mirror of
https://github.com/meshtastic/Meshtastic-Android.git
synced 2026-09-15 14:48:34 -04:00
Room 3.0.2 + androidx.sqlite:sqlite-web:2.7.0's WebWorkerSQLiteDriver, backed by real
SQLite compiled to WASM (@sqlite.org/sqlite-wasm) running in a dedicated Web Worker
(core/database/worker/{package.json,worker.js}), persisting via OPFS -- same shape
already proven end-to-end this session (insert survives a full page reload) against
the upstream danysantiago/room-web-demo reference. Uses the same nonWebMain
hierarchy-split pattern already proven for core:ble.
DatabaseManager (multi-device switching, legacy-DB migration, cross-transport merge)
is built entirely on DatabaseDataStore (a DataStore<Preferences> wrapper), and
androidx.datastore.preferences has zero wasmJs variant at any published version --
not a temporary gap, the Preferences type itself doesn't resolve for that target. That
whole orchestrator is out of scope for a web client (no BLE/USB device-switching story
exists there), so it moves to nonWebMain unchanged, alongside DatabaseDataStore and its
Koin module. wasmJs gets a new SingleDatabaseProvider: one real, persistent,
non-switching MeshtasticDatabase, nothing to switch between.
BusyTimeoutSQLiteDriver turned out not to be platform-neutral as originally assumed:
androidx.sqlite.SQLiteDriver.open() is suspend on androidx.sqlite's own webMain branch,
non-suspend everywhere else (confirmed from androidx.sqlite:sqlite:2.7.0's own
sources) -- split into two independent, identically-shaped classes rather than one
shared implementation, since the suspend-modifier difference means actual can't
paper over it (same "disjoint compilations" shape as core:ble's
BleServiceExtensions.kt).
getInMemoryDatabaseBuilder()/getDatabaseDirectory()/deleteDatabase()/getFileSystem()
fail loudly or return best-effort placeholders on wasmJs -- confirmed via grep that
their only real caller, DatabaseManager, lives entirely in nonWebMain now, so nothing
wasmJs-reachable needs them to do anything real. Same "fail loudly, don't silently
return wrong data" precedent as core:resources' getString().
androidApp/desktopApp needed a small, necessary addition: registering the new
CoreDatabaseNonWebModule alongside the existing CoreDatabaseModule, since without it
neither platform would have a DatabaseDataStore Koin binding anymore.
Verified independently twice: compileKotlinWasmJs/compileTestKotlinWasmJs pass;
full regression (android/jvm/iOS compiles, allTests -- with the ~21 moved
DatabaseManager*/DAO tests confirmed actually executing via real test-report output,
not just exit code) passes; androidApp and desktopApp both compile clean with the new
DI wiring; detekt/spotlessCheck clean across core:database and both app modules. No
real browser round-trip test was run against this exact worker.js (accepted as a
stretch goal, not required for this pass).
:core:database
This module provides the local Room database persistence layer for the application using Room Kotlin Multiplatform (KMP).
Key Components
MeshtasticDatabase: The main Room database class, defined incommonMain.- DAOs (Data Access Objects):
NodeInfoDao: Manages storage and retrieval of node information (NodeEntity). Contains critical logic for handling Public Key Conflict (PKC) resolution and preventing identity wiping attacks.PacketDao: Handles storage of mesh packets, including text messages, waypoints, and reactions.
- Entities:
NodeEntity: Represents a node on the mesh.Packet: Represents a stored packet.ReactionEntity: Represents emoji reactions to packets.
Security Considerations
Public Key Conflict (PKC) Handling
The NodeInfoDao implements specific logic to protect against impersonation and "wipe" attacks:
- Wipe Protection: Receiving an
is_licensed=truepacket (which normally clears the public key for compliance) will not clear an existing valid public key if one is already known. This prevents attackers from sending fake licensed packets to wipe keys from the DB. - Conflict Detection: If a new key arrives for an existing node ID that conflicts with a known valid key, the key is set to
ERROR_BYTE_STRINGto flag the potential impersonation.
Dependency Graph
graph TB
:core:database[database]:::kmp-library
:core:database --> :core:common
:core:database --> :core:model
:core:database -.-> :core:di
:core:database -.-> :core:resources
:core:database -.-> :core:testing
classDef android-application fill:#CAFFBF,stroke:#000,stroke-width:2px,color:#000;
classDef android-application-compose fill:#CAFFBF,stroke:#000,stroke-width:2px,color:#000;
classDef compose-desktop-application fill:#CAFFBF,stroke:#000,stroke-width:2px,color:#000;
classDef android-feature fill:#FFD6A5,stroke:#000,stroke-width:2px,color:#000;
classDef android-library fill:#9BF6FF,stroke:#000,stroke-width:2px,color:#000;
classDef android-library-compose fill:#9BF6FF,stroke:#000,stroke-width:2px,color:#000;
classDef android-test fill:#A0C4FF,stroke:#000,stroke-width:2px,color:#000;
classDef jvm-library fill:#BDB2FF,stroke:#000,stroke-width:2px,color:#000;
classDef kmp-feature fill:#FFD6A5,stroke:#000,stroke-width:2px,color:#000;
classDef kmp-library-compose fill:#FFC1CC,stroke:#000,stroke-width:2px,color:#000;
classDef kmp-library fill:#FFC1CC,stroke:#000,stroke-width:2px,color:#000;
classDef unknown fill:#FFADAD,stroke:#000,stroke-width:2px,color:#000;