Repository navigation
Preserve cloud backups and verify every wallet backup save - #481
Closed
takemiyamakoto wants to merge 2 commits into
Closed
takemiyamakoto wants to merge 2 commits into
takemiyamakoto wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Saving a cloud backup could stall when no prior backup existed, or delete the previous backup before a replacement upload succeeded. The app now uses the existing backup encoder with an app-owned Google Drive adapter: it pins and verifies the prior revision, saves with revision retention enabled, and reads back the exact encrypted payload before reporting success. Ambiguous files and failed preservation or verification checks stop the save; no backup deletion or automatic revision pruning occurs.
The presenter now ends loading on failure, serializes repeated taps, and reuses an already-created onboarding account on retry. Before contacting Drive, it proves the captured wallet identity against retained signing material and the stored derivation path, rejecting stale account selections or conflicting phrases and paths. This retains the existing crypto libraries and backup format. Metadata rechecks detect observed concurrent changes; revision retention is not an atomic compare-and-swap guarantee against older clients writing concurrently.
Validation: four new regressions cover first save/readback, failed revision pin/update/readback and retry, onboarding retry identity and completion flags, and profile identity/path preservation. Swift parsing, the exact new adapter/presenter plus all copied test-target sources against the cached 1304 app module, source predicate checks, and 16 collector self-tests passed. The first canonical Release build and archive were stopped before tests/upload after review found a valid legacy 64-byte Ed25519 representation was rejected by the backup/restore validator. A corrected candidate is being prepared; 278-test validation is pending. This draft candidate will not be uploaded or installed.
Build 2026091305 also inherits the recovery account-choice fix from its parent. External TestFlight publication to both existing public-link groups is pending. Automated checks do not establish recovery of a wallet whose original signing material is unavailable.
Superseded before upload by PR #482, which retains legacy 64-byte Ed25519 backup/restore support. This draft candidate was not uploaded or installed.