Guards the SQLCipher cold-start crash fixed in 592a797 (bug #210): a cold
process opening an already-encrypted cache with nothing to convert reached
Room's keyed nativeOpen with the native .so unloaded and crash-looped with
UnsatisfiedLinkError. Every existing on-device test (DatabaseEncryptionTest,
DatabaseProvisionerInstrumentedTest, DatabaseModuleInstrumentedTest,
AccountDataMigratorTest) runs a conversion first, which loads the process-global
library in-process, masking the bug exactly as production did.
System.loadLibrary is process-global, so the instrumentation process can no
longer observe a cold open once it has minted the encrypted fixture. This adds
ColdOpenCacheProbe -- a debug-only ContentProvider declared with
android:process=":coldopen" -- to host the open in a separate, pristine app
process. The test mints the encrypted fixture in the instrumentation process
(a file created by a prior encrypted DB instance) and drives the cold open in
the :coldopen process via ContentResolver.call, mirroring DatabaseProvisioner's
encrypted branch + DatabaseModule's open lambda against the real DatabaseEncryption,
DeferredOpenHelperFactory and SupportOpenHelperFactory. A cold probe (a keyed open
with no preceding load, asserted to throw UnsatisfiedLinkError) makes the isolation
self-verifying: the test fails rather than passing hollow if the library was
already loaded in the harness process.
Verified locally on an API 36 emulator (connectedDebugAndroidTest): 1 test,
0 failures.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
22 lines
1.1 KiB
XML
22 lines
1.1 KiB
XML
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
|
|
<manifest xmlns:android="http://schemas.android.com/apk/res/android">
|
|
|
|
<!--
|
|
Debug-only test harness for issue #221 (never merged into a release APK — this manifest belongs to
|
|
the debug source set). Hosts ColdOpenCacheProbe in a dedicated ":coldopen" process so an
|
|
instrumented test can observe a GENUINE cold open of a pre-encrypted cache: a process where nothing
|
|
has yet loaded SQLCipher's process-global native library. The instrumentation process can't offer
|
|
that — minting the encrypted fixture (or any earlier test) loads the .so there, masking the 592a797
|
|
nativeOpen crash. The provider is exported="false" and inert unless ContentResolver.call() targets
|
|
it, so it has no effect on ordinary debug runs.
|
|
-->
|
|
<application>
|
|
<provider
|
|
android:name="org.libremail.data.local.coldopen.ColdOpenCacheProbe"
|
|
android:authorities="${applicationId}.coldopen"
|
|
android:exported="false"
|
|
android:process=":coldopen" />
|
|
</application>
|
|
|
|
</manifest>
|