Repository navigation
Conversation
Release builds minify with R8, and every BouncyCastle class reached only through JCA name lookup (Provider.getService) is invisible to that analysis: the shrinker stripped the X25519 and AES-GCM implementations while the provider registration strings stayed. A fresh GitHub sign-in sailed through start and poll - neither touches crypto - and then died inside the first local key derivation, which the account store's catch-all reports as a malformed relay response. Debug builds never shrink, which is why the breakage stayed invisible to contributors. Keeping org.bouncycastle.** intact grows the release APK from 4.6 MB to 6.7 MB; a signed-in client immediately completes X25519-encrypted device RPCs again.
Author
|
用中文补充说明一下问题和原因: 现象:release 包上用 GitHub 网页授权登录,浏览器里一切正常、也提示登录成功,回到 App 却报「中继返回了无效的账号响应」,每次必现;debug 包完全正常。 原因:这个报错其实是个"冤案"——失败发生在本地,和中继返回了什么毫无关系。release 包开了 R8 代码收缩,而 BouncyCastle 的算法实现是通过 JCA 按名字查找的( 证据:坏包的 classes.dex 里 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Release Android builds minify with R8, and every BouncyCastle class reached only through JCA name lookup (
Provider.getService) is invisible to that analysis: the shrinker strips the X25519 and AES-GCM implementations while the provider registration strings stay. A fresh GitHub relay sign-in sails through/api/auth/github/startandpoll— neither touches crypto — and then dies inside the first local key derivation (DeviceIdentity.publicKey), which the account store's catch-all reports to the user as "The relay returned an invalid account response." No relay response is involved at all, so the message is both wrong and a dead end.This PR keeps
org.bouncycastle.**intact in release builds.Type and Areas
Type: bug fix
Areas: mobile (Android app, release build config)
Motivation / Impact
On any release build (
assembleReleaseenables R8 minification), GitHub web sign-in could never complete: the browser authorization succeeds, and the moment the app exchanges the token locally the login fails with the misleading malformed-response error. Debug builds never shrink, which is why the breakage stayed invisible to contributors running:app:assembleDebug. After this change, release sign-in works end to end.Verification
classes.dexinspection of:app:assembleReleaseoutput atupstream/main+ this change:org.bouncycastle.math.ec.rfc7748(X25519) goes from 0 references to 8,GCMBlockCipherfrom 0 to 3; APK size grows 4.6 MB → 6.7 MB.authorization poll result status=authorizedand then fails with the malformed-response error — no/api/auth/loginrequest is ever logged. With this change, the same flow logsaccount login response accepted, and a signed-in client immediately completes X25519-encrypted device RPCs (ping→pong) against a paired desktop.Reviewer Notes
shared/included build needs its ownlocal.propertiesfor local builds; that file is gitignored and is not part of this PR.Checklist