test(db): instrumented cold-open of a pre-encrypted cache (process-isolated SQLCipher regression) #221

Closed
opened 2026-07-03 15:21:43 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-03 15:21:43 +00:00 (Migrated from github.com)

Source: follow-up hardening for the SQLCipher nativeOpen crash (fixed in #208; bug #210).

The crash only manifested on a cold process opening an already-encrypted cache with no conversion running — the one state no test constructs. The existing on-device tests (DatabaseEncryptionTest, AccountDataMigratorTest) always run a conversion first, which loads the native lib in-process, masking the bug exactly as production did.

Add an instrumented test that opens the Room cache through the production wiring (DatabaseModule / DatabaseProvisioner) with encryptCache = true against a pre-existing encrypted DB, in a process where nothing has loaded the SQLCipher .so, and asserts the DB opens (no UnsatisfiedLinkError).

Caveat (why this needs care): System.loadLibrary is process-global — once any test in the run loads sqlcipher, a later test can't observe the "not loaded" state. A faithful reproduction needs process isolation (a dedicated test process / separate instrumentation run, or an orchestrator). Scope includes standing up that harness. Relates to the local-gate gap in preflight-skips-androidtest.

**Source:** follow-up hardening for the SQLCipher `nativeOpen` crash (fixed in #208; bug #210). The crash only manifested on a **cold process opening an already-encrypted cache with no conversion running** — the one state no test constructs. The existing on-device tests (`DatabaseEncryptionTest`, `AccountDataMigratorTest`) always run a conversion first, which loads the native lib in-process, masking the bug exactly as production did. **Add an instrumented test** that opens the Room cache through the production wiring (`DatabaseModule` / `DatabaseProvisioner`) with `encryptCache = true` against a **pre-existing encrypted DB**, in a process where nothing has loaded the SQLCipher `.so`, and asserts the DB opens (no `UnsatisfiedLinkError`). **Caveat (why this needs care):** `System.loadLibrary` is process-global — once any test in the run loads `sqlcipher`, a later test can't observe the "not loaded" state. A faithful reproduction needs **process isolation** (a dedicated test process / separate instrumentation run, or an orchestrator). Scope includes standing up that harness. Relates to the local-gate gap in [[preflight-skips-androidtest]].
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#221