self-review iteration 10

This commit is contained in:
Alain Brenzikofer
2026-09-25 08:31:31 +02:00
parent c3c3d8e3c9
commit ab88104dbd
3 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -21,7 +21,7 @@ constraints: zip +disable-bzip2 +disable-zstd
source-repository-package
type: git
location: https://github.com/simplex-chat/simplexmq.git
tag: 4719c432589c7b2f964d10d0502ee77701ef78fe
tag: 355cec2eb434fe29a8f947c8196e6936a1875932
source-repository-package
type: git
+2 -2
View File
@@ -27,7 +27,7 @@ A device has one piece of [BIP-39](https://github.com/bitcoin/bips/blob/master/b
Each thing the device owns on chain is assigned an **account index**, and the key at that index is the **account key**. Names are the first use: one name, one account, and that account's address is the owner address in the name record. Which chat profile an account belongs to is a mapping in the database. No path contains a profile, so no profile data is an input to the derivation, and the mapping can be changed without changing any key.
```
master seed, 24 words the only thing to back up
master seed, 24 words the only key material to back up
└── m/44'/60'/n'/0/0 account n, n >= 0
```
@@ -114,7 +114,7 @@ Three cases, by how much of the database is restored.
What the scan finds is unbound, and the user attaches each account to a profile with `bind account=<n>`. The names those accounts own identify them, which is what makes the choice possible at all: the user chooses between names they recognise, not between numbers. Binding changes no key and signs nothing, because ownership does not change, only the profile under which the app shows the account. Pointing a name at that profile's SimpleX address is a separate signed edit of the name's record.
**The database is restored from a backup.** It contains the accounts as of the backup and nothing written after it, so its counter is behind if an account was bound after the backup. A counter that is behind is worse than one that is unknown, because it appears valid, so `bind` returns an account that is already in use. Nothing here distinguishes a restored database from a current one, so clearing the counter is the responsibility of whatever restores a database, along with the scan that sets it again.
**The database is restored from a backup.** It contains the accounts as of the backup and nothing written after it, so its counter is behind if an account was bound after the backup. A counter that is behind is worse than one that is unknown, because it appears valid, so `bind` can return an account that is already in use. Nothing here distinguishes a restored database from a current one, so clearing the counter is the responsibility of whatever restores a database, along with the scan that sets it again.
**The database is current.** It records which profile holds which account, so the user is asked nothing.
+1 -1
View File
@@ -1,5 +1,5 @@
{
"https://github.com/simplex-chat/simplexmq.git"."4719c432589c7b2f964d10d0502ee77701ef78fe" = "014iy7a0jqxhky62140smhj1jsr24d1xlr94hcv1fpngw84bn0s4";
"https://github.com/simplex-chat/simplexmq.git"."355cec2eb434fe29a8f947c8196e6936a1875932" = "0rfq20a1vvzw001zgw5df11xkdvh8qxwwanr08cz84g3xbi1ldvf";
"https://github.com/simplex-chat/hs-socks.git"."a30cc7a79a08d8108316094f8f2f82a0c5e1ac51" = "0yasvnr7g91k76mjkamvzab2kvlb1g5pspjyjn2fr6v83swjhj38";
"https://github.com/simplex-chat/direct-sqlcipher.git"."f814ee68b16a9447fbb467ccc8f29bdd3546bfd9" = "1ql13f4kfwkbaq7nygkxgw84213i0zm7c1a8hwvramayxl38dq5d";
"https://github.com/simplex-chat/sqlcipher-simple.git"."a46bd361a19376c5211f1058908fc0ae6bf42446" = "1z0r78d8f0812kxbgsm735qf6xx8lvaz27k1a0b4a2m0sshpd5gl";