Reject counter documents that omit recovery state

This commit is contained in:
archipelago
2026-10-06 14:45:42 -04:00
parent 12e2a82b28
commit 9771378bfd
2 changed files with 8 additions and 2 deletions
+1 -2
View File
@@ -387,7 +387,6 @@ async fn write_seed(data_dir: &Path, mnemonic: &bip39::Mnemonic, source: SeedSou
#[derive(Debug, Default, Serialize, Deserialize)]
struct StoredCounters {
/// keyset id → next unused counter.
#[serde(default)]
counters: BTreeMap<String, u32>,
}
@@ -849,7 +848,7 @@ mod tests {
let dir = tempfile::tempdir().unwrap();
fs::create_dir_all(dir.path().join("wallet")).await.unwrap();
let path = dir.path().join(COUNTER_FILE);
for damaged in ["", " ", "{ truncated"] {
for damaged in ["", " ", "{ truncated", "{}", "{\"counters\":null}"] {
fs::write(&path, damaged).await.unwrap();
assert!(reserve_counters(dir.path(), V1_KEYSET, 1).await.is_err());
assert_eq!(fs::read_to_string(&path).await.unwrap(), damaged);
+7
View File
@@ -104,3 +104,10 @@ Read-only checks found well-shaped seed/counter JSON on dev and Yaya; no secret
values were printed and no wallet files were changed by those checks. Production
build/deployment of this prerequisite remains pending. Durable initial purchase
intent, mint-operation recovery, seller receipt and refund recovery remain open.
Strict-schema follow-up: an existing counter document must actually contain its
counter map. Empty JSON objects and null maps are rejected without modification,
not deserialized as a fresh zero state. The full isolated suite again passes
1,755tests,0failures,5existing ignored in
`/tmp/archy-wallet-recovery-strict-schema-full-tests.log`. No live deployment or
claim of complete initial-payment recovery is implied.