SmartTube TLS Provider Configuration with Conscrypt: Implementation Guide
SmartTube optionally replaces the default Android TLS stack with Conscrypt by exposing a user toggle in Network settings that persists to NetworkData and conditionally inserts the provider at priority position 1 during MainApplication.onCreate().
SmartTube, the open-source Android TV YouTube client developed by yuliskov/SmartTube, implements an optional TLS provider configuration with Conscrypt to modernize encryption support on legacy devices. This architecture allows users to upgrade from outdated OpenSSL implementations to Google's maintained security provider, ensuring TLS 1.3 compatibility and stronger cipher suites while maintaining backward compatibility with Android 10+ systems that already include Conscrypt.
How Conscrypt Integration Works in SmartTube
The implementation follows a three-stage architecture spanning the UI layer, persistent storage, and application initialization.
User-Controlled Toggle in GeneralSettingsPresenter
The entry point resides in GeneralSettingsPresenter.appendConscrypt() (lines 67-74), which appends a switch to the Network settings UI. When toggled, the option immediately persists the choice via mNetworkData.setConscryptEnabled() and flags mRestartApp = true to ensure the provider loads on next launch.
// In GeneralSettingsPresenter.appendConscrypt()
options.add(UiOptionItem.from(
getContext().getString(R.string.enable_conscrypt),
getContext().getString(R.string.enable_conscrypt_desc),
option -> {
// Persist the user choice
mNetworkData.setConscryptEnabled(option.isSelected());
// Restart required to re-initialise provider
mRestartApp = true;
},
// Initial state (read from preferences)
mNetworkData.isConscryptEnabled()));
Persistent Storage via NetworkData
The NetworkData class (lines 22-28) manages the boolean flag using the generic DataSaverBase mechanism. The getter isConscryptEnabled() and setter setConscryptEnabled() provide the API surface for checking and updating the preference.
boolean useConscrypt = NetworkData.instance(context).isConscryptEnabled();
if (useConscrypt) {
// Conscrypt has already been inserted at priority 1 during app start.
// Any subsequent HTTPS connections will automatically use it.
}
Runtime Provider Insertion in MainApplication
The critical initialization occurs in MainApplication.onCreate(). The code instantiates Conscrypt.newProvider() at line 71, then conditionally inserts it at priority position 1 (lines 76-81) only if NetworkData.instance(this).isConscryptEnabled() returns true.
Provider conscryptProvider = null;
try {
// Load native Conscrypt implementation (fails gracefully on unsupported devices)
conscryptProvider = Conscrypt.newProvider();
} catch (Throwable ignored) {}
if (conscryptProvider != null && NetworkData.instance(this).isConscryptEnabled()) {
try {
// Insert at position 1 so it overrides default providers
Security.insertProviderAt(conscryptProvider, 1);
} catch (Throwable ignored) {}
}
Why SmartTube Uses Conscrypt on Older Android Versions
Conscrypt offers TLS 1.3 support, modern cipher suites, and a fully audited OpenSSL-based implementation that outperforms legacy Android security providers. While Android 10 (API 29) and higher ship Conscrypt as the system default, older Android TV devices rely on outdated OpenSSL libraries that may lack critical security patches.
According to the source code comments in MainApplication (lines 60-66), manual insertion is unnecessary on Android 10+ since the system already supplies Conscrypt. The early initialization—performed before any SharedPreferences or disk I/O—prevents class-loader quirks on certain Android TV devices that could trigger silent JNI linking errors (lines 67-69).
Key Implementation Files and Methods
| Component | File Path | Role |
|---|---|---|
| MainApplication | /smarttubetv/src/main/java/com/liskovsoft/smartyoutubetv2/tv/ui/main/MainApplication.java |
Instantiates and conditionally registers the Conscrypt provider |
| NetworkData | /common/src/main/java/com/liskovsoft/smartyoutubetv2/common/prefs/NetworkData.java |
Stores the isConscryptEnabled boolean flag |
| GeneralSettingsPresenter | /common/src/main/java/com/liskovsoft/smartyoutubetv2/common/app/presenters/settings/GeneralSettingsPresenter.java |
Renders the UI toggle and handles user input |
Summary
- SmartTube TLS provider configuration with Conscrypt is optional and user-controlled via the Network settings toggle managed by
GeneralSettingsPresenter. - The
NetworkDataclass persists the boolean flag and provides the runtime check used during application startup. MainApplication.onCreate()instantiatesConscrypt.newProvider()and inserts it at security provider position 1 when enabled.- This upgrade primarily benefits Android devices running API 28 and below; Android 10+ already uses Conscrypt as the system default.
- Initialization occurs early in the application lifecycle to avoid class-loader issues on Android TV hardware.
Frequently Asked Questions
What is Conscrypt and why does SmartTube use it?
Conscrypt is Google's Java Security Provider implementation based on OpenSSL. SmartTube uses it to provide TLS 1.3 support and modern encryption algorithms on older Android TV devices that ship with outdated OpenSSL versions lacking recent security patches. The integration ensures encrypted connections use the strongest available cipher suites regardless of the underlying Android version.
How do I enable Conscrypt in SmartTube?
Navigate to Settings > Network in the SmartTube interface and toggle "Enable Conscrypt". Because MainApplication.onCreate() must insert the provider into the Java security list before any network connections initialize, the app requires a restart after enabling the option. The GeneralSettingsPresenter automatically sets mRestartApp = true when the toggle changes.
Is Conscrypt enabled by default on Android 10+?
No manual configuration is required on Android 10 (API 29) and higher because the system already uses Conscrypt as the default TLS provider. As noted in the MainApplication source comments, the manual insertion logic exists primarily to benefit devices running Android 9 and earlier, where the legacy OpenSSL provider remains the system default.
What happens if Conscrypt fails to load?
The implementation includes comprehensive silent error handling. If Conscrypt.newProvider() throws an exception during instantiation or Security.insertProviderAt() fails during registration, SmartTube catches the throwable and falls back to the system's default TLS implementation without crashing the application. This ensures compatibility with devices that may have broken native library support.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →