refactor(security): single source of truth for the cache DB filename/sidecars #103

Closed
opened 2026-07-02 02:56:06 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-02 02:56:06 +00:00 (Migrated from github.com)

Origin: code review of PR #45 (screen-lock app gate). Reuse/altitude cleanup — one facet is security-relevant (backup exclusion).

Problem

DatabaseFiles.NAME + its hard-coded sidecar suffix list ("", -wal, -shm, -journal) re-enumerates knowledge that already lives elsewhere:

  • BackupPolicy.EXCLUDED_DATABASE_PATHS (self-described "single source of truth") hard-codes the same libremail.db + sidecars. The PR re-pointed DatabaseModule.DB_NAME at the new DatabaseFiles.NAME constant but left BackupPolicy hard-coded. Two Kotlin sources of truth: a drifted BackupPolicy would silently stop excluding the mail cache from Android Backup (security-relevant); a drifted DatabaseFiles.clear would leave an undecryptable sidecar on disk.
  • DatabaseFiles.clear hand-rolls db+sidecar deletion when Context.deleteDatabase(NAME) — already used in DatabaseEncryptionTest — does the same in one line and also removes the -mj* master-journal temp files the manual list misses.

Suggested fix

Derive BackupPolicy.EXCLUDED_DATABASE_PATHS from DatabaseFiles.NAME, and implement DatabaseFiles.clear via context.deleteDatabase(NAME) (falling back to explicit sidecar deletion only if a caller needs the no-Context form). One source of truth for the cache filename and its sidecars.

Origin: code review of PR #45 (screen-lock app gate). Reuse/altitude cleanup — one facet is security-relevant (backup exclusion). ## Problem `DatabaseFiles.NAME` + its hard-coded sidecar suffix list (`""`, `-wal`, `-shm`, `-journal`) re-enumerates knowledge that already lives elsewhere: - **`BackupPolicy.EXCLUDED_DATABASE_PATHS`** (self-described "single source of truth") hard-codes the same `libremail.db` + sidecars. The PR re-pointed `DatabaseModule.DB_NAME` at the new `DatabaseFiles.NAME` constant but left `BackupPolicy` hard-coded. Two Kotlin sources of truth: a drifted `BackupPolicy` would silently stop excluding the mail cache from Android Backup (security-relevant); a drifted `DatabaseFiles.clear` would leave an undecryptable sidecar on disk. - **`DatabaseFiles.clear`** hand-rolls db+sidecar deletion when `Context.deleteDatabase(NAME)` — already used in `DatabaseEncryptionTest` — does the same in one line and also removes the `-mj*` master-journal temp files the manual list misses. ## Suggested fix Derive `BackupPolicy.EXCLUDED_DATABASE_PATHS` from `DatabaseFiles.NAME`, and implement `DatabaseFiles.clear` via `context.deleteDatabase(NAME)` (falling back to explicit sidecar deletion only if a caller needs the no-Context form). One source of truth for the cache filename and its sidecars.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#103