What changed, and why it matters
This commit removes a Linux-specific workaround that manually loaded a bundled SQLite library and switches to a newer Flutter mechanism for copying native assets. It appears to be a build/packaging fix rather than a security patch. There is no indication in the commit that it addresses a security vulnerability.
No security action required. Treat as a routine build/maintenance fix. If reviewing for supply-chain risk, verify the new `sqlite3_flutter_libs` version and native-asset build behavior in CI.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch removes the direct dart:ffi and sqlite3/open.dart usage in cw_core/lib/db/sqlite.dart, eliminating a custom open.overrideFor(OperatingSystem.linux, ...) that loaded libsqlite3_flutter_libs_plugin.so with a fallback to libsqlite3.so.0. It also removes the sqlite3: 3.5.1 dependency from cw_core/pubspec.yaml and adds a CMake install step to copy native assets from native_assets/linux/ into the bundle. The change is consistent with migrating to sqlite3_flutter_libs’s newer build-time native asset handling. No security-relevant signals are present in the diff.
Changed components
cw_core/lib/db/sqlite.dartcw_core/pubspec.yamllinux/CMakeLists.txtInspect captured patch +6 / −17
diff --git a/cw_core/lib/db/sqlite.dart b/cw_core/lib/db/sqlite.dart
index 3e91f24a..07297449 100644
--- a/cw_core/lib/db/sqlite.dart
+++ b/cw_core/lib/db/sqlite.dart
@@ -1,4 +1,3 @@
-import 'dart:ffi';
import 'dart:io';
import 'package:cw_core/db/sqlite_debug.dart';
@@ -6,7 +5,6 @@ import 'package:cw_core/root_dir.dart';
import 'package:cw_core/utils/print_verbose.dart';
import 'package:flutter/foundation.dart';
import 'package:sqflite_common_ffi/sqflite_ffi.dart';
-import 'package:sqlite3/open.dart';
import 'package:path/path.dart' as p;
Database? db;
@@ -51,20 +49,6 @@ Future<void> initDb({String? pathOverride}) async {
Future<void> _initDb({String? pathOverride}) async {
if (Platform.isLinux || Platform.isWindows) {
- if (Platform.isLinux) {
- // The Linux bundle only installs the bundled sqlite3 shared object as
- // libsqlite3_flutter_libs_plugin.so (see linux/CMakeLists.txt); load it
- // directly instead of relying on a libsqlite3.so symlink, which the
- // release tarball dereferences into a second copy of the same library
- // and crashes the process when both copies get mapped.
- open.overrideFor(OperatingSystem.linux, () {
- try {
- return DynamicLibrary.open('libsqlite3_flutter_libs_plugin.so');
- } catch (_) {
- return DynamicLibrary.open('libsqlite3.so.0');
- }
- });
- }
databaseFactory = databaseFactoryFfi;
}
diff --git a/cw_core/pubspec.yaml b/cw_core/pubspec.yaml
index a5d49647..b7843f4b 100644
--- a/cw_core/pubspec.yaml
+++ b/cw_core/pubspec.yaml
@@ -47,7 +47,6 @@ dependencies:
bech32:
git:
url: https://github.com/cake-tech/bech32.git
- sqlite3: 3.5.1
sqlite3_flutter_libs: 0.5.40
dev_dependencies:
diff --git a/linux/CMakeLists.txt b/linux/CMakeLists.txt
index 7a45c054..e9769eae 100644
--- a/linux/CMakeLists.txt
+++ b/linux/CMakeLists.txt
@@ -160,6 +160,12 @@ foreach(bundled_library ${PLUGIN_BUNDLED_LIBRARIES})
COMPONENT Runtime)
endforeach(bundled_library)
+# Copy the native assets provided by the build.dart from all packages.
+set(NATIVE_ASSETS_DIR "${PROJECT_BUILD_DIR}native_assets/linux/")
+install(DIRECTORY "${NATIVE_ASSETS_DIR}"
+ DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
+ COMPONENT Runtime)
+
# Fully re-copy the assets directory on each build to avoid having stale files
# from a previous install.
set(FLUTTER_ASSET_DIR_NAME "flutter_assets")
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.