aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md21
1 files changed, 20 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 6025875..c01339c 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -3469,7 +3469,7 @@ foreground service (`BackupService`) and the WebView reported visible, like a
cast (§11.3). Android 15 limits that type to six hours a day; the service stops
when told and the run carries on at the next opening.
-### 9.13 Contacts, calendar, messages and files backup (Android)
+### 9.13 Contacts, calendar, messages, files and WhatsApp backup (Android)
The Android application sends a copy of the phone's **contacts**, its
**calendars** and its **text messages** to a folder of a group, on the photo backup's terms (§9.12): a client
@@ -3528,6 +3528,25 @@ later do not let an application choose the whole of `Download`, only folders
in it; the section says so. Hidden files (`.x`) are skipped; a name the node
would refuse is mended (`DrivePlan.safeName`), never dropped.
+**WhatsApp.** `<folder>/<account>-whatsapp/`: WhatsApp's own folder,
+`Android/media/com.whatsapp/WhatsApp`, chosen once through the same picker,
+opened on it (`EXTRA_INITIAL_URI`; Android 17 lets it be chosen, checked on a
+Pixel 9); any other folder is refused. The same class runs it as the files
+backup (`DriveChannels` with `DriveKind.WHATSAPP`), the same runner sends it.
+The chats are only ever in WhatsApp's own backups, encrypted with a key only
+it (or the person's end-to-end backup password) opens: nothing here can read
+them, a restore can use them. WhatsApp writes a full copy weekly
+(`Databases/msgstore.db.crypt14`) and an increment a night
+(`msgstore-increment-N.db.crypt14`), and renames last week's set with its
+date when a new week starts; those dated copies are earlier versions this
+backup already kept, so they are not sent again. `Backups/` (contacts,
+settings, stickers) goes too. `Media/` only if the person ticks it, as it is
+often gigabytes; what the photo backup sends is left out. Because files are
+replaced in place, a restore must take one week's copy with that week's
+increments: once anything in that set was sent, the manifest gets a
+`restore-set` line naming, for each file of the set as it is now, the copy
+on the node that goes with it.
+
**Two builds.** Play's policy gives `READ_SMS` to the default SMS application
only, so the APK has a `store` dimension: `full`, distributed directly, and
`play`, which has neither the permission (`src/full/AndroidManifest.xml`) nor