Skip to content

Preserve cloud backups and retained Ed25519 wallet credentials - #482

Draft
takemiyamakoto wants to merge 2 commits into
codex/ios-wallet-upgrade-testflight-2026091304from
codex/ios-wallet-upgrade-testflight-2026091305-r2
Draft

takemiyamakoto wants to merge 2 commits into
codex/ios-wallet-upgrade-testflight-2026091304from
codex/ios-wallet-upgrade-testflight-2026091305-r2

Conversation

@takemiyamakoto

@takemiyamakoto takemiyamakoto commented Sep 13, 2026 •

Copy link
Copy Markdown

Cloud backup saving could stall on the first backup or delete the prior backup before a replacement upload succeeded. The app now preserves and verifies the old Drive revision, saves through the existing encoder with revision retention enabled, and verifies the exact uploaded bytes before reporting success; it never deletes or prunes recovery copies.

Backup retries reuse the created onboarding account, loading always ends, and repeated taps are serialized. The presenter proves the captured wallet and stored derivation path before upload. Legacy Ed25519 JSON credentials retain their exact 32-byte seed or 64-byte seed-plus-public-key representation through backup and recovery; the suffix and signing identity are both checked. Metadata rechecks detect observed concurrent changes but do not provide atomic compare-and-swap against older clients.

Four new test methods cover save/readback failures, retained revisions, retry identity, and account/path conflicts; existing recovery methods also cover both Ed25519 representations, restarts, and rejection of altered seed or public-key suffix without wallet writes. Swift parsing and source checks passed, as did 16 collector self-tests. Canonical Release validation 3 passed: 278 wallet tests, zero failures and zero skips. All 6,085 tracked source hashes were unchanged before and after the run. The exact verified runtime patch is integrated into the primary checkout, with unrelated work and the index preserved. Runtime ec3c07f2c6ffaddbfff8c2983a63214718c519a8; publication e55774deff4d19818e006597cb65f748613256e0; build 2026091305. The signed device archive and external-capable IPA passed signature, profile, entitlement, runtime, and resource verification, including all 10 unsigned native images. Apple accepted build 2026091305 through Xcode Organizer at 2026-09-14T00:19:53Z, delivery d2278853-f1ab-4633-8758-70309d690fb7. The actual GUI package also passed verification; IPA SHA-256 19fd7a8df56e48c441ce672c46751699415c2572746cbf3943c2a2ce57099fd2. Xcode reported nine missing-dSYM warnings for bundled vendor frameworks; package upload succeeded. Processing, external group assignment and beta review still require App Store Connect verification. Build 1305 has not been installed on the reporting phone. GitHub CI passed on merge checkout 7dd820965e25e1f17ad3bccc0c9e7e4f3abe8f7b: 310 unit tests and 19 integration tests passed; the UI bundle reported 3 tests, with 1 passed and 2 skipped. These results are separate from the exact-runtime local 278-test run.

The inherited recovery account chooser allows a different Google account to be selected on each attempt. External TestFlight publication to both existing public-link groups is pending. Mnemonic recovery generates supported Taira children while retaining SORA identity; seed-only and JSON-only recovery preserve the existing SORA2-only policy. Automated results do not establish recovery of an installation with unavailable original signing material.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant