The signer for a provisioned descriptor, verified to actually be that
descriptor's key.
The verification is a public-key equality, never a wallet-type probe: a
wallet that answers with the wrong key — another seed's, after a restore
mix-up — would sign happily, and the failure would surface only as a
counterparty rejection or a dead script.
Know its limit. It catches a wallet that substitutes its baseline
identity, which is the failure this exists for. It cannot catch one that
returns a descriptor-scoped identity built over the same descriptor, since
such an identity reads its pubkey back out of the descriptor string and the
comparison becomes a tautology. What rules that case out is
resolveDescriptorSigner's isOurs test, which both shipped wallets
resolve through — so this is the backstop for a hand-rolled IWallet, not
the primary guarantee.
The signer for a provisioned descriptor, verified to actually be that descriptor's key.
The verification is a public-key equality, never a wallet-type probe: a wallet that answers with the wrong key — another seed's, after a restore mix-up — would sign happily, and the failure would surface only as a counterparty rejection or a dead script.
Know its limit. It catches a wallet that substitutes its baseline identity, which is the failure this exists for. It cannot catch one that returns a descriptor-scoped identity built over the same descriptor, since such an identity reads its pubkey back out of the descriptor string and the comparison becomes a tautology. What rules that case out is resolveDescriptorSigner's
isOurstest, which both shipped wallets resolve through — so this is the backstop for a hand-rolledIWallet, not the primary guarantee.