pico-quorum

Tracking upstream picowallet

PicoQuorum keeps picowallet’s secure-element drivers and changes them as little as possible, so their fixes can come across cleanly. This file is where the fork point, merges, and the files worth watching get recorded.

Where we are

  commit date
Fork point 87c717c 2026-09-13
Our picowallet work on top (chip map, config fix, wiring) through 35c744c 2026-09-19
Upstream merged through 72539d5 2026-09-21 (merged 2026-09-24)

What the 2026-09-24 merge brought in: firmware/trustm.py (OPTIGA Trust M driver), TrustMAttest.sol and its test, the USB wallet (usbwallet.py, main_usb.py, USB.md, WebSerial in the app), blockies.py, tools/check_config, CLEARSIGNING.md, and emulator serial stdin.

How the conflicts were resolved (keep this in mind on the next merge):

Checked after the merge: tools/check_config ok; test-vectors 9/9 on CPython and MicroPython; the emulator boots the WiFi wallet, the chip map and the USB wallet, and USB setup provisions a blank virtual chip; forge test 40/40, including TrustMAttest 6/6. Not checked: anything on real hardware, and trustm.py has not run against a Trust M in this repo. (It has since: 2026-09-28, unchanged, under trustm_q.py. See docs/TRUSTM.md.)

What is still from picowallet

These files started in picowallet, by Austin Griffith (MIT), and each says so at its top:

  files
Chip drivers firmware/atecc.py (its transport core), firmware/trustm.py
Crypto and display helpers firmware/keccak.py, firmware/p256.py, firmware/lcd.py (the ST7789 core), firmware/blockies.py, firmware/net.py (WLAN join)
The emulator emu/core/runtime.mjs, png.mjs, workspace.mjs, ship.mjs, devices.mjs, usbinfo.py; the shims machine.py, _bootstrap.py, network.py, requests.py, socket.py, rp2.py; emu/headless.mjs, emu/cli.mjs, emu/server.mjs, the dev page in emu/web/ (not browser.mjs)
Tools tools/emu, the start of tools/check_config

Removed on 2026-10-06, before the repository went public, because PicoQuorum doesn’t use them: the single-owner vault app (app/: Scaffold-ETH 2, ChipAccount, TrustMAttest), the case (cad/console/, with the Plass and Zez0000 parts), the Pi signer and SeedSigner parts (reference/), the wallet firmware (wallet.py, usbwallet.py, mock.py, demo.py, keytest.py, vid.py, eip712.py, main.py, main_usb.py, power.py), the case and WiFi-console tools (pico, push, qr, shot, gif2pv, lid, zez*), the 3D view, and the picowallet notes (picowallet.md, PLAN-picowallet.md, HANDOFF.md, USB.md, CLEARSIGNING.md, TESTPLAN.md, UPSTREAM.md, UPSTREAM-ISSUE.md, the 2026-09-05 build-log entries and photos). They are all in this repository’s history, and in picowallet.

How to bring a fix across

A whole merge would mostly be conflicts now: upstream edits files this repo no longer has. Bring fixes across file by file instead:

git remote add upstream https://github.com/austintgriffith/picowallet   # once
git fetch upstream
git log --oneline 72539d5..upstream/main -- firmware/atecc.py firmware/trustm.py firmware/keccak.py firmware/p256.py firmware/lcd.py
git diff 72539d5 upstream/main -- firmware/trustm.py | git apply -3    # one file at a time
python3 test-vectors/run.py && python3 tools/check_config               # must still pass

A change to a console-image file changes the release fingerprint: rebuild the pages and badges (RELEASES.md). Then update the table above and add a line to the log below.

Files to watch

firmware/atecc.py, firmware/trustm.py, firmware/keccak.py, firmware/p256.py, and upstream’s SECURITY.md.

Log