* Decompile and recreate Soul Browser v1.4.85 with APK CI builds Co-authored-by: KaKi87 <KaKi87@pm.me> * Fix CI build: include bundled google.jks and remove PR trigger The apktool build failed in CI because app/unknown/.../google.jks was excluded by the *.jks gitignore rule. Whitelist app-bundled JKS files and commit the missing resource. Also remove the redundant pull_request workflow trigger. Co-authored-by: KaKi87 <KaKi87@pm.me> * Change package ID to com.github.kaki87.soulbrowser Rename the application ID so the rebuilt APK can be installed alongside the original Soul Browser from Google Play. - Update AndroidManifest package, permissions, providers, and actions - Update R class references in smali (com/github/kaki87/soulbrowser/R) - Update shortcuts.xml targetPackage - Rename app label to "Soul Rebuild" for easy identification Co-authored-by: KaKi87 <KaKi87@pm.me> * Fix install compatibility: remove split APK metadata and bundle native libs The rebuilt APK still declared requiredSplitTypes and Play Store split metadata, causing Android to reject standalone installs as incompatible. - Remove requiredSplitTypes and split-related manifest meta-data - Merge native libs from all ABI splits with uncompressed storage - Page-align before signing for extractNativeLibs=false - Add .so to apktool doNotCompress list Co-authored-by: KaKi87 <KaKi87@pm.me> * Fix install failure: use apksigner v2/v3 and bundle arm64 native libs Target SDK 36 requires APK Signature Scheme v2+, but jarsigner only produces v1 signatures, causing Android to reject the install. - Sign with apksigner (v1+v2+v3) instead of jarsigner - Add arm64-v8a native libraries from universal Soul Browser 1.4.79 - Set extractNativeLibs=true for reliable sideload installs - Commit stable debug keystore for consistent signatures across builds Co-authored-by: KaKi87 <KaKi87@pm.me> * Add committed debug keystore for consistent APK signatures Co-authored-by: KaKi87 <KaKi87@pm.me> * Fix startup crash: use original classes2.dex desugar libraries Apktool recompiles smali_classes2 into a broken classes2.dex, causing ClassNotFoundException for j$.com.android.tools.r8.a at ML Kit init. Inject the original classes2.dex (Java 8+ desugar libs) after apktool build instead of using the recompiled version. Co-authored-by: KaKi87 <KaKi87@pm.me> * Fix missing drawable resources from density split APKs The base APK is an app bundle module; density-specific drawables like seek_thumb_nor_b live in config.xhdpi.apk and were missing after rebuild, causing Resources$NotFoundException at runtime. - Merge non-9-patch resources from split APKs before apktool build - Sync public.xml IDs from R smali only when backing files exist - Add 713 density-specific resource IDs to public.xml Co-authored-by: KaKi87 <KaKi87@pm.me> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
101 lines
4.7 KiB
Java
101 lines
4.7 KiB
Java
package okhttp3.internal.tls;
|
|
|
|
import com.google.android.gms.ads.RequestConfiguration;
|
|
import java.security.GeneralSecurityException;
|
|
import java.security.cert.X509Certificate;
|
|
import java.util.ArrayDeque;
|
|
import java.util.ArrayList;
|
|
import java.util.Iterator;
|
|
import java.util.List;
|
|
import javax.net.ssl.SSLPeerUnverifiedException;
|
|
import kotlin.Metadata;
|
|
import kotlin.jvm.internal.Intrinsics;
|
|
|
|
@Metadata(d1 = {"\u0000\f\n\u0002\u0018\u0002\n\u0002\u0018\u0002\n\u0002\b\u0002\u0018\u00002\u00020\u0001:\u0001\u0002¨\u0006\u0003"}, d2 = {"Lokhttp3/internal/tls/BasicCertificateChainCleaner;", "Lokhttp3/internal/tls/CertificateChainCleaner;", "Companion", "okhttp"}, k = 1, mv = {2, 2, 0}, xi = 48)
|
|
/* loaded from: classes4.dex */
|
|
public final class BasicCertificateChainCleaner extends CertificateChainCleaner {
|
|
|
|
/* renamed from: a, reason: collision with root package name */
|
|
public final TrustRootIndex f22188a;
|
|
|
|
@Metadata(d1 = {"\u0000\u0010\n\u0002\u0018\u0002\n\u0002\u0010\u0000\n\u0002\u0010\b\n\u0002\b\u0003\b\u0086\u0003\u0018\u00002\u00020\u0001R\u0014\u0010\u0003\u001a\u00020\u00028\u0002X\u0082T¢\u0006\u0006\n\u0004\b\u0003\u0010\u0004¨\u0006\u0005"}, d2 = {"Lokhttp3/internal/tls/BasicCertificateChainCleaner$Companion;", RequestConfiguration.MAX_AD_CONTENT_RATING_UNSPECIFIED, RequestConfiguration.MAX_AD_CONTENT_RATING_UNSPECIFIED, "MAX_SIGNERS", "I", "okhttp"}, k = 1, mv = {2, 2, 0}, xi = 48)
|
|
/* loaded from: classes4.dex */
|
|
public static final class Companion {
|
|
}
|
|
|
|
public BasicCertificateChainCleaner(TrustRootIndex trustRootIndex) {
|
|
Intrinsics.checkNotNullParameter(trustRootIndex, "trustRootIndex");
|
|
this.f22188a = trustRootIndex;
|
|
}
|
|
|
|
public static boolean b(X509Certificate x509Certificate, X509Certificate x509Certificate2, int i) {
|
|
if (Intrinsics.areEqual(x509Certificate.getIssuerDN(), x509Certificate2.getSubjectDN()) && x509Certificate2.getBasicConstraints() >= i) {
|
|
try {
|
|
x509Certificate.verify(x509Certificate2.getPublicKey());
|
|
return true;
|
|
} catch (GeneralSecurityException unused) {
|
|
return false;
|
|
}
|
|
}
|
|
return false;
|
|
}
|
|
|
|
@Override // okhttp3.internal.tls.CertificateChainCleaner
|
|
public final List a(String hostname, List chain) {
|
|
Intrinsics.checkNotNullParameter(chain, "chain");
|
|
Intrinsics.checkNotNullParameter(hostname, "hostname");
|
|
ArrayDeque arrayDeque = new ArrayDeque(chain);
|
|
ArrayList arrayList = new ArrayList();
|
|
Object removeFirst = arrayDeque.removeFirst();
|
|
Intrinsics.checkNotNullExpressionValue(removeFirst, "removeFirst(...)");
|
|
arrayList.add(removeFirst);
|
|
boolean z = false;
|
|
for (int i = 0; i < 9; i++) {
|
|
Object obj = arrayList.get(arrayList.size() - 1);
|
|
Intrinsics.checkNotNull(obj, "null cannot be cast to non-null type java.security.cert.X509Certificate");
|
|
X509Certificate x509Certificate = (X509Certificate) obj;
|
|
X509Certificate a2 = this.f22188a.a(x509Certificate);
|
|
if (a2 != null) {
|
|
if (arrayList.size() > 1 || !Intrinsics.areEqual(x509Certificate, a2)) {
|
|
arrayList.add(a2);
|
|
}
|
|
if (!b(a2, a2, arrayList.size() - 2)) {
|
|
z = true;
|
|
} else {
|
|
return arrayList;
|
|
}
|
|
} else {
|
|
Iterator it = arrayDeque.iterator();
|
|
Intrinsics.checkNotNullExpressionValue(it, "iterator(...)");
|
|
while (it.hasNext()) {
|
|
Object next = it.next();
|
|
Intrinsics.checkNotNull(next, "null cannot be cast to non-null type java.security.cert.X509Certificate");
|
|
X509Certificate x509Certificate2 = (X509Certificate) next;
|
|
if (b(x509Certificate, x509Certificate2, arrayList.size() - 1)) {
|
|
it.remove();
|
|
arrayList.add(x509Certificate2);
|
|
}
|
|
}
|
|
if (!z) {
|
|
throw new SSLPeerUnverifiedException("Failed to find a trusted cert that signed " + x509Certificate);
|
|
}
|
|
return arrayList;
|
|
}
|
|
}
|
|
throw new SSLPeerUnverifiedException("Certificate chain too long: " + arrayList);
|
|
}
|
|
|
|
public final boolean equals(Object obj) {
|
|
if (obj == this) {
|
|
return true;
|
|
}
|
|
if ((obj instanceof BasicCertificateChainCleaner) && Intrinsics.areEqual(((BasicCertificateChainCleaner) obj).f22188a, this.f22188a)) {
|
|
return true;
|
|
}
|
|
return false;
|
|
}
|
|
|
|
public final int hashCode() {
|
|
return this.f22188a.hashCode();
|
|
}
|
|
}
|