Device upgrade testing surfaced a crash: on a cache last written before
v13, account_settings has 4 columns (accountId, signature,
signatureEnabled, notificationsEnabled) but the destination table has 6
(retentionCount/retentionMonths were added at v13). The migrator ran
`INSERT OR IGNORE INTO account_settings SELECT * FROM cache...`, which
supplied 4 values for 6 columns and threw SQLiteException — and because
the done-flag is only set after a successful copy, every launch re-ran
and re-crashed (crash loop).
AccountDataMigrator now copies each table by the column names present in
BOTH the freshly-created destination and the (possibly older) source, so
columns the source lacks take the destination's defaults instead of
overflowing the value list. Verified on-device: the upgrade migrates a
pre-v13 install cleanly and the account stays signed in (sync/backfill
workers run). Regression test seeds a v12 cache and asserts the copy.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Main advanced to @Database v15 (the #66 folder hierarchyDelimiter
migration). Renumbered the account-tables-drop migration 14->15 to
15->16 and bumped the cache DB to v16; this exports the v16 schema
(main's v15 delimiter schema minus the moved account tables). Main's
own 15.json is kept unchanged.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two on-device assertion failures (green on JVM compile, red on the
emulator):
- migratorDdlMatchesExportedAccountDatabaseSchema built its expected DDL
by substituting the schema's `${TABLE_NAME}` placeholder with a
backtick-wrapped name, but the exported createSql already wraps the
placeholder in backticks — producing a double-backticked identifier
that never matched the (correct, single-backticked) migrator DDL.
Substitute the bare name so the guard compares like-for-like.
- movesEveryAccountTableOutOfAPlaintextCache asserted signatureEnabled
was false, but the seed row sets it to 1 (true). Assert the seeded
values for both booleans so a true and a false each round-trip.
The production migrator DDL and drop logic were already correct; only
the tests were wrong.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
`@Test fun x() = runBlocking { ... }` whose block ends in `.apply { }`
returns the DB (non-Unit), so JUnit4 rejects the whole class at runtime
with InvalidTestClassError ("method should be void") — which compiles
fine locally but fails every E2E job on the emulator. Use
`runBlocking<Unit>` (the existing DatabaseEncryptionTest idiom) so the
methods are void while keeping the expression body ktlint expects.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Accounts, credentials, per-account settings and signatures lived in the
same libremail.db that SQLCipher encrypts under the auth-bound passphrase
when app-lock + encrypted-cache are on. A genuine key invalidation
(biometric re-enrollment or lock removal/re-add) made that file
undecryptable, and the "clear + re-sync" recovery wiped the accounts and
stored credentials along with the mail cache, dropping the user into
onboarding (issue #111).
Move those four tables into a new plaintext AccountDatabase
(libremail-accounts.db) that is never bound to the auth key. Credentials
stay AES-GCM sealed at the column level by the surviving non-auth
KeystoreCrypto master key, so the only secret never touches disk in the
clear. A cache-key invalidation now wipes only libremail.db; the user
stays signed in.
- AccountDatabase (v1) + AccountDatabaseModule; the cache DB drops to v15
via MIGRATION_14_15. DAOs are unchanged and re-provided from the new DB,
so no injection site changes.
- AccountDataMigrator performs the one-time cross-DB copy at startup,
before Room opens either database. It attaches the cache (with its
resolved passphrase, so an encrypted source is handled) and copies with
INSERT OR IGNORE. It is crash-safe and idempotent: the source is dropped
only by MIGRATION_14_15 after the copy, a re-run never duplicates or
overwrites, and it runs after the clear-pending wipe so an unrecoverable
cache degrades to "nothing to move" instead of blocking.
- Exported schemas for both databases; MigrationTest asserts the account
rows/backfills survive to v14 then are dropped at v15, plus a dedicated
14->15 test. AccountDataMigratorTest covers the plaintext + encrypted
copy, idempotency, a DDL-vs-Room drift guard, and end-to-end survival of
a simulated cache wipe.
Closes#111
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>