proomt

Search

Search posts, papers, and topics

All posts

CodeName OneShai Almog6 min readintermediate

App Hardening: One Obfuscation Pipeline Across Every Port

Summary

Codename One adds a cloud‑side hardening step that runs on the merged JAR before it is split into Android, iOS, JavaScript, and desktop binaries. It can rename symbols, encrypt string literals, and insert opaque‑predicate control‑flow guards at configurable levels (off → standard → aggressive → paranoid). The transforms are selective per platform to avoid breaking optimizers, and a mapping is kep…

  • Hardening is a single, cloud‑side transform applied to the merged JAR, ensuring consistent protection across all target platforms.
  • Four configurable levels let teams trade off size and analysis cost against protection; the default `standard` only renames symbols and encrypts constant strings.
  • Platform‑specific exclusions (e.g., Android uses R8 for renaming, JavaScript skips string encryption) prevent optimizer breakage and binary bloat.
  • A server‑stored mapping enables automatic retracing of obfuscated stack traces, keeping crash reports usable.

Cross‑platform apps often protect only Android binaries, leaving iOS, web, and desktop artifacts exposed. A unified hardening pipeline raises the bar for reverse engineering on every shipped artifact without requiring separate toolchains per platform, and it preserves operational visibility through…

6/10

Related reading

  1. VoIP, VPN, and the Build System Behind Them

    Codename One’s new builder pipeline can automatically generate the native plumbing required for VoIP call integration, managed VPN profiles, and packet‑tunnel extensions on iOS and Android. By inspecting which Java packages an app imports, the builder adds the necessary frameworks, entitlements, services, and even a separate signed Network Extension for iOS, letting developers keep their signalin…

    CodeName Onecodenameone.com10 min
  2. SQLite Across Every Port: One Contract, One Encrypted File Format

    Codename One now ships a single, tested SQLite contract that works natively on Android, iOS, Windows, Linux, and in browsers via WebAssembly, with built‑in SQLCipher‑4 encryption supporting three key models. A conformance suite guarantees identical behavior across platforms, and migration helpers let legacy apps opt‑in. The update also adds a proper watch‑app model, DOM‑based text for JavaScript,…

    CodeName Onecodenameone.com11 min
  3. App Intents: One Java Declaration for Siri, Spotlight, and Shortcuts

    Codename One adds @AppIntent annotations that let a static Java method be exposed as a Siri, Spotlight, or Android shortcut. The build‑time processor generates native declarations, a reflection‑free dispatch table, and validates the intent metadata. Handlers can be headless, accept typed parameters, return results, and be invoked internally via Intents.invoke(). Entities enable system‑driven disa…

    CodeName Onecodenameone.com5 min
  4. Why Codename One Is Moving Beyond Maven Central

    Codename One is moving its Maven artifacts from Sonatype’s Maven Central to a self‑hosted Cloudflare R2 bucket. Phase 1 reduces release payloads (from 229 MB to 77 MB) by dropping fat‑JARs and freezing stable deps, adds dual‑publish, and updates generated POMs to include a custom repository for both dependencies and plugins. After a three‑week observation window (ending Aug 28 2026) new releases…

    CodeName Onecodenameone.com7 min
  5. Android 17 Without the Last-Minute Scramble

    CodeName One prepared for Android 17 (API 37) by addressing platform changes proactively, including fixing version number parsing and implementing the new system-rendered location button. They also added robust PEM key parsing and explicit task removal to simplify common security operations for app developers.

    CodeName Onecodenameone.com8 min