BIP375 pairs an ECDH share with a DLEQ proof: a signer must "compute and set an ECDH share and DLEQ proof for each eligible input", and the invalid PSBT table already lists "missing PSBT_IN_SP_DLEQ field for input when PSBT_IN_SP_ECDH_SHARE set" without qualifying it on PSBT_OUT_SCRIPT.
The reference validator does not enforce that pairing for in-progress PSBTs. Its per-input DLEQ presence check sits inside the scan_key_has_computed_output branch, so as soon as PSBT_OUT_SCRIPT is absent the branch is skipped entirely and a PSBT carrying PSBT_IN_SP_ECDH_SHARE without PSBT_IN_SP_DLEQ passes validation:
$ python3 test_runner.py # before
Summary: 43 passed, 1 failed
The global path does not have this hole: a global ECDH share always requires PSBT_GLOBAL_SP_DLEQ, whether or not the output script has been computed.
This moves the share/proof pairing check out of the computed-output branch so it applies to every ECDH share, while the branch keeps doing only what its name says - checking coverage of eligible inputs. It also adds the corresponding invalid test vector (the existing one sets PSBT_OUT_SCRIPT, so it never exercised the skipped path), the matching row in the invalid PSBT table, and a changelog entry.
$ python3 test_runner.py # after
Summary: 44 passed, 0 failed
To run the tests:
cd bip-0375
python3 test_runner.py