From 6f4128c0f833ec5f3d74dc43a7c168ffc015f849 Mon Sep 17 00:00:00 2001 From: greenart7c3 Date: Fri, 4 Sep 2026 09:00:03 -0300 Subject: [PATCH] Fix offline SecurityException from WorkManager network tracking WorkManager's persisted work database and JobScheduler jobs survive an upgrade from the free flavor (shared applicationId). On startup, WorkManagerInitializer reschedules that stale network-constrained work, and WorkManager 2.11.2 tracks it via ConnectivityManager.registerDefaultNetworkCallback, which throws SecurityException because the offline flavor removes ACCESS_NETWORK_STATE. The flavor guards in Amber only prevent new enqueues and cannot stop this. WorkManager is unused in the offline flavor (all enqueues are flavor-guarded and ConnectivityService never starts), so strip all of its manifest components there: WorkManagerInitializer plus SystemJobService, SystemForegroundService, ForceStopRunnable receiver, RescheduleReceiver and DiagnosticsReceiver, which would otherwise crash via stale jobs or BOOT_COMPLETED after initialization is disabled. Also guard cancelBackupApplicationsAlarm (reachable from ApplicationsBackupScreen) with isOfflineFlavor like its siblings, and extend check-offline-permissions.yml to fail if WorkManagerInitializer or SystemJobService reappear in the offline merged manifest. --- .../workflows/check-offline-permissions.yml | 15 ++++++++ .../java/com/greenart7c3/nostrsigner/Amber.kt | 1 + app/src/offline/AndroidManifest.xml | 38 +++++++++++++++++++ 3 files changed, 54 insertions(+) diff --git a/.github/workflows/check-offline-permissions.yml b/.github/workflows/check-offline-permissions.yml index e506e290..66b01263 100644 --- a/.github/workflows/check-offline-permissions.yml +++ b/.github/workflows/check-offline-permissions.yml @@ -60,5 +60,20 @@ jobs: else echo "OK: No $PERMISSION in offline build manifest" fi + for COMPONENT in androidx.work.WorkManagerInitializer androidx.work.impl.background.systemjob.SystemJobService; do + if grep -q "$COMPONENT" "$MANIFEST"; then + echo "" + echo "ERROR: $COMPONENT found in offline build manifest!" + echo "WorkManager must never initialize in the offline flavor: it tracks" + echo "network-constrained work via ConnectivityManager, which crashes with" + echo "SecurityException because ACCESS_NETWORK_STATE is removed." + echo "" + echo "Offending lines:" + grep "$COMPONENT" "$MANIFEST" + FAILED=1 + else + echo "OK: No $COMPONENT in offline build manifest" + fi + done done exit $FAILED diff --git a/app/src/main/java/com/greenart7c3/nostrsigner/Amber.kt b/app/src/main/java/com/greenart7c3/nostrsigner/Amber.kt index 16af1eb5..5bd3fdc2 100644 --- a/app/src/main/java/com/greenart7c3/nostrsigner/Amber.kt +++ b/app/src/main/java/com/greenart7c3/nostrsigner/Amber.kt @@ -337,6 +337,7 @@ class Amber : } fun cancelBackupApplicationsAlarm() { + if (BuildFlavorChecker.isOfflineFlavor()) return WorkManager.getInstance(this).cancelUniqueWork("BackupApplicationsWorker") } diff --git a/app/src/offline/AndroidManifest.xml b/app/src/offline/AndroidManifest.xml index ba3a49c5..3c68176e 100644 --- a/app/src/offline/AndroidManifest.xml +++ b/app/src/offline/AndroidManifest.xml @@ -29,6 +29,44 @@ android:enabled="true" android:exported="true" /> + + + + + + + + + + + + + + +