Skip to content

Preserve cloud backups and verify every wallet backup save - #481

Closed
takemiyamakoto wants to merge 2 commits into
codex/ios-wallet-upgrade-testflight-2026091304from
codex/ios-wallet-upgrade-testflight-2026091305
Closed

takemiyamakoto wants to merge 2 commits into
codex/ios-wallet-upgrade-testflight-2026091304from
codex/ios-wallet-upgrade-testflight-2026091305

Conversation

@takemiyamakoto

@takemiyamakoto takemiyamakoto commented Sep 13, 2026 •

Copy link
Copy Markdown

Saving a cloud backup could stall when no prior backup existed, or delete the previous backup before a replacement upload succeeded. The app now uses the existing backup encoder with an app-owned Google Drive adapter: it pins and verifies the prior revision, saves with revision retention enabled, and reads back the exact encrypted payload before reporting success. Ambiguous files and failed preservation or verification checks stop the save; no backup deletion or automatic revision pruning occurs.

The presenter now ends loading on failure, serializes repeated taps, and reuses an already-created onboarding account on retry. Before contacting Drive, it proves the captured wallet identity against retained signing material and the stored derivation path, rejecting stale account selections or conflicting phrases and paths. This retains the existing crypto libraries and backup format. Metadata rechecks detect observed concurrent changes; revision retention is not an atomic compare-and-swap guarantee against older clients writing concurrently.

Validation: four new regressions cover first save/readback, failed revision pin/update/readback and retry, onboarding retry identity and completion flags, and profile identity/path preservation. Swift parsing, the exact new adapter/presenter plus all copied test-target sources against the cached 1304 app module, source predicate checks, and 16 collector self-tests passed. The first canonical Release build and archive were stopped before tests/upload after review found a valid legacy 64-byte Ed25519 representation was rejected by the backup/restore validator. A corrected candidate is being prepared; 278-test validation is pending. This draft candidate will not be uploaded or installed.

Build 2026091305 also inherits the recovery account-choice fix from its parent. External TestFlight publication to both existing public-link groups is pending. Automated checks do not establish recovery of a wallet whose original signing material is unavailable.

Superseded before upload by PR #482, which retains legacy 64-byte Ed25519 backup/restore support. This draft candidate was not uploaded or installed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant