Skip to content

fix(android): propagate deletion failures and reduce cipher allocation - #808

Open
OskarEichler wants to merge 1 commit into
oblador:masterfrom
OskarEichler:codex/keychain-android-cipher
Open

OskarEichler wants to merge 1 commit into
oblador:masterfrom
OskarEichler:codex/keychain-android-cipher

Conversation

@OskarEichler

@OskarEichler OskarEichler commented Aug 28, 2026 •

Copy link
Copy Markdown

Fixes and observable changes

  • Use a completion predicate around the condition wait: an early callback cannot lose its wakeup, and a spurious signal cannot publish an incomplete result.
  • Publish only the first terminal result; release the retained crypto context/prompt and shut down the per-operation callback executor. Late callbacks after shutdown are discarded.
  • Settle startup/activity errors, restore interrupted-thread state, and cancel a prompt created concurrently with terminal cancellation.
  • Make blocking encrypt/decrypt interruptible when the module coroutine is cancelled.
  • Retry the legacy OEM workaround only for its cancellation path, not user cancellation or lockout. Schedule its delay instead of sleeping on the callback executor; remove duplicate handler result fields and startup logic.
  • Observable correction: cancellation/startup errors settle instead of hanging or restarting authentication. Public API and ciphertext format are unchanged.

Verification

  • Eleven actual Kotlin handler checks pass for early completion, repeated completion, executor/context cleanup, spurious wakeup, interruption, UI startup failure, success, user cancellation, and cancellation during prompt creation. These run with real locks/threads and Android API doubles.
  • Six actual module-method/coroutine checks pass: encrypt/decrypt cancellation interrupts a blocked cipher while ordinary results are preserved. Both cancellation checks failed before.
  • Relevant checks pass on this PR alone over 6be201b.
  • Combined branch Android Debug builds pass for both architectures. No physical OEM biometric matrix or Android E2E pass is claimed; checked-in tests are unchanged.

This does not change biometric strength, authentication freshness, key validity windows, or CryptoObject binding (#788/#798). Android itself has pre-API-29 credential-cancellation limitations; this patch does not claim to remove those.

Consumer integration

  • The combined runtime fixes are backported onto released 10.0.0 at immutable artifact dbd32b5, preserving its bridge/error-code and StrongBox policies. Example/tooling-only changes are not shipped in that runtime artifact.
  • On RN 0.87.1, immutable install, lint, both Android Debug products, both unsigned iOS Simulator Debug products, all four production Metro bundles, 13 web targets and four browser extensions pass. All installed package files were verified against the artifact. These are combined-backport integration results, not independent device validation of this PR.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant