mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
ProGuard in the release DMG (compose-rules.pro) was keeping pt.davidafsilva.apple.** — a library no longer in the dependency graph. The actual macOS-keychain dependency is com.github.javakeyring:java-keyring, which reflection-loads its OS-specific backend (OSXKeychainBackend / SecretServiceBackend / WinCredentialStoreBackend) at Keyring.create() time. The shrinker stripped the backend classes, Keyring.create() threw BackendNotSupportedException on every cold boot, SecureKeyStorage's fallback silently returned null (no password prompt in a GUI cold-boot), and every account whose key lived in the OS keychain (nsec, NIP-46 bunker ephemeral, NWC secret) was forced back to the login screen on each launch of the release DMG. Dev/Gradle runs skip ProGuard, which is why this never surfaced in development. Primary fix: - Replace dead pt.davidafsilva.apple.** keep rules with com.github.javakeyring.** and keep native methods + constructors on internal.** backends. Defense in depth (so a future regression is visible, not silent): - AccountManager._keychainUnavailable: StateFlow<Boolean> mirrors the existing _storageCorruption / _forceLogoutReason channels. - loadInternalAccount / loadBunkerAccount raise the signal when accounts.json.enc points at a key the keychain cannot return. - LoginScreen shows a one-line error banner when the signal is set; cleared on any successful login. Tests: - AccountManagerLoadAccountTest gains four cases: Internal-no-privkey signals, Bunker-no-ephemeral signals, clearKeychainUnavailable resets, happy path does NOT signal. See docs/plans/2026-06-18-fix-desktop-macos-bunker-relogin-plan.md for brainstorm + plan + deferred follow-ups (Linux/Windows DMG verification, signed-DMG smoke test, ProGuard mapping regression guard). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>