SmartTube TLS Provider Configuration with Conscrypt: Implementation Guide

SmartTube optionally replaces the default Android TLS stack with Conscrypt by exposing a user toggle in Network settings that persists to NetworkData and conditionally inserts the provider at priority position 1 during MainApplication.onCreate().

SmartTube, the open-source Android TV YouTube client developed by yuliskov/SmartTube, implements an optional TLS provider configuration with Conscrypt to modernize encryption support on legacy devices. This architecture allows users to upgrade from outdated OpenSSL implementations to Google's maintained security provider, ensuring TLS 1.3 compatibility and stronger cipher suites while maintaining backward compatibility with Android 10+ systems that already include Conscrypt.

How Conscrypt Integration Works in SmartTube

The implementation follows a three-stage architecture spanning the UI layer, persistent storage, and application initialization.

User-Controlled Toggle in GeneralSettingsPresenter

The entry point resides in GeneralSettingsPresenter.appendConscrypt() (lines 67-74), which appends a switch to the Network settings UI. When toggled, the option immediately persists the choice via mNetworkData.setConscryptEnabled() and flags mRestartApp = true to ensure the provider loads on next launch.

// In GeneralSettingsPresenter.appendConscrypt()
options.add(UiOptionItem.from(
        getContext().getString(R.string.enable_conscrypt),
        getContext().getString(R.string.enable_conscrypt_desc),
        option -> {
            // Persist the user choice
            mNetworkData.setConscryptEnabled(option.isSelected());
            // Restart required to re-initialise provider
            mRestartApp = true;
        },
        // Initial state (read from preferences)
        mNetworkData.isConscryptEnabled()));

Persistent Storage via NetworkData

The NetworkData class (lines 22-28) manages the boolean flag using the generic DataSaverBase mechanism. The getter isConscryptEnabled() and setter setConscryptEnabled() provide the API surface for checking and updating the preference.

boolean useConscrypt = NetworkData.instance(context).isConscryptEnabled();
if (useConscrypt) {
    // Conscrypt has already been inserted at priority 1 during app start.
    // Any subsequent HTTPS connections will automatically use it.
}

Runtime Provider Insertion in MainApplication

The critical initialization occurs in MainApplication.onCreate(). The code instantiates Conscrypt.newProvider() at line 71, then conditionally inserts it at priority position 1 (lines 76-81) only if NetworkData.instance(this).isConscryptEnabled() returns true.

Provider conscryptProvider = null;
try {
    // Load native Conscrypt implementation (fails gracefully on unsupported devices)
    conscryptProvider = Conscrypt.newProvider();
} catch (Throwable ignored) {}

if (conscryptProvider != null && NetworkData.instance(this).isConscryptEnabled()) {
    try {
        // Insert at position 1 so it overrides default providers
        Security.insertProviderAt(conscryptProvider, 1);
    } catch (Throwable ignored) {}
}

Why SmartTube Uses Conscrypt on Older Android Versions

Conscrypt offers TLS 1.3 support, modern cipher suites, and a fully audited OpenSSL-based implementation that outperforms legacy Android security providers. While Android 10 (API 29) and higher ship Conscrypt as the system default, older Android TV devices rely on outdated OpenSSL libraries that may lack critical security patches.

According to the source code comments in MainApplication (lines 60-66), manual insertion is unnecessary on Android 10+ since the system already supplies Conscrypt. The early initialization—performed before any SharedPreferences or disk I/O—prevents class-loader quirks on certain Android TV devices that could trigger silent JNI linking errors (lines 67-69).

Key Implementation Files and Methods

Component File Path Role
MainApplication /smarttubetv/src/main/java/com/liskovsoft/smartyoutubetv2/tv/ui/main/MainApplication.java Instantiates and conditionally registers the Conscrypt provider
NetworkData /common/src/main/java/com/liskovsoft/smartyoutubetv2/common/prefs/NetworkData.java Stores the isConscryptEnabled boolean flag
GeneralSettingsPresenter /common/src/main/java/com/liskovsoft/smartyoutubetv2/common/app/presenters/settings/GeneralSettingsPresenter.java Renders the UI toggle and handles user input

Summary

  • SmartTube TLS provider configuration with Conscrypt is optional and user-controlled via the Network settings toggle managed by GeneralSettingsPresenter.
  • The NetworkData class persists the boolean flag and provides the runtime check used during application startup.
  • MainApplication.onCreate() instantiates Conscrypt.newProvider() and inserts it at security provider position 1 when enabled.
  • This upgrade primarily benefits Android devices running API 28 and below; Android 10+ already uses Conscrypt as the system default.
  • Initialization occurs early in the application lifecycle to avoid class-loader issues on Android TV hardware.

Frequently Asked Questions

What is Conscrypt and why does SmartTube use it?

Conscrypt is Google's Java Security Provider implementation based on OpenSSL. SmartTube uses it to provide TLS 1.3 support and modern encryption algorithms on older Android TV devices that ship with outdated OpenSSL versions lacking recent security patches. The integration ensures encrypted connections use the strongest available cipher suites regardless of the underlying Android version.

How do I enable Conscrypt in SmartTube?

Navigate to Settings > Network in the SmartTube interface and toggle "Enable Conscrypt". Because MainApplication.onCreate() must insert the provider into the Java security list before any network connections initialize, the app requires a restart after enabling the option. The GeneralSettingsPresenter automatically sets mRestartApp = true when the toggle changes.

Is Conscrypt enabled by default on Android 10+?

No manual configuration is required on Android 10 (API 29) and higher because the system already uses Conscrypt as the default TLS provider. As noted in the MainApplication source comments, the manual insertion logic exists primarily to benefit devices running Android 9 and earlier, where the legacy OpenSSL provider remains the system default.

What happens if Conscrypt fails to load?

The implementation includes comprehensive silent error handling. If Conscrypt.newProvider() throws an exception during instantiation or Security.insertProviderAt() fails during registration, SmartTube catches the throwable and falls back to the system's default TLS implementation without crashing the application. This ensures compatibility with devices that may have broken native library support.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →