feat(android): opt into ARM Memory Tagging Extension (async)

Declare android:memtagMode on the application so devices with MTE
enabled (Pixel 8+ with the developer toggle or Advanced Protection,
GrapheneOS) tag-check our native code: WebRTC, zxing-cpp, bundled
SQLite, secp256k1 and Arti. Release and benchmark builds use async,
the low-overhead production mode; debug uses sync so a tag fault
crashes at the exact faulting access. The attribute is ignored on
devices without MTE and below API 31.

Closes #4196

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TUQgtrHcA21Npt8ajDjWYC
This commit is contained in:
Claude
2026-09-27 16:27:13 +00:00
parent c3ca872ae5
commit b8dad13265
2 changed files with 8 additions and 0 deletions
+7
View File
@@ -140,6 +140,12 @@ android {
buildConfigField("String", "RELEASE_NOTES_ID", "\"f7914e7a7e293988485439eb2bea29c09c388d54c452c4a19f89e106dbf1969e\"")
testInstrumentationRunner = "androidx.test.runner.AndroidJUnitRunner"
// ARM Memory Tagging Extension for our native code (WebRTC, zxing-cpp, SQLite,
// secp256k1, Arti). Async is the low-overhead production mode; debug overrides
// it to sync so a tag fault crashes at the exact faulting access. Ignored on
// devices without MTE hardware or with it switched off.
manifestPlaceholders["memtagMode"] = "async"
vectorDrawables {
useSupportLibrary = true
}
@@ -267,6 +273,7 @@ android {
applicationIdSuffix = ".debug"
versionNameSuffix = "-DEBUG"
resValue("string", "app_name", "@string/app_name_debug")
manifestPlaceholders["memtagMode"] = "sync"
}
create("benchmark") {
initWith(getByName("release"))
+1
View File
@@ -184,6 +184,7 @@
android:networkSecurityConfig="@xml/network_security_config"
android:hardwareAccelerated="true"
android:localeConfig="@xml/locales_config"
android:memtagMode="${memtagMode}"
tools:targetApi="34">
<activity
android:name=".ui.MainActivity"