Files
Amber/app
greenart7c3 313396559e Close clearnet leak for Tor users during the startup settings race
Profile fetches and boot-time network callbacks could dial relays
directly before the async settings load finished: Amber.settings
starts as the data-class default (torMode = DISABLED), so the relay
and Coil factories read 'Tor off' and picked the direct OkHttp
client. The fail-closed SOCKS placeholder never got consulted. Seen
in adb logs: kind-0 profile REQs went out over clearnet TLS a full
ten seconds before the built-in Tor SOCKS port existed.

Fix, at the factory decision point:

- Preset the proxy synchronously from plain prefs in
  Application.onCreate: ORBOT gets the configured port, BUILTIN the
  fail-closed placeholder (SOCKS 127.0.0.1:<dynamic>, refused until
  Tor binds), DISABLED stays direct.
- Add Amber.isSettingsLoaded, set when reloadApp() assigns the
  loaded settings. Until then both factories route through the
  proxy client instead of trusting the DISABLED default, so early
  dials (network callbacks, NotificationSubscription /
  ProfileSubscription / BunkerRequestUtils) hit the placeholder and
  retry rather than leak.

Verified on device: cold start with BUILTIN Tor shows pre-Tor dials
refused and every profile REQ flowing after the SOCKS port comes up.
2026-09-14 09:57:50 -03:00
..
2024-03-01 06:56:32 -03:00
2023-07-26 16:44:33 -03:00
2026-09-09 19:06:54 -03:00