test(db): pin "native lib loaded before keyed open" at the DatabaseModule factory site #220

Closed
opened 2026-07-03 15:21:41 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-03 15:21:41 +00:00 (Migrated from github.com)

Source: follow-up hardening for the SQLCipher nativeOpen crash (fixed in #208; bug #210).

The regression guard added in #208 lives in DatabaseProvisionerTest and asserts (against a mocked DatabaseEncryption) that the encryptCache = true branch calls ensureNativeLibraryLoaded(). That pins the specific fixed line, but it's a mock-interaction proxy: it verifies a call, not that the load precedes the actual keyed open, and it does not cover the open site — DatabaseModule's DeferredOpenHelperFactory → SupportOpenHelperFactory.

Add a unit-level guard closer to the open: assert that DatabaseModule's encrypted open path loads SQLCipher's native library before it constructs the SupportOpenHelperFactory (pin the "load precedes open" invariant at the factory site, not just that the provisioner calls the loader). This catches a regression where the keyed open is wired without a preceding load — which the current provisioner-only assertion would miss.

**Source:** follow-up hardening for the SQLCipher `nativeOpen` crash (fixed in #208; bug #210). The regression guard added in #208 lives in `DatabaseProvisionerTest` and asserts (against a mocked `DatabaseEncryption`) that the `encryptCache = true` branch calls `ensureNativeLibraryLoaded()`. That pins the specific fixed line, but it's a **mock-interaction proxy**: it verifies a *call*, not that the load precedes the actual keyed open, and it does not cover the open site — `DatabaseModule`'s `DeferredOpenHelperFactory` → `SupportOpenHelperFactory`. **Add a unit-level guard closer to the open:** assert that `DatabaseModule`'s encrypted open path loads SQLCipher's native library **before** it constructs the `SupportOpenHelperFactory` (pin the "load precedes open" invariant at the factory site, not just that the provisioner calls the loader). This catches a regression where the keyed open is wired without a preceding load — which the current provisioner-only assertion would miss.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#220