The key that spends a leg we claim, plus the preimage that unlocks it.
Pass opts.preimage to bring your own 32-byte P; it comes back verbatim
with mustPersistPreimage set, since the wallet cannot re-derive what it
did not choose.
Three arms, and which one a wallet lands in is the whole of this function:
Caller-supplied P. Returned unchanged, mustPersistPreimage: true.
Per-artifact descriptor (an HD child). Derives from the key alone at
the pinned index. Nothing at rest. Raises rather than falling through if
the signer cannot sign deterministically — an HD descriptor whose wallet
refuses is a broken wallet, not a fallback case.
Anything else — a static wallet's tr(pubkey), or a constant
descriptor from a custom provider. Mints a public per-artifact salt and
derives from it, so a key that repeats still yields a distinct P. Only
this arm falls back to a stored random preimage, and only when the signer
refuses — which is discovered by deriving, never by probing.
The key that spends a leg we claim, plus the preimage that unlocks it.
Pass
opts.preimageto bring your own 32-byte P; it comes back verbatim withmustPersistPreimageset, since the wallet cannot re-derive what it did not choose.Three arms, and which one a wallet lands in is the whole of this function:
mustPersistPreimage: true.tr(pubkey), or a constant descriptor from a custom provider. Mints a public per-artifact salt and derives from it, so a key that repeats still yields a distinct P. Only this arm falls back to a stored random preimage, and only when the signer refuses — which is discovered by deriving, never by probing.