From b8dad13265a5719f08084aef5bf8444966567d4d Mon Sep 17 00:00:00 2001 From: Claude Date: Sun, 27 Sep 2026 16:27:13 +0000 Subject: [PATCH] feat(android): opt into ARM Memory Tagging Extension (async) Declare android:memtagMode on the application so devices with MTE enabled (Pixel 8+ with the developer toggle or Advanced Protection, GrapheneOS) tag-check our native code: WebRTC, zxing-cpp, bundled SQLite, secp256k1 and Arti. Release and benchmark builds use async, the low-overhead production mode; debug uses sync so a tag fault crashes at the exact faulting access. The attribute is ignored on devices without MTE and below API 31. Closes #4196 Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01TUQgtrHcA21Npt8ajDjWYC --- amethyst/build.gradle.kts | 7 +++++++ amethyst/src/main/AndroidManifest.xml | 1 + 2 files changed, 8 insertions(+) diff --git a/amethyst/build.gradle.kts b/amethyst/build.gradle.kts index 1f432394be..432eac5d92 100644 --- a/amethyst/build.gradle.kts +++ b/amethyst/build.gradle.kts @@ -140,6 +140,12 @@ android { buildConfigField("String", "RELEASE_NOTES_ID", "\"f7914e7a7e293988485439eb2bea29c09c388d54c452c4a19f89e106dbf1969e\"") testInstrumentationRunner = "androidx.test.runner.AndroidJUnitRunner" + + // ARM Memory Tagging Extension for our native code (WebRTC, zxing-cpp, SQLite, + // secp256k1, Arti). Async is the low-overhead production mode; debug overrides + // it to sync so a tag fault crashes at the exact faulting access. Ignored on + // devices without MTE hardware or with it switched off. + manifestPlaceholders["memtagMode"] = "async" vectorDrawables { useSupportLibrary = true } @@ -267,6 +273,7 @@ android { applicationIdSuffix = ".debug" versionNameSuffix = "-DEBUG" resValue("string", "app_name", "@string/app_name_debug") + manifestPlaceholders["memtagMode"] = "sync" } create("benchmark") { initWith(getByName("release")) diff --git a/amethyst/src/main/AndroidManifest.xml b/amethyst/src/main/AndroidManifest.xml index d2b9dabc65..91acb98039 100644 --- a/amethyst/src/main/AndroidManifest.xml +++ b/amethyst/src/main/AndroidManifest.xml @@ -184,6 +184,7 @@ android:networkSecurityConfig="@xml/network_security_config" android:hardwareAccelerated="true" android:localeConfig="@xml/locales_config" + android:memtagMode="${memtagMode}" tools:targetApi="34">