{"record":{"id":"ac2066d3c76c391c","repo":"MuntashirAkon/AppManager","slug":"failed-to-encrypt-sourcefiles","errorCode":null,"errorMessage":"Failed to encrypt [${sourceFiles}]","messagePattern":"Failed to encrypt \\[(.+?)\\]","errorType":"exception","errorClass":"BackupException","httpStatus":null,"severity":"error","filePath":"app/src/main/java/io/github/muntashirakon/AppManager/backup/convert/TBConverter.java","lineNumber":235,"sourceCode":"        } catch (Exception ignore) {\n        }\n        // Backup APK file\n        String sourceBackupFilePrefix = BackupUtils.getSourceFilePrefix(getExt(mDestMetadata.info.tarType));\n        Path[] sourceFiles;\n        try {\n            sourceFiles = TarUtils.create(mDestMetadata.info.tarType, baseApkFile, mBackupItem.getUnencryptedBackupPath(), sourceBackupFilePrefix,\n                            /* language=regexp */new String[]{\".*\\\\.apk\"}, null, null, false)\n                    .toArray(new Path[0]);\n        } catch (Throwable th) {\n            throw new BackupException(\"APK files backup is requested but no APK files have been backed up.\", th);\n        } finally {\n            baseApkFile.requireParent().delete();\n        }\n        // Overwrite with the new files\n        try {\n            sourceFiles = mBackupItem.encrypt(sourceFiles);\n        } catch (IOException e) {\n            throw new BackupException(\"Failed to encrypt \" + Arrays.toString(sourceFiles));\n        }\n        for (Path file : sourceFiles) {\n            mChecksum.add(file.getName(), DigestUtils.getHexDigest(mDestMetadata.info.checksumAlgo, file));\n        }\n    }\n\n    private void backupData() throws BackupException {\n        Path dataFile;\n        try {\n            dataFile = getDataFile(Paths.trimPathExtension(mPropFile.getName()), mSourceMetadata.tarType);\n        } catch (FileNotFoundException e) {\n            throw new BackupException(\"Could not get data file\", e);\n        }\n        String tarType = mDestMetadata.info.tarType;\n        int i = 0;\n        String intBackupFilePrefix = null;\n        String extBackupFilePrefix = null;\n        if (mDestMetadata.info.flags.backupInternalData()) {","sourceCodeStart":217,"sourceCodeEnd":253,"githubUrl":"https://github.com/MuntashirAkon/AppManager/blob/0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5/app/src/main/java/io/github/muntashirakon/AppManager/backup/convert/TBConverter.java#L217-L253","documentation":"After re-packaging, backupApkFile() encrypts the produced archive files via mBackupItem.encrypt(sourceFiles); an IOException is wrapped as this message including the file list (no cause preserved). It means encryption of the APK archive files failed.","triggerScenarios":"mBackupItem.encrypt(sourceFiles) throws IOException: crypto engine cannot initialize (missing/invalid keystore key or alias), unsupported algorithm for the destination format, or I/O failure reading plaintext/writing ciphertext.","commonSituations":"Keystore deleted or key invalidated between metadata generation and encryption; destination crypto algorithm mismatched with the selected key; storage full or ciphertext files unreplaceable from a previous failed run.","solutions":["Validate the destination crypto settings (key alias, algorithm) before conversion; re-select or recreate the encryption key.","Check free space and writability of the destination backup path.","Delete stale .enc files from a previous failed conversion and retry.","Inspect crypto-layer logs, since this BackupException drops the original IOException cause (add `e` as cause when editing the library)."],"exampleFix":"// before\nthrow new BackupException(\"Failed to encrypt \" + Arrays.toString(sourceFiles));\n// after\nthrow new BackupException(\"Failed to encrypt \" + Arrays.toString(sourceFiles), e); // keep cause","handlingStrategy":"validation","validationCode":"// Pre-check crypto readiness before conversion\nif (mBackupItem.isEncrypted() && !CryptoUtils.keyExists(destCrypto.keyAlias)) {\n    throw new IllegalStateException(\"Encryption key for alias not found: \" + destCrypto.keyAlias);\n}","typeGuard":"fun CryptoInfo?.canEncryptFiles(): Boolean =\n    this != null && keyAlias != null && algo != null && CryptoUtils.keyExists(keyAlias)","tryCatchPattern":"try {\n    converter.convert();\n} catch (BackupException e) {\n    if (e.getMessage() != null && e.getMessage().startsWith(\"Failed to encrypt [\")) {\n        Log.e(TAG, \"APK encryption failed for files listed in message — verify keystore/algorithm\");\n    }\n}","preventionTips":["Validate keystore key availability and algorithm support before starting conversion.","Ensure free space for both plaintext and ciphertext copies of the APK archives.","Improve the library call site to attach the IOException as cause for diagnosability."],"tags":["crypto","encryption","apk"],"backgroundTag":"missing-credentials","analyzedSha":"0152f468fc9463ee02dc2ca83f6fe4989a2c4ca5","analyzedAt":"2026-09-12T14:03:37.243Z","contentChangedAt":"2026-09-12T14:03:37.243Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}