MuntashirAkon/AppManager · error · KeyStoreException
Alias exists.
Error message
Alias ${alias} exists. What it means
addSecretKey enforces unique aliases: if the alias is already registered in both shared preferences and the AM keystore and isOverride is false, a KeyStoreException is thrown. With isOverride=true the existing key is silently replaced instead.
Solutions
- Pass isOverride=true if the existing key should be replaced
- Check mAmKeyStore.containsAlias(alias)/preference first and skip adding when present
- Use a different alias for the new key
Example fix
// before
ksManager.addSecretKey(alias, secretKey, false);
// after
if (!ksManager.containsAlias(alias)) {
ksManager.addSecretKey(alias, secretKey, false);
} else {
ksManager.addSecretKey(alias, secretKey, true); // intentional override
} Defensive patterns
Strategy: validation
Validate before calling
String prefAlias = KeyStoreManager.getPrefAlias(alias);
boolean exists = prefs.contains(prefAlias) && ksManager.containsAlias(alias);
if (exists && !allowOverride) {
alias = alias + "-" + System.currentTimeMillis(); // unique alias
} Try / catch
try {
ksManager.addSecretKey(alias, secretKey, false);
} catch (KeyStoreException e) {
// alias already exists; retry with override or new alias
ksManager.addSecretKey(alias, secretKey, true);
} Prevention
- Make migration idempotent: skip aliases that already exist
- Pass isOverride=true deliberately, not by default
- Generate unique aliases for one-off keys
When it happens
Trigger: Calling addSecretKey(alias, secretKey, false) when the alias already exists in both sSharedPreferences and mAmKeyStore — typically during migrateKeyStore when the target key was already migrated.
Common situations: Running keystore migration twice; re-importing a key that already exists; concurrent processes adding the same alias.
Understand the failure class
Background: "already exists" / EEXIST / FileAlreadyExistsException: what the 'file already exists' error means and how to fix it — this error's family across 37 libraries.
Related errors
- Alias app_manager does not exist in KeyStore.
- Checksums for master key did not match.
- Could not decrypt encrypted password.
- Could not load AES local protection key from keystore
- Decrypted pass is empty for alias
AI-assisted analysis of MuntashirAkon/AppManager@0152f468fc (2026-09-12).
Data as JSON: /api/errors/e0fe24a6594c9940.
Report an issue: GitHub.
Appendix: source
Thrown at app/src/main/java/io/github/muntashirakon/AppManager/crypto/ks/KeyStoreManager.java:287
String encryptedPass = getEncryptedPassword(mContext, password);
if (encryptedPass == null) {
mAmKeyStore.deleteEntry(alias);
throw new KeyStoreException("Password for " + alias + " could not be saved.");
}
sSharedPreferences.edit().putString(prefAlias, encryptedPass).apply();
try (OutputStream is = new FileOutputStream(AM_KEYSTORE_FILE)) {
mAmKeyStore.store(is, password);
Utils.clearChars(password);
Utils.clearChars(password);
}
}
public void addSecretKey(String alias, @NonNull SecretKey secretKey, boolean isOverride)
throws KeyStoreException, IOException, CertificateException, NoSuchAlgorithmException {
// Check existence of this alias in system preferences, this should be unique
String prefAlias = getPrefAlias(alias);
if (sSharedPreferences.contains(prefAlias) && mAmKeyStore.containsAlias(alias)) {
if (!isOverride) throw new KeyStoreException("Alias " + alias + " exists.");
else Log.w(TAG, "Alias %s exists.", alias);
}
char[] password = getAmKeyStorePassword();
mAmKeyStore.setEntry(alias, new KeyStore.SecretKeyEntry(secretKey), new KeyStore.PasswordProtection(password));
String encryptedPass = getEncryptedPassword(mContext, password);
if (encryptedPass == null) {
mAmKeyStore.deleteEntry(alias);
throw new KeyStoreException("Password for " + alias + " could not be saved.");
}
sSharedPreferences.edit().putString(prefAlias, encryptedPass).apply();
try (OutputStream is = new FileOutputStream(AM_KEYSTORE_FILE)) {
mAmKeyStore.store(is, password);
} finally {
Utils.clearChars(password);
Utils.clearChars(password);
}
}
View on GitHub (pinned to 0152f468fc)