Fixed in https://github.com/badbundle/vault-app/pull/627 (merged as ad7d43dc).
Write-ahead log and freed pages
- The system SQLite runs with
secure_delete = FAST. That clears a short deleted note, but leaves a long note's overflow pages intact on the freelist, and SwiftData can't change the setting. - So
PersistedStoreScrubberopens a short-lived secondsqlite3connection. It never creates the file and has a 2 s busy timeout. It runsVACUUM, thenPRAGMA wal_checkpoint(TRUNCATE). - It runs after:
- a killphrase match, a single delete, delete all, and an override import;
- a killphrase or search passphrase being set, changed or cleared.
- At launch it runs as a checkpoint, and only vacuums if pages were freed. That also clears phrases a schema migration left on freed pages.
- It's silent and best effort, and only runs after a killphrase match, so it adds no oracle (C2).
Pending rehash files
- They're deleted as soon as they're drained.
- After a crash mid-drain, the next launch re-applies every entry and deletes the file.
- An undecodable file is deleted, and an unreadable one is kept.
- The false "overwrite with zeros" was removed and its doc comments corrected. On iOS, a file's per-file key goes when the file is deleted.
Recovery archives
- These are never deleted automatically, except empty folders.
- The Backups page shows a "Vault Set Aside" section with the date. "Delete Set-Aside Vault" asks for confirmation, then device authentication.
- Delete All Data removes them. An override import doesn't.
Tests:
PersistedLocalVaultStoreResidueTests: after each kind of delete or secret change, short and overflow-page notes can't be found in.sqlite,-walor-shm.- Tests for archives, the set-aside view model and the rehash services.
- Snapshots of the Backups section.