From 9cc70e9111e85027ef8918554936ff88b18df631 Mon Sep 17 00:00:00 2001 From: Alexander Gil Casas Date: Wed, 23 Sep 2026 17:40:05 +0200 Subject: [PATCH] fix: address v1.23 settings and EC SSH regressions --- .../java/app/passwordstore/ui/settings/PGPSettings.kt | 10 +++++++++- .../java/app/passwordstore/util/git/sshj/SshKey.kt | 6 ++++-- 2 files changed, 13 insertions(+), 3 deletions(-) diff --git a/app/src/main/java/app/passwordstore/ui/settings/PGPSettings.kt b/app/src/main/java/app/passwordstore/ui/settings/PGPSettings.kt index 64b57b51ee..f60ed0762a 100644 --- a/app/src/main/java/app/passwordstore/ui/settings/PGPSettings.kt +++ b/app/src/main/java/app/passwordstore/ui/settings/PGPSettings.kt @@ -24,7 +24,15 @@ import kotlinx.coroutines.launch class PGPSettings(private val activity: FragmentActivity) : SettingsProvider { - private val backend = OpenPgpApiBackend(activity.applicationContext) + // Keep the optional OpenPGP API implementation out of the SettingsActivity startup path. A + // broken or unavailable provider integration must not make the entire settings screen unusable. + private val backend by + lazy(LazyThreadSafetyMode.NONE) { + OpenPgpApiBackend(activity.applicationContext) + } + + // Activity Result launchers must be registered before the activity reaches STARTED, so this + // bridge remains eager even though the OpenPGP backend itself is initialized on demand. private val interactionHandler = OpenPgpActivityInteractionHandler(activity) override fun provideSettings(builder: PreferenceScreen.Builder) { diff --git a/app/src/main/java/app/passwordstore/util/git/sshj/SshKey.kt b/app/src/main/java/app/passwordstore/util/git/sshj/SshKey.kt index 122e751d77..4c3d24f000 100644 --- a/app/src/main/java/app/passwordstore/util/git/sshj/SshKey.kt +++ b/app/src/main/java/app/passwordstore/util/git/sshj/SshKey.kt @@ -382,9 +382,11 @@ object SshKey { val publicKey = androidKeystore.sshPublicKey ?: throw NullPointerException() val privateKey = androidKeystore.sshPrivateKey ?: throw NullPointerException() - // let Keystore do cryptographic operations - SecurityUtils.setRegisterBouncyCastle(false) + // SSHJ 0.41.1 resets the BouncyCastle registration mode when its configured provider is + // cleared. Clear the provider first, then explicitly disable BC so Android Keystore-backed + // private keys are signed by the platform provider without requiring an exportable encoding. SecurityUtils.setSecurityProvider(null) + SecurityUtils.setRegisterBouncyCastle(false) client.loadKeys(KeyPair(publicKey, privateKey)) }