This PR clarifies which keys can decrypt a BIP138 backup.
It expands the existing exclusion rule to consider all descriptors and key expressions in the backup. This makes encryption safer, but does not impact decryption, so it's not a breaking change.
Four middle commits:
- generalize key-selection test vectors: rename
keys_types.jsontorecipient_keys.jsonand support lists of descriptors and expected keys, preserving the nine existing cases. - clarify MuSig participant eligibility: add two vectors, clarify that the participant xpubs should be used, not the aggregate key
- collect and deduplicate recipient keys across the backup: deduplicate across all descriptor / policy sets.
- exclude roots exposed by another expression: three test vectors: bare/derived reuse, an opposite-parity literal, and a MuSig participant exposed in a script leaf.
The first commit introduces a changelog. I'm reusing that commit across a few parallel pull requests.
The last commit updates the changelog; I'll update that depending on merge order.