fix: 离线解密恢复 WAL 并区分密钥认证与索引损坏 - #168
Merged
2977094657 merged 7 commits intoSep 28, 2026
Merged
2977094657 merged 7 commits into
2977094657 merged 7 commits into
Conversation
xiaoshengbao
marked this pull request as draft
September 28, 2026 10:22
xiaoshengbao
marked this pull request as ready for review
September 28, 2026 13:13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #166
离线解密此前忽略未 checkpoint 的 WAL,同时把输出完整性失败当作密钥认证失败。本次恢复经校验的已提交 WAL 页面;如果所有页面认证通过,而输出仅有已识别的索引条目异常,则在临时副本上重建对应索引,完整性检查通过后才原子发布。失败时保留已有输出,原始微信文件不修改。
保留 session + message 跨库密钥认证,将密钥正确性与输出结构完整性分开。界面显示部分成功、失败文件、密钥认证状态及索引恢复提示。损坏 WAL、页面 HMAC 错误、源文件变化和表页损坏仍明确报错。
针对 Issue #166 的验证
已合并上游
1b516cf的新 macOS source-public 运行时。用户完成系统钥匙串授权后,标准npm run dev启动了 Nuxt、Electron 和完整后端,健康检查通过。没有绕过过期、签名或授权检查。source=decrypted,会话和消息接口分别返回 5 个会话、5 条消息;实际 Electron 聊天窗口能够显示已有数据。git diff --check通过。验证范围
真实账号没有原生索引损坏;报告者仅提供日志,没有提供其 734 页原始数据库。同名索引损坏由真实 SQLite 页构造的加密样本复现,不能声称已经验证过报告者原库。
桌面验证覆盖真实应用启动、完整后端的针对性回归和可见聊天页面;不宣称自动点击完成整个首次使用/密钥捕获向导。此前最小 FastAPI 路由容器的测试只作为补充证据。
详细记录见
docs/issue-166-validation.md。PR 不包含真实账号标识、密钥、聊天内容、数据库或原始日志。