feat(security): encrypt persisted problem/crash reports at rest when cache encryption is on #369

Closed
opened 2026-07-06 18:22:48 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-06 18:22:48 +00:00 (Migrated from github.com)

Context

When the opt-in cache encryption (encryptCache) is ON, all of the app''s persistent data should be encrypted at rest. Today, user-initiated "Report a problem" reports (DiagnosticsCollector) and auto-captured crash reports persist as plaintext JSON in files/debug_reports (ReportStore) — a plaintext diagnostic artifact inconsistent with the user''s encryption choice.

Requirement

When encryptCache is ON, encrypt persisted reports at rest using the existing Keystore-backed crypto (KeystoreCrypto / AesGcmKeystoreCipher); decrypt on read (the ProblemReports screen). No plaintext report left on disk. When encryptCache is OFF, persist plaintext exactly as today. Reports stay PII-free regardless. Crash reports MUST still persist (encrypted when encryption is on) so they survive the crash.

NOT this ticket

The decryption-FAILURE gate report is ephemeral (cannot be encrypted because encryption is unavailable in that moment) — handled in the #367 fail-closed rework. This ticket is the normal persist-encrypted path.

Dependency

Queued behind #367 (fail-closed encryption rework). Dispatch after #367 merges.

Definition of done

Unit tests: report encrypted at rest when encryptCache on + readable back; plaintext when off; crash report persists + encrypted. PII-free AppLog. Instrumented test if the on-device Keystore path needs it.

## Context When the opt-in cache encryption (`encryptCache`) is ON, all of the app''s persistent data should be encrypted at rest. Today, user-initiated "Report a problem" reports (`DiagnosticsCollector`) and auto-captured **crash reports** persist as **plaintext JSON** in `files/debug_reports` (`ReportStore`) — a plaintext diagnostic artifact inconsistent with the user''s encryption choice. ## Requirement When `encryptCache` is ON, encrypt persisted reports **at rest** using the existing Keystore-backed crypto (`KeystoreCrypto` / `AesGcmKeystoreCipher`); decrypt on read (the ProblemReports screen). No plaintext report left on disk. When `encryptCache` is OFF, persist plaintext exactly as today. Reports stay PII-free regardless. Crash reports MUST still persist (encrypted when encryption is on) so they survive the crash. ## NOT this ticket The decryption-FAILURE gate report is *ephemeral* (cannot be encrypted because encryption is unavailable in that moment) — handled in the #367 fail-closed rework. This ticket is the normal persist-**encrypted** path. ## Dependency **Queued behind #367** (fail-closed encryption rework). Dispatch after #367 merges. ## Definition of done Unit tests: report encrypted at rest when `encryptCache` on + readable back; plaintext when off; crash report persists + encrypted. PII-free `AppLog`. Instrumented test if the on-device Keystore path needs it.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#369