The key that spends a leg we fund — the refund key of an HTLC, the user key
of a covenant's cancel path.
The returned pubkey is taken from a signer the wallet produced, never
from the descriptor string alone. That is the difference between an
invariant and a comment: deriving the leaf key is pure parsing and would
succeed just as well for a key this wallet cannot sign for — a descriptor
allocated by a worker rebound to another identity, a record restored onto
the wrong seed — and the covenant would bind it, the leg would fund, and
the failure would surface at refund time with the money already committed.
Throws ForeignDescriptorError instead, before there is a quote.
The wallet's identity key is reused rather than a fresh HD child, so no
index is consumed when the artifact is never built — and the covenant's
refund path is on the same key as the refund address the caller sends to
at quote time.
The key that spends a leg we fund — the refund key of an HTLC, the user key of a covenant's cancel path.
The returned
pubkeyis taken from a signer the wallet produced, never from the descriptor string alone. That is the difference between an invariant and a comment: deriving the leaf key is pure parsing and would succeed just as well for a key this wallet cannot sign for — a descriptor allocated by a worker rebound to another identity, a record restored onto the wrong seed — and the covenant would bind it, the leg would fund, and the failure would surface at refund time with the money already committed. Throws ForeignDescriptorError instead, before there is a quote.The wallet's identity key is reused rather than a fresh HD child, so no index is consumed when the artifact is never built — and the covenant's refund path is on the same key as the refund address the caller sends to at quote time.