Source: follow-up hardening for the SQLCipher nativeOpen crash (fixed in #208; bug #210).
The regression guard added in #208 lives in DatabaseProvisionerTest and asserts (against a mocked DatabaseEncryption) that the encryptCache = true branch calls ensureNativeLibraryLoaded(). That pins the specific fixed line, but it's a mock-interaction proxy: it verifies a call, not that the load precedes the actual keyed open, and it does not cover the open site — DatabaseModule's DeferredOpenHelperFactory → SupportOpenHelperFactory.
Add a unit-level guard closer to the open: assert that DatabaseModule's encrypted open path loads SQLCipher's native library before it constructs the SupportOpenHelperFactory (pin the "load precedes open" invariant at the factory site, not just that the provisioner calls the loader). This catches a regression where the keyed open is wired without a preceding load — which the current provisioner-only assertion would miss.
**Source:** follow-up hardening for the SQLCipher `nativeOpen` crash (fixed in #208; bug #210).
The regression guard added in #208 lives in `DatabaseProvisionerTest` and asserts (against a mocked `DatabaseEncryption`) that the `encryptCache = true` branch calls `ensureNativeLibraryLoaded()`. That pins the specific fixed line, but it's a **mock-interaction proxy**: it verifies a *call*, not that the load precedes the actual keyed open, and it does not cover the open site — `DatabaseModule`'s `DeferredOpenHelperFactory` → `SupportOpenHelperFactory`.
**Add a unit-level guard closer to the open:** assert that `DatabaseModule`'s encrypted open path loads SQLCipher's native library **before** it constructs the `SupportOpenHelperFactory` (pin the "load precedes open" invariant at the factory site, not just that the provisioner calls the loader). This catches a regression where the keyed open is wired without a preceding load — which the current provisioner-only assertion would miss.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Source: follow-up hardening for the SQLCipher
nativeOpencrash (fixed in #208; bug #210).The regression guard added in #208 lives in
DatabaseProvisionerTestand asserts (against a mockedDatabaseEncryption) that theencryptCache = truebranch callsensureNativeLibraryLoaded(). That pins the specific fixed line, but it's a mock-interaction proxy: it verifies a call, not that the load precedes the actual keyed open, and it does not cover the open site —DatabaseModule'sDeferredOpenHelperFactory→SupportOpenHelperFactory.Add a unit-level guard closer to the open: assert that
DatabaseModule's encrypted open path loads SQLCipher's native library before it constructs theSupportOpenHelperFactory(pin the "load precedes open" invariant at the factory site, not just that the provisioner calls the loader). This catches a regression where the keyed open is wired without a preceding load — which the current provisioner-only assertion would miss.