depends: protobuf: don't use android system logging
What changed, and why it matters
This commit changes how Monero's build system handles the protobuf library on Android. It disables protobuf's use of Android's system logging and stops linking the Android 'log' library when building through the project's dependency system. The change appears to be a build-system hardening or compatibility fix, not a patch for an active security vulnerability. There is no direct evidence in the commit that this fixes an exploitable bug.
Treat as a build-system maintenance and hardening change. Review whether any runtime protobuf logging paths on Android could still leak sensitive data, and verify that disabling Android logging does not suppress important diagnostic output needed for debugging Trezor integration. No urgent security response is indicated based on the commit alone.
Security signals we found
Build system hardening: removes Android system logging linkage from dependency build
Third-party dependency patching: modifies protobuf behavior specifically for Android builds
Potential privacy hygiene: disables Android log output from protobuf internals, which could reduce sensitive data exposure to system logs on Android
No explicit security claim, CVE, or vulnerability description in commit message or diff
Evidence from the diff
The patch adds a new protobuf patch file (no-android-logging.patch) that replaces two #if defined(__ANDROID__) preprocessor checks in src/google/protobuf/stubs/common.cc with #if 0, effectively disabling Android-specific log output via __android_log_write. It also modifies src/device_trezor/CMakeLists.txt so that the log library is only linked when building for Android outside of the depends build system. This prevents the dependency build from requiring Android system logging libraries and avoids a build-time/link-time dependency on Android’s log subsystem for the Trezor device code.
Changed components
contrib/depends/packages/protobuf.mkcontrib/depends/patches/protobuf/no-android-logging.patchsrc/device_trezor/CMakeLists.txtAndroid builds using the depends build systemTrezor device integration on AndroidInspect captured patch +28 / −1
diff --git a/contrib/depends/packages/protobuf.mk b/contrib/depends/packages/protobuf.mk
index 8525749..ee97b67 100644
--- a/contrib/depends/packages/protobuf.mk
+++ b/contrib/depends/packages/protobuf.mk
@@ -5,6 +5,7 @@ $(package)_download_path=$(native_$(package)_download_path)
$(package)_file_name=$(native_$(package)_file_name)
$(package)_sha256_hash=$(native_$(package)_sha256_hash)
$(package)_dependencies=native_$(package)
+$(package)_patches=no-android-logging.patch
define $(package)_set_vars
$(package)_config_opts=--disable-shared --with-protoc=$(build_prefix)/bin/protoc
@@ -15,6 +16,10 @@ define $(package)_config_cmds
$($(package)_autoconf) AR_FLAGS=$($(package)_arflags)
endef
+define $(package)_preprocess_cmds
+ patch -p1 < $($(package)_patch_dir)/no-android-logging.patch
+endef
+
define $(package)_build_cmds
$(MAKE) -C src libprotobuf.la
endef
diff --git a/contrib/depends/patches/protobuf/no-android-logging.patch b/contrib/depends/patches/protobuf/no-android-logging.patch
new file mode 100644
index 0000000..fce2a8f
--- /dev/null
+++ b/contrib/depends/patches/protobuf/no-android-logging.patch
@@ -0,0 +1,22 @@
+diff --git a/src/google/protobuf/stubs/common.cc b/src/google/protobuf/stubs/common.cc
+index e0a807f..7f2e7e7 100644
+--- a/src/google/protobuf/stubs/common.cc
++++ b/src/google/protobuf/stubs/common.cc
+@@ -45,7 +45,7 @@
+ #include <windows.h>
+ #define snprintf _snprintf // see comment in strutil.cc
+ #endif
+-#if defined(__ANDROID__)
++#if 0
+ #include <android/log.h>
+ #endif
+
+@@ -121,7 +121,7 @@ std::string VersionString(int version) {
+
+ namespace internal {
+
+-#if defined(__ANDROID__)
++#if 0
+ inline void DefaultLogHandler(LogLevel level, const char* filename, int line,
+ const std::string& message) {
+ if (level < GOOGLE_PROTOBUF_MIN_LOG_LEVEL) {
diff --git a/src/device_trezor/CMakeLists.txt b/src/device_trezor/CMakeLists.txt
index 80e932f..c51b1a6 100644
--- a/src/device_trezor/CMakeLists.txt
+++ b/src/device_trezor/CMakeLists.txt
@@ -75,7 +75,7 @@ if(DEVICE_TREZOR_READY)
message(STATUS "Trezor: debugging enabled")
endif()
- if(ANDROID)
+ if(ANDROID AND NOT DEPENDS)
set(TREZOR_EXTRA_LIBRARIES "log")
endif()
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.