realm / realm-kotlin

Kotlin Multiplatform and Android SDK for the Realm Mobile Database: Build Better Apps Faster.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[RLM_ERR_INVALID_DATABASE] Realm cannot be decrypted after a migration from java-sdk to kotlin-sdk

brnmr opened this issue · comments

How frequently does the bug occur?



We've recently decided to migrate from java-sdk to to the kotlin-sdk and when the app is first started right after the migration, the encrypted realm file cannot be opened with the same key that has been used to encrypt the realm prior to the migration to the kotlin-sdk. The error we're getting is as follows:

[RLM_ERR_INVALID_DATABASE]: Failed to open Realm file at path '/data/user/0/': Realm file decryption failed (Decryption failed: 'unable to decrypt after 0 seconds (retry_count=4, from=i != bytes_read, size=4096)')

Here are details about the SDK versions:

// Java-sdk version prior to migration
// Kotlin-sdk version after the migration
implementation ("io.realm.kotlin:library-base:1.11.0")

We've verified that the key used for the realm config is the same before and after the migration so there should be no issue with the key itself. In addition, we did tests with unencrypted realm and in this case we don't have issues with the migration.

In addition, we tried to open the realm file using Realm Studio by providing the encryption key. We get warning that the realm file is in an outdated format which I'm not sure is related to the issue but after choosing the Backup and upgrade option, we are able to decrypt the realm database and see the content - everything is in there.

Screenshot 2024-03-20 at 17 24 57

Here is the code for generating the realm config:

private fun initRealmConfig(): RealmConfiguration? {
        // Increment whenever you made changes to the Realm* database models
        val schemaVersion: Long = 2
        // Get encryption key
        val realmKey = DBHelper.loadEncryptionKey(App.applicationContext())

        realmKey?.let {
            val realmConfig = RealmConfiguration.Builder(getSchemaClasses())

            // Once we've used the key to generate a config, erase it in memory manually
            Arrays.fill(realmKey, 0.toByte())

            return realmConfig

        return null

Stacktrace & log output

[RLM_ERR_INVALID_DATABASE]: Failed to open Realm file at path '/data/user/0/': Realm file decryption failed (Decryption failed: 'unable to decrypt after 0 seconds (retry_count=4, from=i != bytes_read, size=4096)')

Can you reproduce the bug?


Reproduction Steps

  1. Run app version with java-sdk
  2. Migrate to kotlin-sdk
  3. Update the installed app version in step 1 with the migrated version


  • Realm decryption fails



What Atlas App Services are you using?

Local Database only

Are you using encryption?


Platform OS and version(s)


Build environment

Android Studio version: Hedgehog | 2023.1.1 Patch 2
Android Build Tools version:
Gradle version: gradle-7.4-bin

➤ PM Bot commented:

Jira ticket: RKOTLIN-1047

Hi guys,

After further debugging I figured out that this line in the initialization of the RealmConfigration is causing the issue. I still have no clue why since this was working fine in the java-sdk and was taken from the official documentation here:

This is the line I am referring to:

// Once we've used the key to generate a config, erase it in memory manually
Arrays.fill(realmKey, 0.toByte())

So, when I delete this line and update to the app version with the migrated java-sdk to kotlin-sdk, the database is working fine and can be decrypted without issues.

Any ideas?

Hi @brnmr. The encryption key is actual not copied as part in the Kotlin RealmConfiguration, so clearing the data inbetween creating the configuration and opening the realm will cause the to use the cleared key. The key is also used to asynchronously open some internal background instances of the realm which causes it to be a bit tricky when the memory can be cleared, as the asynchronous operations are not guaranteed to happen before returns. The only safe way to know this at the moment is to wait for initialization of the internal realms by forcing an update through an empty transaction with:

realm.write {  }

We are working on a fix to this with a callback to provide the key and a callback when it is safe to clear the key again. This should ensure that the key is in memory as little as possible. The progress of that can be track in #1636

Thank you @rorbech for the provided information. We are looking forward to the callback for when it's safe to clear the key.