Files
LibreMail/app/src/main/AndroidManifest.xml
T
JMR-devandClaude Fable 5 15c4cd9ae8 fix(security): harden app-lock recovery restart
The key-invalidation recovery restart was unreliable in two ways, both in
AppLockViewModel:

1. Same-process self-restart race: restartProcess() did
   context.startActivity(...) immediately followed by Runtime.exit(0) in the
   same process, so ActivityManager could schedule the relaunch into the
   process being killed and drop it — the app just closed, recovering only on
   the next manual launch. Fixed with a ProcessPhoenix-style separate-process
   trampoline (RestartActivity in a distinct ":restart" process, driven by
   ProcessRestarter): it kills the original process by PID and only then
   relaunches, so the relaunch is issued from a process that survives the kill.
   No new dependency; LibreMailApplication early-returns in the ":restart"
   process so it runs no normal startup work.

2. Lost syncNow() enqueue: clearCacheAndRestart() enqueued the post-wipe
   re-sync fire-and-forget, but WorkManager persists the WorkSpec
   asynchronously on its serial task executor, so exiting raced that insert and
   could drop the re-sync (now user-visible after #118: an empty mailbox until
   the next periodic sync). syncNow() now returns its enqueue Operation, and
   clearCacheAndRestart awaits it (bounded by a 5s timeout) before restarting,
   so the WorkSpec is durably persisted first.

CLEAR_PENDING recovery-flag semantics are preserved; the cache wipe still
happens at cold start in DatabaseModule (unchanged).

Tests: JVM unit tests assert the enqueue Operation is awaited before the
restart is triggered (order) and that a timed-out enqueue still restarts;
SyncSchedulerTest pins syncNow() returning the enqueue Operation. The
separate-process kill/relaunch is device-only and noted for on-device
wipe+resync verification.

Closes #99

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 10:09:21 -05:00

135 lines
7.3 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:tools="http://schemas.android.com/tools">
<uses-permission android:name="android.permission.INTERNET" />
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
<uses-permission android:name="android.permission.READ_CONTACTS" />
<uses-permission android:name="android.permission.POST_NOTIFICATIONS" />
<uses-permission android:name="android.permission.FOREGROUND_SERVICE" />
<uses-permission android:name="android.permission.FOREGROUND_SERVICE_DATA_SYNC" />
<!-- Android Backup is opt-in and OFF by default (issue #21). allowBackup can't be toggled at
runtime, so LibreMailBackupAgent gates it on the "Include settings in Android Backup"
preference: with backup disabled the agent ships nothing. When enabled, only the settings
DataStore is backed up per the allowlist in data_extraction_rules (API 31+) /
backup_rules (API 29-30) — never credentials, the mail cache, or the Keystore-sealed cache
passphrase. fullBackupOnly keeps this to Auto Backup (full-data) only. -->
<application
android:name=".LibreMailApplication"
android:allowBackup="true"
android:backupAgent=".backup.LibreMailBackupAgent"
android:dataExtractionRules="@xml/data_extraction_rules"
android:fullBackupContent="@xml/backup_rules"
android:fullBackupOnly="true"
android:icon="@mipmap/ic_launcher"
android:label="@string/app_name"
android:roundIcon="@mipmap/ic_launcher_round"
android:supportsRtl="true"
android:theme="@style/Theme.LibreMail">
<activity
android:name=".MainActivity"
android:exported="true"
android:label="@string/app_name"
android:theme="@style/Theme.LibreMail">
<intent-filter>
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
</intent-filter>
<!-- Handle mailto: links tapped in browsers and other apps (ACTION_VIEW), which is also
what makes LibreMail appear on the system "Open by default" / default-apps screen
where the platform exposes an email association. Android has no public RoleManager
email role, so becoming the system default is OEM-dependent — hence "where supported". -->
<intent-filter>
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="mailto" />
</intent-filter>
<!-- "Send email to <address>" targets from other apps (contacts, dialer, etc.). -->
<intent-filter>
<action android:name="android.intent.action.SENDTO" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="mailto" />
</intent-filter>
<!-- Share-to-email: text and RFC-822 email payloads with recipients/subject/body extras. -->
<intent-filter>
<action android:name="android.intent.action.SEND" />
<category android:name="android.intent.category.DEFAULT" />
<data android:mimeType="text/plain" />
<data android:mimeType="message/rfc822" />
</intent-filter>
<intent-filter>
<action android:name="android.intent.action.SEND_MULTIPLE" />
<category android:name="android.intent.category.DEFAULT" />
<data android:mimeType="message/rfc822" />
</intent-filter>
</activity>
<!-- WorkManager is initialized on-demand via Configuration.Provider, so remove the
default automatic initializer. -->
<provider
android:name="androidx.startup.InitializationProvider"
android:authorities="${applicationId}.androidx-startup"
android:exported="false"
tools:node="merge">
<meta-data
android:name="androidx.work.WorkManagerInitializer"
android:value="androidx.startup"
tools:node="remove" />
</provider>
<!-- Holds a long-lived IMAP IDLE connection for instant push (opt-in via Advanced Settings). -->
<service
android:name=".push.IdleService"
android:exported="false"
android:foregroundServiceType="dataSync" />
<!-- Separate-process trampoline for the app-lock key-invalidation recovery restart. Runs in
its own ":restart" process (android:process) so it survives the main process being killed
and can reliably relaunch the app from the outside — a same-process "startActivity then
exit(0)" restart races ActivityManager and can be dropped (the ProcessPhoenix pattern).
Not exported; only ProcessRestarter starts it. Translucent + excluded from recents so it
never flashes UI or lingers in the switcher before it finishes and exits its own process. -->
<activity
android:name=".restart.RestartActivity"
android:excludeFromRecents="true"
android:exported="false"
android:process=":restart"
android:theme="@android:style/Theme.Translucent.NoTitleBar" />
<!-- Shares downloaded attachments with viewer apps via a content:// URI. -->
<provider
android:name="androidx.core.content.FileProvider"
android:authorities="${applicationId}.fileprovider"
android:exported="false"
android:grantUriPermissions="true">
<meta-data
android:name="android.support.FILE_PROVIDER_PATHS"
android:resource="@xml/file_paths" />
</provider>
<!-- Captures the Microsoft OAuth redirect for Outlook sign-in. AppAuth's bundled manifest
already declares RedirectUriReceiverActivity with an intent-filter for
${appAuthRedirectScheme}, which build.gradle.kts sets to the Outlook scheme
(org.libremail.outlook); the redirect URI org.libremail.outlook://oauth2redirect must
be registered as a public-client (mobile/desktop) redirect in the Azure app
registration. We only merge a theme onto that activity here: AppAuth declares no theme
and RedirectUriReceiverActivity extends AppCompatActivity, so without an AppCompat theme
it inherits the app's Theme.Material shell and crashes ("You need to use a Theme.AppCompat
theme") when the redirect launches it. We reuse the translucent theme AppAuth itself
applies to AuthorizationManagementActivity. -->
<activity
android:name="net.openid.appauth.RedirectUriReceiverActivity"
android:exported="true"
android:theme="@style/Theme.AppCompat.Translucent.NoTitleBar"
tools:node="merge" />
</application>
</manifest>