Reject counter documents that omit recovery state
This commit is contained in:
@@ -387,7 +387,6 @@ async fn write_seed(data_dir: &Path, mnemonic: &bip39::Mnemonic, source: SeedSou
|
|||||||
#[derive(Debug, Default, Serialize, Deserialize)]
|
#[derive(Debug, Default, Serialize, Deserialize)]
|
||||||
struct StoredCounters {
|
struct StoredCounters {
|
||||||
/// keyset id → next unused counter.
|
/// keyset id → next unused counter.
|
||||||
#[serde(default)]
|
|
||||||
counters: BTreeMap<String, u32>,
|
counters: BTreeMap<String, u32>,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -849,7 +848,7 @@ mod tests {
|
|||||||
let dir = tempfile::tempdir().unwrap();
|
let dir = tempfile::tempdir().unwrap();
|
||||||
fs::create_dir_all(dir.path().join("wallet")).await.unwrap();
|
fs::create_dir_all(dir.path().join("wallet")).await.unwrap();
|
||||||
let path = dir.path().join(COUNTER_FILE);
|
let path = dir.path().join(COUNTER_FILE);
|
||||||
for damaged in ["", " ", "{ truncated"] {
|
for damaged in ["", " ", "{ truncated", "{}", "{\"counters\":null}"] {
|
||||||
fs::write(&path, damaged).await.unwrap();
|
fs::write(&path, damaged).await.unwrap();
|
||||||
assert!(reserve_counters(dir.path(), V1_KEYSET, 1).await.is_err());
|
assert!(reserve_counters(dir.path(), V1_KEYSET, 1).await.is_err());
|
||||||
assert_eq!(fs::read_to_string(&path).await.unwrap(), damaged);
|
assert_eq!(fs::read_to_string(&path).await.unwrap(), damaged);
|
||||||
|
|||||||
@@ -104,3 +104,10 @@ Read-only checks found well-shaped seed/counter JSON on dev and Yaya; no secret
|
|||||||
values were printed and no wallet files were changed by those checks. Production
|
values were printed and no wallet files were changed by those checks. Production
|
||||||
build/deployment of this prerequisite remains pending. Durable initial purchase
|
build/deployment of this prerequisite remains pending. Durable initial purchase
|
||||||
intent, mint-operation recovery, seller receipt and refund recovery remain open.
|
intent, mint-operation recovery, seller receipt and refund recovery remain open.
|
||||||
|
|
||||||
|
Strict-schema follow-up: an existing counter document must actually contain its
|
||||||
|
counter map. Empty JSON objects and null maps are rejected without modification,
|
||||||
|
not deserialized as a fresh zero state. The full isolated suite again passes
|
||||||
|
1,755tests,0failures,5existing ignored in
|
||||||
|
`/tmp/archy-wallet-recovery-strict-schema-full-tests.log`. No live deployment or
|
||||||
|
claim of complete initial-payment recovery is implied.
|
||||||
|
|||||||
Reference in New Issue
Block a user