Done in https://github.com/badbundle/vault-app/pull/699, merged as 03f8f062.
- The corpus is in
Vault/Tests/VaultFeedTests/Fixtures/Backups/, with a README giving each file's build, password and contents:- an auto-backup padded to 32 KiB (kept as the backup its PDF carries);
- a randomly padded PDF;
- a PDF from before the QuickType and preview choices;
- a PDF with plain-text search passphrases (from before #519);
- a device transfer's QR codes.
- How it was made: between the release tags only the payload's fields and the padding changed, so each format was recorded with today's writer set to that format. The pre-#519 one was hand-built from the payload at that commit.
- Restores: every restore goes through the password screen, into merge, override, an encrypted vault reopened from disk, and a duress vault. Only the duress vault's own slot changes.
- Malformed input: each step (the PDF, the QR codes, the
EncryptedVaultJSON, decompression and the payload JSON) has malformed-input tests and a seeded fuzz test. - A fix these tests found: the bounded decompressor from #677 ignored anything after the payload's compressed stream. It now refuses it.
- Another device: a backup made before #686 (keys travel with backups) restores its items with their digests as they were. Its killphrases and passphrases can't match under another device's keys, as the FAQ now says.