fix: complete android jmap release hardening #15

Merged
ober merged 5 commits from fix/android-local-download-origin into main 2026-08-11 10:37:07 -04:00
Owner

Summary

  • Rewrite Android loopback JMAP download/blob origins to the configured server origin in foreground sync and background worker paths.
  • Harden the Android release APK build so signed releases always rebuild the JNI with JSMTP_STORE_PRIVATE_KEY, require the packaged first-run config asset, and verify the signed APK contains both the config and native library.
  • Advertise the JMAP vendor capability from the Android client and prefer StrongBox-backed Keystore keys with fallback on devices/emulators without StrongBox.
  • Bump repository version to 0.2.6 and refresh the tracked jjmapd binary.

Verification

  • make verify
  • make release-verify
  • ./jjmapd version and env -i PATH="$PATH" ./jjmapd version
  • Built signed keyed release APK through support/android/build-release-apk.sh; script verified packaged assets/jjmap-debug-config.json and lib/arm64-v8a/libjjmap_android.so.
  • Installed the exact signed APK in the API 35 jjmap_api35_test emulator from a clean app state.
  • Verified emulator reachability to 10.66.60.1:8443, saved bundled config, authenticated as ober@mauthesis.com, fetched inbox state, and displayed decrypted message bodies.
  • Logcat scan found no app crash, TLS, fetch, StrongBox, or decrypt failure lines after the successful fetch.
  • Uploaded the tested APK to Termux: /data/data/com.termux/files/home/jerboa-mail-0.2.6-release-signed.apk.
  • APK SHA256: 91a8cae4c4a0c696f085144ecb99fc64df36e8adbf97ecd348e321bc0fbe918d.
## Summary - Rewrite Android loopback JMAP download/blob origins to the configured server origin in foreground sync and background worker paths. - Harden the Android release APK build so signed releases always rebuild the JNI with `JSMTP_STORE_PRIVATE_KEY`, require the packaged first-run config asset, and verify the signed APK contains both the config and native library. - Advertise the JMAP vendor capability from the Android client and prefer StrongBox-backed Keystore keys with fallback on devices/emulators without StrongBox. - Bump repository version to 0.2.6 and refresh the tracked `jjmapd` binary. ## Verification - `make verify` - `make release-verify` - `./jjmapd version` and `env -i PATH="$PATH" ./jjmapd version` - Built signed keyed release APK through `support/android/build-release-apk.sh`; script verified packaged `assets/jjmap-debug-config.json` and `lib/arm64-v8a/libjjmap_android.so`. - Installed the exact signed APK in the API 35 `jjmap_api35_test` emulator from a clean app state. - Verified emulator reachability to `10.66.60.1:8443`, saved bundled config, authenticated as `ober@mauthesis.com`, fetched inbox state, and displayed decrypted message bodies. - Logcat scan found no app crash, TLS, fetch, StrongBox, or decrypt failure lines after the successful fetch. - Uploaded the tested APK to Termux: `/data/data/com.termux/files/home/jerboa-mail-0.2.6-release-signed.apk`. - APK SHA256: `91a8cae4c4a0c696f085144ecb99fc64df36e8adbf97ecd348e321bc0fbe918d`.
chore: bump version for android download origin fix
All checks were successful
version-policy / required (pull_request) Successful in 7s
required-ci / required (pull_request) Successful in 7m43s
70ab6bb728
Author
Owner

Closing because the active scope requires one final PR only after the full kimi requirement audit, implementation, and verification are complete.

Closing because the active scope requires one final PR only after the full kimi requirement audit, implementation, and verification are complete.
ober changed title from fix: rewrite local jmap download origins for android to fix: complete android jmap release hardening 2026-08-11 00:12:46 -04:00
docs: align android sync gate with implementation
All checks were successful
version-policy / required (pull_request) Successful in 7s
required-ci / required (pull_request) Successful in 9m30s
50959d29d7
ober scheduled this pull request to auto merge when all checks succeed 2026-08-11 10:36:41 -04:00
ober merged commit 3ef7a7560d into main 2026-08-11 10:37:07 -04:00
ober referenced this pull request from a commit 2026-08-11 10:37:08 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-jmap!15
No description provided.