Commit Graph
3 Commits
Author SHA1 Message Date
iris 90a77386dc Record that the local-network permission survives the tunnel
Android's Local Network Definition says a local network "excludes
cellular (WWAN) or VPN connections", which reads as: an app reaching its
server through WireGuard needs no ACCESS_LOCAL_NETWORK. Both projects
reach their server through WireGuard, so both had a reason to delete it.

Measured on a real device on 2026-08-28: the permission is still
required, and without it the traffic is dropped. The documented exclusion
does not hold for a tun carrying an RFC1918 destination.

The note goes here because this is the one function a person would read
before removing the permission, and because neither project can find this
out for itself -- the API 36 emulator images both are tested against do
not enforce the permission at all, so removing it passes every test
available locally and fails only on the phone.
2026-08-28 18:19:32 -04:00
iris 4de8bff5f2 Ignore the app half's build outputs, which the last commit added
.gitignore covered the Rust half's target/ only, so `git add -A` swept in
about 190 files of Gradle intermediates -- caches, lint models, .class and
.dex files. Removed from tracking and ignored, in a new commit rather than
by rewriting what was already pushed.
2026-08-28 17:57:18 -04:00
iris 4e423bbfb0 Take the app half too, which was duplicated the same way
Four Kotlin files appeared in both apps. Diffed with the product names
normalised, EnrollmentScanActivity was 31 lines each differing in six --
all of them comments -- and PinnedCert was 58 against 59 with identical
TrustManager logic. That is the same evidence that moved the Rust half.

Two parameters, both per-app, and they fail differently. A wrong URI
scheme means a scanned QR is ignored, which is visible at once. A wrong
Keystore alias means the app cannot unseal the token it already stored,
so an enrolled phone reads as not enrolled and nothing says why -- so
both existing values are recorded in the README rather than left to be
rediscovered.

The certificate alias went the other way and became a constant: it names
an entry in a KeyStore that exists only in memory for the length of one
lazy block, so nothing ever reads it back and having two of them said
nothing.

The drift was in both directions, as the evidence predicted: ai-app had
gained localNetworkAllowed -- which matters because Android 17's
ACCESS_LOCAL_NETWORK denial is invisible at the socket, and without it a
blocked app and an unreachable server produce the same timeout -- and had
moved to the KTX `edit` block. dev-updater had neither, and gets both.

No Compose, deliberately. Nothing here draws anything; the screens are
each app's own because that is where the two products actually differ.

The PinnedCaCertificate generator did not move, and the README says why:
all three things it varies are per-app, so sharing it means a composite
build neither project has. Its one historical bug is already fixed
identically in both copies.
2026-08-28 17:57:07 -04:00