Skip to content

Guard iOS transfers and validate portable receive identities - #1304

Open
takemiyamakoto wants to merge 168 commits into
developfrom
codex/testflight-redesign-2026.8.17
Open

takemiyamakoto wants to merge 168 commits into
developfrom
codex/testflight-redesign-2026.8.17

Conversation

@takemiyamakoto

@takemiyamakoto takemiyamakoto commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

This candidate keeps new transfer execution behind current release authorization while retaining read-only route discovery and fee quotation. It adds disabled portable-backup components for iOS 18+ native passkey PRF, explicit-account Google Drive app-data access, local key wrapping, owner-head reconciliation, original-source proof and a read-only receive plan. Production XCM execution and passkey recovery remain off pending their release gates.

Current pushed source is 9415f7f7b8f37b1807229655c300f7d40e32d7fe on codex/testflight-redesign-2026.8.17. The portable receive path can now project a journal-bound cohort into the app-owned MetaAccountSelectionModel records consumed by the existing exact-replacement Core Data mapper. It preserves fresh destination IDs, selected wallet and cohort order, signed Substrate/EVM/native TON public identities, approved/named chain accounts, favorites and native display preferences. Currency IDs resolve against a supplied trusted local catalog. The projection keeps every existing install blocker and sets backup completion to false; it neither writes storage itself nor authorizes recovery.

Watch custody, Android-only display fields, uninitialized wallets, unknown chains and root combinations the released mapper cannot round-trip reject the entire projection. Watch identity proofs still require the original public-key/address binding and a reviewed Substrate genesis inventory for chain-specific watches. FPWMSM01 retains Android display metadata IDs 10/11 and versioned asset-row ID 12 with exact UTF-8 bytes and nullable state; their prospective wallet-bound sidecars remain uninstalled. Original Android auxiliary material still needs durable iOS storage and signing/export projection. Recovery has no partial-cohort fallback.

The current source passed 25/25 iOS 18.1 arm64 Release simulator tests, with no skips or failures: 9 new Core Data projection cases and 16 existing mapper regressions. Tests persist and refetch real Core Data records for mixed Substrate/EVM, standalone EVM, native TON, TON/EVM, historical SS58 Substrate and named chain accounts, and reject journal/signer substitution and unrepresentable cohorts. Strict source SwiftLint, SwiftFormat, Swift parse, project syntax and diff checks passed. The preceding db4beab4 source passed all hosted checks; this successor requires its own hosted checks and independent human security review. Earlier receive/presentation tests and Codex Security scans ce118e0e-f508-414f-b44f-8ef4664c696c and 653bd1c8-6909-4c6e-bf98-2c9340edf73e remain supporting evidence for their own immutable ranges. No new formal scan result is claimed for the Core Data projection diff.

Production still requires atomic Core Data/Keychain installation and original-key signing/export readback, durable foreign-source/display storage, real Google Password Manager and Drive interoperability, verified service cutover, both replacement-device restoration directions with the original devices unavailable, funded transfer and general TON evidence, provider provisioning, and Apple-delivered in-place upgrade acceptance. The audited Release identity is jp.co.soramitsu.fearlesswallet 4.2.0 (2026.8.34); archive preflight lacks this host's required provider configuration and successor build numbering needs reconciliation. No feature was enabled, uploaded or deployed. Iroha remains with its owner on optimizations and is untouched by this PR.

Signed-off-by: Makoto Takemiya <takemiya@soramitsu.co.jp>
Signed-off-by: Makoto Takemiya <takemiya@soramitsu.co.jp>
Pin the reviewed v7.0.0 action commit. Its bundled wrapper uses the live codecovsecops Keybase account after the v5.5.2 codecovsecurity URL began returning HTTP 404. Extend the fail-closed contract with an adversarial regression for the retired action.

Signed-off-by: Makoto Takemiya <takemiya@soramitsu.co.jp>
Prevent a concurrent owner CAS during selected-account revalidation from returning stale local backup evidence. Exercise a valid revision-8 successor head in the regression fixture.
Replace stale setup guidance that suggested post-resolution shared-features patching with the pinned source and verify-only contract.
@takemiyamakoto takemiyamakoto changed the title feat(ios): guard wallet transfers and add portable backup primitives Guard iOS transfers and validate portable receive identities Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant