mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
KeyStore::write_and_verify confirmed a write by calling load(), which returns the in-process cache that store() itself just advanced — proving the cache was updated, not that the OS keyring durably holds the value. mint_bound_identity relies on this before returning a commit-ready binding, so a backend that acks a write without persisting it could let Phase 4b commit an identity binding whose only secret dies with the process, violating the §2.5 invariant that no binding exists with an unverified key. Route the production confirmation through SecretStore::verify_stored_raw, which bypasses the cache and reads the OS backend directly — the same primitive the identity path already uses. The other caller (migrate_inline_key) is upgraded for free; its Ok/Err contract is unchanged, only strengthened to mean durably-verified. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>