Skip to content

Restore retained wallet keys from encrypted Google Drive backups - #479

Draft
takemiyamakoto wants to merge 2 commits into
codex/ios-wallet-upgrade-testflight-2026091302from
codex/ios-wallet-upgrade-testflight-2026091303
Draft

takemiyamakoto wants to merge 2 commits into
codex/ios-wallet-upgrade-testflight-2026091302from
codex/ios-wallet-upgrade-testflight-2026091303

Conversation

@takemiyamakoto

@takemiyamakoto takemiyamakoto commented Sep 13, 2026 •

Copy link
Copy Markdown

Wallets blocked by missing_wallet_secret can now restore an existing encrypted Google Drive backup directly from the recovery screen. The reader uses bounded, exact-file reads and rejects ambiguous matches; every supplied phrase, seed or encrypted JSON credential must prove the retained SORA identity before an absent credential is added. Existing account records, credentials and recovery state are preserved until full startup verification succeeds. Mnemonic recovery enables Taira through the existing derivation policy; seed-only and JSON-only accounts retain their existing SORA2-only policy.

The screen distinguishes missing backups, wrong passwords, identity mismatches and protected-storage failures. The password stays on the phone. Validation passed: 274 canonical Release wallet tests, zero failures/skips, unchanged hashes for all 6,085 tracked files, 7 focused recovery tests, 16 collector tests, and 8 publication-contract tests. The exact tested runtime patch is integrated into the primary checkout with its index and unrelated work preserved.

Build 2026091303 is pinned to runtime 204ee5a7bbc58fc7d3b88d429bfc2198ad79e2fa and publication 6f7625b3d40b19b06166fa418ba2359731e1b2ef. The verified archive/IPA was accepted by Apple at 2026-09-13T14:16:08Z, delivery 2d4ab467-a8bf-49d4-9143-06153e90b6f8, with no package-upload errors and nine vendor dSYM symbol warnings. Processing is complete and the build is Ready to Submit, with only the two internal App Store Connect Users attached; external groups and beta review are not yet submitted, and public-link availability is unconfirmed.

The build is installed in place and the retained account identity is unchanged. The reporting phone still has database_migration / missing_wallet_secret. The attempted Drive recovery found no matching backup and did not reach the password stage; a complete metadata-only listing confirmed the currently signed-in account’s SORA app-data space contains zero files or folders. Another account may hold a backup, but this is unproven; the recovery flow currently reuses the existing Google session, and an explicit account-choice correction is under development. Actual wallet recovery and the timing or cause of credential unavailability remain unproven.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant