txt
53
58
python seedgen.py --self-test
54
59
python seedgen.py
55
60
```
56
61
57
-
The generator uses the Python standard library for normal mnemonic generation. `qrcode` is used only for optional terminal QR output, and `pytest` is listed for the test suite.
62
+
The generator uses the Python standard library for normal mnemonic generation. `pytest` is listed only for development and test runs. `qrcode` is installed only through the optional `.[qr]` extra when terminal QR output is wanted.
58
63
59
64
---
60
65
@@ -128,14 +133,16 @@ If `--qr` is requested without QR support installed, the program exits before co
128
133
129
134
## Entropy Sources
130
135
131
-
OS CSPRNG entropy from `secrets.token_bytes` is always included and cannot be disabled. Manual typing, dice rolls, and timer jitter are supplemental only — they strengthen the pool, they do not replace it.
136
+
OS CSPRNG entropy from `secrets.token_bytes` is the mandatory foundation and cannot be disabled. Dice rolls are a strong independent supplement when the dice are fair, private, and used correctly. Manual typing is an optional supplement, but the tool does not assume or quantify its entropy. Timer jitter is an opportunistic local supplement, not a substitute for the OS CSPRNG.
132
137
133
138
Generation fails if the mandatory OS CSPRNG source is missing or returns an unexpected amount of entropy. The tool is designed to fail closed rather than silently downgrade to weaker supplemental sources.
134
139
135
140
Dice input accepts digits `1` through `6`; spaces are ignored. For 12-word generation, at least 50 dice rolls are required. For 24-word generation, at least 99 dice rolls are required.
136
141
137
142
Timer jitter displays a short collection message and progress dots. It is collected in memory and should complete quickly.
138
143
144
+
The supported CLI path is `collect_sources() -> derive_mnemonic()`. Internally, `derive_mnemonic()` requires the mandatory OS source label (`os-csprng`) before mixing; this is a fail-closed software check for the supported path, not cryptographic proof of byte provenance.
0 commit comments