Extend inputPaths tuples with an optional 4th `slot` element so a single
contract input can carry several sig/pubkey placeholders, each filled by
a different key. Gated behind a `multislot` capability the wallet
advertises in wallet_ready (session["hdwalletv1"].extensions.multislot);
dapps must not send slotted/repeated-index requests otherwise.
- core: widen inputPaths to [number, PathName, number, number?]; accept
3- or 4-tuples (non-negative integer slot) in isSignTransactionRequest;
add EXT_MULTISLOT constant.
- wallet: fix extractContractSighashBytes so a filled pubkey placeholder
is no longer mis-read as a signature (only signature-length pushes
carry a sighash flag); export validateSighashFlags / isP2PKH.
- docs: protocol.md (slot semantics, placeholder byte format, capability
negotiation, SIGHASH 0x41/0x61 reconciliation), extensions.md
(multislot), wallet.md, dapp.md.
- tests: multislot-signing.test.ts reference fill; sighash-validation
pubkey-placeholder regression + slot cases; validator slot accept/
reject; integration repeated-index-with-slots passthrough.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>