Commit Graph
836 Commits
Author SHA1 Message Date
JMR-dev abfa60ba86 Merge origin/main into feat-363-icloud-imap-limits (combine iCloud connection-cap + Gmail bandwidth-tracker in MailBackfiller) 2026-07-08 20:23:18 -05:00
mergify[bot] 4c3937edde Merge pull request #469 from JMR-dev/feat-361-gmail-imap-limits
perf(gmail): respect Gmail IMAP connection & bandwidth limits in sync/backfill
2026-07-09 01:15:21 +00:00
mergify[bot] cb9e0e3e54 Merge pull request #467 from JMR-dev/fix-apppassword-intent-flake
test(accountsetup): de-flake URL-open link E2E tests via fake LocalUriHandler
2026-07-09 01:15:18 +00:00
JMR-dev 8a70b329ab perf(icloud): respect iCloud Mail IMAP connection & message-size limits
Adds two iCloud-specific, provider-scoped policies that build on the
existing shared throttling framework (#360's AccountThrottleGate, #356's
BackfillPacer) without refactoring either:

- IcloudConnectionLimiter: a per-account permit gate capping an iCloud
  account at 5 simultaneous connections (Apple documents 5-8; pinned to
  the conservative low end). Wired into MailBackfiller around both
  connection-opening call sites (the header-page fetch and the
  body/attachment prefetch loop - the "1 + K + attachments" per-page
  connection count issue #363 describes). A no-op passthrough for every
  other provider, so it composes cleanly with #360's reactive backoff
  (already consulted first, per account) and #356's slice pacing
  (BackfillWorker composes BackfillPacer.runPaced around
  MailBackfiller.runBackfill, so the cap sits one layer beneath the
  pacer's cooldown/cap in the same call graph).

- IcloudSendLimits: enforces Apple's ~20 MB outgoing message-size cap
  before SmtpSender ever opens a connection, estimating the actual
  encoded wire size (base64 inflates binary attachment bytes by ~4/3)
  rather than comparing raw file bytes, mirroring GraphSender's existing
  pre-send attachment-size guard. An over-cap send throws
  MessageTooLargeException, caught by SendWorker's existing runCatching
  and turned into a clean, PII-free outbox error - no crash, no raw
  provider rejection.

Both are new, self-contained files kept intentionally separate from a
shared cross-provider table, per the parallel-safety note on this ticket
(sibling issues #361/#362/#364 add their own provider's limits the same
way).

Touches two shared files: MailBackfiller.kt (new constructor dependency
+ two call sites wrapped in icloudConnectionLimiter.withPermit) and
SendWorker.kt (one guard call before smtpSender.send). Both are
minimal, additive edits — flagged for conflict-awareness with the
sibling provider tickets.

Also excludes MailBackfillerTest.kt from detekt's LargeClass rule
(config/detekt/detekt.yml), mirroring the existing MailRepositoryImplTest
exclusion: one cohesive single-SUT suite tipped over the LLOC boundary
by the new connection-cap wiring tests.

Closes #363
2026-07-08 19:31:03 -05:00
JMR-dev b1a7931dfa perf(gmail): respect Gmail IMAP connection & bandwidth limits in sync/backfill
Add Gmail's documented IMAP caps (15 max simultaneous connections, 2,500 MB/day
download, 500 MB/day upload, 10,000 messages/labels per limit) as provider-scoped
config/policy that feeds the existing #360/#356 pacing machinery instead of
reinventing it:

- GmailSyncLimits: pure constants + `appliesTo(account)` provider detection via the
  existing MailProvider.forImapHost lookup (no changes to MailProvider itself).
- GmailBandwidthTracker: a new, per-account/per-day download-byte tracker (mirrors
  AccountThrottleGate's shape: ConcurrentHashMap state, injectable clock, PII-free
  once-per-crossing AppLog breadcrumb). Proactive and orthogonal to the #360
  AccountThrottleGate (which only reacts to a provider-issued throttle) and #356's
  BackfillPacer (which paces slice cadence, not bytes) - same relationship
  InteractiveImapGate already documents having to AccountThrottleGate.

Wiring: MailRepositoryImpl.prefetchMessage (the single funnel both MailBackfiller
and MailSyncer's background prefetch already share) records bytes actually pulled
over the network for Gmail accounts; MailBackfiller/MailSyncer's prefetchIfEnabled
consult isOverDailyBudget once per account before starting a batch and defer
body/attachment prefetch for the rest of the day once Gmail's budget is reached -
header paging/sync is never gated, and interactive fetches (open, attachment tap,
inline images) are never gated either, matching the existing interactive-priority
principle (#355/#360).

The 15-connection cap is already satisfied by the existing architecture
(ImapConnectionCache keeps one reused connection per account plus one dedicated
IDLE connection - 2 total, well under the cap); GmailSyncLimitsTest pins that
invariant against the documented ceiling so a future change that grows per-account
concurrency trips a test before it could approach Gmail's real limit. The
10k-messages-per-label figure is captured as a documented constant only - it is
deliberately NOT wired into a backfill stop condition, since issue #12's full
history backfill is intentional and a large real mailbox can exceed 10k messages.

AccountThrottleGate, BackfillPacer, ThrottleClassifier/ThrottleSignal/ThrottleBackoff,
InteractiveImapGate, and MailProvider are all untouched.

Closes #361
2026-07-08 19:23:25 -05:00
JMR-dev 65eae0f6c7 test(accountsetup): de-flake URL-open link E2E tests via fake LocalUriHandler
The outbound-link E2E tests verified the opened page with Espresso-Intents
(intending(ACTION_VIEW).respondWith(...) + intended(...)). intended() runs an
onView(isRoot()).check(...) whose RootViewPicker waits up to 10s for a
window-focused root. On the CI matrix emulator the activity window
intermittently reports has-window-focus=false, so the assertion flakes with
RootViewPicker$RootViewWithoutFocusException, failing the whole E2E leg and
forcing a 9-min retry. The intent stubs were already present and do NOT fix
this: no external activity launches, the focus loss is environmental (the same
run failed 8 unrelated RootViewPicker-based tests at once).

Verify these ACTION_VIEW/browser-open link taps by injecting a recording
LocalUriHandler and asserting the exact URL the screen opens. That keeps the
tests entirely on Compose interactions, which do not depend on window focus
(280+ Compose-only tests passed in the same failing run), so they are
deterministic without weakening the assertion (still asserts the provider
page / host).

Converted (ACTION_VIEW / UriHandler "browser-open" shape):
- AppPasswordSetupScreenTest.tappingCreateAppPasswordPage_launchesBrowserIntentToHelpUrl
- AppPasswordSetupScreenTest.imapDisabledFailure_showsThePrompt_andHelpLinkOpensTheProviderPage
- OutlookImapNoticeScreenTest.tappingImapHelpLink_opensTheMicrosoftArticle

Real-intent tests (hasComponent/Settings action, no UriHandler seam) keep
Espresso-Intents and are out of scope here.
2026-07-08 19:04:13 -05:00
mergify[bot] d7429dfef0 Merge pull request #463 from JMR-dev/feat-356-backfill-cooldown
perf(sync): pace backfill with an inter-slice cooldown and per-run cap
2026-07-08 23:35:34 +00:00
mergify[bot] ca62f77064 Merge pull request #464 from JMR-dev/ci-421-matrix-wedge-capture
ci(e2e): restore wedge-capture diagnostics on the matrix E2E legs (#421)
2026-07-08 22:50:01 +00:00
JMR-dev 9407b20914 ci(e2e): restore wedge-capture diagnostics on the matrix E2E legs (#421)
Mirror the e2e-preview job's proven wedge-capture onto the API 29-36 matrix
legs, now that #454 replaced reactivecircus/android-emulator-runner with the
same hand-provisioned manual boot e2e-preview uses.

Each leg now wraps its `./gradlew connectedDebugAndroidTest` in the #404
`timeout -k 30s $WEDGE_TIMEOUT` wrapper; on a hang (exit 124) capture_wedge
dumps the smoking gun (running test via TestRunner logcat, SIGQUIT thread
dumps of the app + instrumentation processes, service list / service check,
dumpsys activity+window, logcat tail) into a per-API-level
wedge-diagnostics-api<level> artifact (if-no-files-found: ignore so healthy
runs stay quiet).

Why it cannot re-hang the legs (the #406/90dfb18 revert reason): the wrapper
wraps ONLY the foreground gradle client, never the backgrounded emulator --
identical in shape to e2e-preview's run_shard. The reverted #404 wrapper wrapped
reactivecircus's emulator boot; #454 removed that. WEDGE_TIMEOUT reuses preview's
1200s: healthy matrix legs run ~8.3-12.0 min (whole job), well under 20 min, which
is itself well under this job's 50-min cap, so a genuine wedge is caught + captured
and a false trip on a healthy run is not possible.
2026-07-08 17:04:54 -05:00
JMR-dev 5c564ebeda perf(sync): pace backfill with an inter-slice cooldown and per-run cap
Backfill chained bounded slices back-to-back with no gap, and on a large
mailbox `moreWork` never clears, so a single BackfillWorker run paged
flat-out for its whole session and kept the account's IMAP connection
saturated -- the background load that starves interactive message-opens
(#355) and worsens provider throttling (#360).

Add BackfillPacer, a small in-process primitive that bounds one run:
- inter-slice cooldown: a fixed 30s idle between chained slices;
- per-run slice cap: at most 4 slices per run, then defer to the 30-min
  periodic cadence so one run cannot monopolise the account.

Composes with the two sibling mechanisms instead of duplicating them:
- #355 (InteractiveImapGate): the cooldown is SKIPPED while an interactive
  fetch is active -- the next slice already parks at its per-page yield
  point, so a fixed delay on top would only double the idle (no pathological
  double-delay);
- #360 (AccountThrottleGate): a slice whose only outstanding work is a
  throttled account returns moreWork=false, so the loop stops and no
  cooldown is spent spinning on a backed-off provider.

The cooldown is a cancellable delay and the loop rechecks !isStopped before
each slice, so a WorkManager stop / teardown ends a run promptly. All
breadcrumbs are PII-free (durations/counts only).

Tests: BackfillPacerTest (JVM, virtual time) covers cooldown timing, cap,
cancellation, and the #355/#360 composition; BackfillWorkerTest asserts the
worker caps a flat-out run; BackfillPacerInstrumentedTest proves forward
progress across paced runs, the interactive skip, and prompt cancellation on
the real Android runtime.

Closes #356
2026-07-08 16:57:15 -05:00
mergify[bot] 0273ea4d39 Merge pull request #460 from JMR-dev/ci-420-path-filter-scripts
ci(path-filter): skip E2E for scripts/docs/.claude-only PRs (#420)
2026-07-08 21:46:06 +00:00
mergify[bot] 2cd282fedc Merge pull request #459 from JMR-dev/feat-355-pause-backfill-on-open
perf(sync): pause background backfill while a message is opening
2026-07-08 21:21:03 +00:00
mergify[bot] 389bd974d0 Merge pull request #458 from JMR-dev/chore-385-compose-rule-v2
chore(test): migrate v1 createComposeRule/createAndroidComposeRule usages to v2
2026-07-08 20:34:59 +00:00
JMR-dev b98ae99abc ci(path-filter): skip E2E for scripts/docs/.claude PRs via negated allow-list (#420)
The #399 E2E path-filter listed its safe paths as POSITIVE globs under
`predicate-quantifier: 'every'`. dorny/paths-filter's `every` makes the
per-file predicate "matches EVERY pattern", so `skippable` required a single
file to be under app/src/test AND docs AND scripts AND .claude AND be *.md at
once -- impossible. `skippable` was therefore always false and the full E2E
matrix ran for every PR, including the docs/scripts-only PRs it was meant to
skip (e.g. scripts-only #419).

Rewrite the filter the way dorny documents `every`: `non_skippable` lists the
same safe allow-globs, each NEGATED, so a file forces E2E iff it matches NONE
of them (i.e. it is outside the allow-list). e2e_needed = non_skippable, keeping
the fail-safe "run E2E unless every changed file is provably irrelevant" rule --
a mixed PR still runs the matrix.

Add an `e2e_harness` override so a change under .claude/skills/preflight/** (the
local instrumented-test harness) still forces E2E even though .claude/** is
otherwise skippable.

Skip: app/src/test/**, **/*.md, docs/**, scripts/**, .claude/** (minus preflight).
Run:  everything else -- app/**, *.gradle*, gradle/**, gradle/libs.versions.toml,
      app/schemas, app/proguard-rules.pro, .github/workflows/**, .github/scripts/**,
      .claude/skills/preflight/**. This ci.yml change itself runs the matrix.

Verified with PyYAML (valid) + a dorny-semantics simulation over representative
changed-file sets (scripts-only/docs/unit-test/.claude skip; app/androidTest/
gradle/ci.yml/preflight/.github-scripts run).

Closes #420
2026-07-08 15:22:03 -05:00
JMR-dev 52da77b6a0 perf(sync): pause background backfill while a message is opening
Opening an uncached message stalled ~35-74s (avg 48s) behind the reader
spinner because the on-demand IMAP body fetch has no priority over the
continuous full-history backfill (#12) and loses the race for the
account's IMAP throughput (connect-per-op client, no shared lock).

Introduce InteractiveImapGate (@Singleton), a process-wide priority
signal mirroring MailMaintenanceGate/AccountThrottleGate (#360):

- MailRepositoryImpl wraps the user-facing IMAP paths (openMessage,
  inlineImages, downloadAttachment, buildReplyDraft) in withInteractive
  {}, which raises an in-flight counter for the duration and always
  lowers it in a finally, so a failed fetch can never strand it.
- MailBackfiller parks (awaitInteractiveIdle) at its per-page yield
  point while the counter is non-zero, resuming the instant it clears.
  This is also the slice's first yield point, so a slice never begins a
  page while a user is waiting on a body.
- Backfill's own content prefetch bypasses the gate (calls
  ensureAttachmentFile directly) so it never yields to itself.

A counter, not a mutex, is used so overlapping interactive fetches run
concurrently and backfill waits for all to clear. PII-free AppLog
park/resume breadcrumbs (accountLogRef) at the backfill yield points.

Builds on #360's throttle framework (orthogonal: that backs off after a
provider rejects background work; this yields to a foreground fetch).

Tests: InteractiveImapGateTest (counter/park/resume/error-release/
concurrency + Turbine), MailBackfillerTest park+resume+no-deadlock,
MailRepositoryImplTest gate-held-during-open, and
InteractiveImapGateInstrumentedTest (on-device pause/resume across the
CI API matrix).

Closes #355
2026-07-08 15:17:56 -05:00
JMR-dev 2c35301756 chore(test): migrate v1 createAndroidComposeRule usages to v2
Compose BOM 2026.06.00 deprecates the v1 test-rule factories in
androidx.compose.ui.test.junit4 in favour of the ...junit4.v2 package
(v2 composes on StandardTestDispatcher instead of UnconfinedTestDispatcher).
Swap the import in all 30 androidTest classes from
androidx.compose.ui.test.junit4.createAndroidComposeRule to
androidx.compose.ui.test.junit4.v2.createAndroidComposeRule.

v2's createAndroidComposeRule<A>() returns the same
AndroidComposeTestRule type, so the call sites are unchanged. The tests
already wait on async state via waitUntil/waitForIdle rather than
assuming eager effect execution, so no test semantics needed adjusting
for the StandardTestDispatcher change. The JVM (test) source set already
used the v2 createComposeRule from PR #375.

Closes #385
2026-07-08 15:04:27 -05:00
mergify[bot] 94fee9779a Merge pull request #434 from JMR-dev/refactor-307-domain-platform-nits
fix(notifications): verify notification-tap origin before opening a message (#307)
2026-07-08 19:45:50 +00:00
mergify[bot] 3cd441c85e Merge pull request #436 from JMR-dev/feat-360-throttling-backoff
feat(sync): graceful degradation + exponential backoff on provider throttling
2026-07-08 19:45:46 +00:00
Jason Ross b63354b89a Merge branch 'main' into feat-360-throttling-backoff 2026-07-08 13:46:07 -05:00
Jason Ross 9e6f3ebef8 Merge pull request #435 from JMR-dev/perf-298-mail-richtext-nits
fix(mail): below-cut mail/richtext perf & correctness nits (#298)
2026-07-08 13:42:54 -05:00
Jason Ross 2c215c696a Merge pull request #454 from JMR-dev/ci-448-emulator-boot-race
ci(e2e): converge matrix emulator boot on e2e-preview manual boot
2026-07-08 13:41:18 -05:00
Jason Ross b9863b16ca Merge pull request #450 from JMR-dev/ci-pin-gradle-dist-sha
ci(gradle): pin Gradle distribution against published SHA-256
2026-07-08 13:39:22 -05:00
JMR-dev 2b958404bb ci(e2e): converge matrix emulator boot on e2e-preview manual boot
The matrix `e2e` job (API 29-36) relied on reactivecircus/android-emulator-
runner default boot, whose un-guarded, fatal `adb shell input keyevent 82`
races system_server binder republish on snapshot resume ("No service published
for: input") -- an intermittent boot race that flaked the merge queue and hit
BOTH the run and its retry once #446 let runs finally reach boot on API 33.

Replace the android-emulator-runner boot (snapshot-generate + run + retry steps
plus the AVD snapshot cache) with the e2e-preview job proven hand-provisioned
manual boot:
- avdmanager creates the AVD (google_apis/x86_64, pixel_2 -- kept in lockstep
  with testOptions.managedDevices in app/build.gradle.kts);
- a 2-attempt COLD boot loop (-no-snapshot), each with ONE bounded
  `timeout 300 adb wait-for-device shell wait-for-sys.boot_completed` so a stuck
  emulator fails fast instead of hanging to the 50-min job cap;
- a NON-FATAL `adb shell input keyevent 82 || true` unlock (kills the race) plus
  a boot_completed readiness gate before connectedDebugAndroidTest;
- emulator flags mirror e2e-preview; gradle retries once on a test failure.

Cold boot drops the AVD snapshot cache (snapshot resume is the documented root
cause of the race); the shared android-sdk-v1 cache and #446 hardened
pre-install step are untouched. No #404 wedge-capture wrapper (it was reverted
from this matrix job in 90dfb18 for hanging all 8 legs). Streamed logcat +
emulator.log + boot-diagnostics are uploaded for parity diagnosability.

Closes #448
2026-07-08 12:48:54 -05:00
mergify[bot] 677512760a Merge pull request #437 from JMR-dev/refactor-308-ui-nits
fix(ui): address below-cut UI/Compose review nits (#308)
2026-07-08 17:24:42 +00:00
mergify[bot] 6ce9274ff6 Merge pull request #446 from JMR-dev/ci-443-emulator-corrupt-zip-guard
ci(e2e): harden matrix emulator + system-image install against corrupt-zip (extend #389)
2026-07-08 17:24:38 +00:00
JMR-dev 7a0cc3145c ci(gradle): pin Gradle distribution against published SHA-256
The Gradle wrapper had no distributionSha256Sum, so the Gradle 9.6.0
distribution was the one unpinned download in CI (validateDistributionUrl
only checks the URL shape, not content). Pin it to Gradle's published
SHA-256 so the wrapper fails closed on any corrupt/tampered distribution,
matching the SHA-256 integrity pin cmdline-tools already gets (#389).
2026-07-08 12:05:00 -05:00
mergify[bot] 487c3b36a5 Merge pull request #438 from JMR-dev/refactor-313-data-core-nits
refactor(data): tighten data-core atomicity, chunking, and dead code (#313)
2026-07-08 16:42:27 +00:00
JMR-dev 5c00a8da70 ci(e2e): route matrix emulator + system-image install through the #389-hardened installer
The E2E (33) matrix leg deadlocked the merge queue for ~2h when
android-emulator-runner's un-guarded "Create AVD and generate snapshot" step
died with "Error on ZipFile unknown archive" installing a corrupt Android
Emulator SDK zip. #389 hardened the platform/build-tools install (SHA-verify ->
reject-corrupt -> purge -> re-download) but left the emulator + system-image
install to the action, un-guarded.

Pre-install "emulator" + "system-images;android-<api>;google_apis;x86_64"
through setup_android_sdk.py before the emulator-runner steps, so a corrupt zip
is self-healed here and the action then finds both packages already installed
and skips its fragile fetch. Runs on both AVD-cache hit and miss (the emulator
binary + image live under the SDK root, not the ~/.android AVD-snapshot cache,
so they must be present for even a cached AVD to boot). Not added to the
android-sdk-v1 cache (kept small); re-install is a fast sdkmanager no-op when
already present.

The e2e-preview (API 37) job already routes emulator + system image through the
hardened installer, so no change there. setup_android_sdk.py already handles
these package ids generically; add a unit assertion pinning the matrix's
google_apis/x86_64 id to the correct purge path.

Closes #443
2026-07-08 10:39:38 -05:00
JMR-dev 91f2f7105b Merge origin/main into refactor-308-ui-nits (resolve BatteryOptimizationStepTest import conflict with #174) 2026-07-08 10:35:12 -05:00
mergify[bot] 08be7e6541 Merge pull request #439 from JMR-dev/feat-174-battery-usage-help
feat(onboarding): Battery -> Unrestricted help animation (#174)
2026-07-08 15:19:10 +00:00
JMR-dev b038c3bdae feat(onboarding): add Battery -> Unrestricted help animation (#174)
Show a lightweight, dependency-free looping illustration of the
"tap Battery -> choose Unrestricted" path on BatteryOptimizationScreen,
before the user is sent to system settings (complements the #150 deep
link, which cannot guarantee the exact per-OEM screen).

- BatteryGuideAnimation: a stylized Compose illustration driven by
  rememberInfiniteTransition (no Lottie / AnimatedVectorDrawable, no new
  dependency). A highlight moves from a "Battery" row to an
  "Unrestricted" option while a tap dot pulses.
- Reduced motion: rememberReducedMotion() reads ANIMATOR_DURATION_SCALE;
  when animations are off it renders the same card at rest (no motion).
- TalkBack: the illustration exposes a single contentDescription
  mirroring the retained onboarding_battery_guidance text (additive, not
  a replacement). Screen made scrollable so the actions stay reachable.
- PII-free AppLog breadcrumbs: shown / opening-settings / skipped.
- Robolectric JVM tests (animated + static + reduced-motion decision)
  and the instrumented step test exercise the guide; the step test
  disables device animations so the static path renders on-device.
2026-07-08 08:34:00 -05:00
JMR-dev d0ed168fcb refactor(data): tighten data-core atomicity, chunking, and dead code (#313)
Addresses the below-cut data-core review nits from #313:

- SignatureRepository.delete: wrap delete + default-promotion in one SignatureDao
  @Transaction (deletePromotingDefault) so a crash between them can't leave an
  account with signatures but no default; log the promotion (PII-free).
- SignatureRepository.create: move the count-then-default check-then-act into a
  SignatureDao @Transaction (insertMakingFirstDefault) so two concurrent
  first-creates can't both become default.
- AccountSettingsRepository.update: route the read-modify-write through an
  AccountSettingsDao @Transaction (readModifyWrite) so concurrent per-field
  setters can't clobber each other.
- MailRepositoryImpl expunge/move/move-by-role: chunk the unbounded
  getRoutingByIds/deleteByIds IN(:ids) queries (500/chunk) like MailPruner,
  removing the latent SQLITE_MAX_VARIABLE_NUMBER crash.
- MessageDao.observeSummaries: remove the dead whole-table projection (superseded
  by Paging #124/#214); migrate test/debug-probe callers to getById or the paged
  query (which now guards the #51 CursorWindow regression).
- AccountDataMigrator: fix stale KDoc (schema is v2 with sortOrder, not v1).
- DatabaseEncryption.migrate: also sweep the stale -journal sidecar (journal_mode
  = DELETE), matching AccountDataMigrator's sweep.

Unit tests updated for the repository delegations; instrumented DAO tests cover
the new @Transaction behaviour; MailRepositoryImplTest covers the chunk split;
DatabaseEncryptionTest covers the -journal sweep.

Closes #313
2026-07-08 08:09:12 -05:00
JMR-dev 2c0ca30919 fix(ui): address below-cut UI/Compose review nits (#308)
Six of the seven LOW findings collected in #308; the seventh is
deliberately skipped (see below).

- SettingsViewModel: run the app-lock disable-path Keystore/DataStore
  reseal off the main dispatcher (withContext(Dispatchers.Default)),
  matching AppLockViewModel's threading policy - no Keystore crypto on
  Main.
- AppLockGateHost: clear the covered app content out of the semantics
  tree while locked so TalkBack can't traverse the occluded mailbox/
  compose nodes behind the opaque cover; content stays composed so its
  state still survives a re-lock.
- ReaderViewModel.toggleStar: reconcile the optimistic star on a failed
  persist - roll it back and surface a one-shot StarFailed event instead
  of leaving the star stuck in a state the store rejected.
- OnboardingViewModel: persist firstAddedAccountId in SavedStateHandle so
  a process kill mid-onboarding still finishes onto the first account's
  inbox rather than the unfiltered mailbox (preserves #30).
- RichTextEditor: memoize the formatting toolbar's parse + selection
  scans with remember(value) so the per-keystroke hot path isn't
  re-derived on every recomposition.
- AccountSetupViewModel.onOutlookResult: treat a normal OAuth cancel
  (null result) as a no-op instead of surfacing an error snackbar.

Skipped: MailboxViewModel per-keystroke search re-paging - the finding
is documented-intentional and only a "could". The local pager narrows
cached results instantly as you type while the expensive server search
is already debounced (400ms); debouncing the local pager would add lag
for no clear win, and correct scoping (query only, not account/folder)
adds risk to a hot, well-tested path.

Each behavioral change ships a JVM/Robolectric test; the toolbar
memoization (a pure refactor) adds a toolbarStateOf test. PII-free
AppLog breadcrumbs added on the new fallback/state-change paths.

Closes #308
2026-07-08 08:07:48 -05:00
mergify[bot] 1ee6366bec Merge branch 'main' into refactor-307-domain-platform-nits 2026-07-08 13:01:23 +00:00
mergify[bot] 6802b60c42 Merge pull request #433 from JMR-dev/ci-mergify-phase2-batching
ci(mergify): Phase 2 - enable batching (batch_size 5) (#410)
2026-07-08 13:01:17 +00:00
JMR-dev fc9c87629c feat(sync): graceful degradation + exponential backoff on provider throttling
Adds the reactive throttle layer for #360: when a provider rate-limits or
locks us (IMAP `[THROTTLED]`/"too many connections" NO, HTTP 429, auth
lockout), the app now backs off exponentially and pauses the offending
activity instead of hammering the server (which the perf drilldown proved
makes throttling worse — `docs/perf/issue-125-*`).

- ThrottleClassifier: message-text (IMAP/SMTP) + HTTP-status classification of
  throttle vs lockout, distinct from ordinary transient errors; conservative
  so a wrong password or the #390 "IMAP disabled" state is never misread.
- ThrottleBackoff: pure exponential schedule with equal jitter, a bounded cap,
  and Retry-After honoring; a longer window for a lockout (sized to Yahoo's ~1h).
- AccountThrottleGate: per-account backoff state (@Singleton), so one throttled
  account never stalls the others; PII-free AppLog breadcrumbs on throttle/clear.
- MailBackfiller: skips an account inside its backoff window and stops paging one
  that throttles mid-slice (a degradation, not a moreWork spin) — resumes on a
  later slice once the window elapses. Reset on the next successful page.
- MailSyncer: foreground sync feeds the gate but is never blocked by it, so
  interactive work keeps priority over background backfill.

Integrates with the existing WorkManager retry (#403) and connection reuse
(#357) rather than duplicating them. Unit tests cover classification (positive
+ negative), the backoff schedule, and the degrade-not-tight-loop behaviour
(virtual time for the timing).

Closes #360
2026-07-08 07:42:36 -05:00
mergify[bot] 68e45df0ea Merge branch 'main' into ci-mergify-phase2-batching 2026-07-08 12:34:48 +00:00
JMR-dev 49594da10e fix(mail): below-cut mail/richtext perf & correctness nits (#298)
Address the Phase-3 review nits collected in #298:

- perf(HtmlToText): hoist the 4 per-call Regex literals in convert() to
  private vals so each compiles once, not once per fetched HTML body.
- fix(ReportStore): write reports via temp-file + atomic rename so a crash
  mid-write can't truncate a .json that scan() then silently drops. Temp uses
  a non-.json suffix so it is never scanned.
- fix(RichTextEditing): applyLink now splits partially-overlapping links
  (keeping the non-overlapping remainder) instead of un-linking it whole,
  mirroring subtractRange.
- perf(GraphSender): guard attachment size before readBytes() so an oversized
  file can't OOM or blow Graph sendMail's ~4 MB request cap; fails
  mayHaveSent=false so the outbox falls back to SMTP (which streams).
- perf(RichText): mergeSameValueSpans is O(n) via a last-run-per-style map
  instead of O(n^2) indexOfLast; output is identical.
- fix(DiagnosticsCollector): bucket provider labels by DNS-label boundary, not
  raw substring, so mail.notgmail.example no longer reads as Gmail.

Adds/updates unit tests for each behavioural change; pure-perf nits keep their
existing green coverage plus a direct mergeSameValueSpans equivalence test.
2026-07-08 07:24:49 -05:00
JMR-dev a1455d541c fix(notifications): verify notification-tap origin before opening a message (#307)
MainActivity is exported (launcher / mailto: / share), so although the
per-message ACTION_OPEN_MESSAGE intent is explicit and carries no manifest
intent-filter, any app could still craft an explicit intent at the exported
component and drive the reader to an arbitrary cached message id (#307,
domain/platform review nit 1).

Trust only this app's own notification taps: openMessage now attaches an
unforgeable sender-token PendingIntent (its creator package is stamped by the
system and cannot be forged), and messageId yields the id only when that token
was minted by us. A foreign caller carries no token, or one attributed to its
own package, so its intent is ignored and logged PII-free via AppLog.

NotificationIntentsTest gains a case proving a token-less ACTION_OPEN_MESSAGE
intent is rejected while the genuine one still resolves; existing cases move to
the new messageId(context, intent) signature.
2026-07-08 07:17:52 -05:00
mergify[bot] 4d724a52a8 Merge pull request #428 from JMR-dev/fix-319-uidplus-fallback
fix(mail): gracefully fall back when the IMAP server lacks UIDPLUS
2026-07-08 12:09:10 +00:00
JMR-dev f629091b18 ci(mergify): Phase 2 - enable batching (batch_size 5) (#410) 2026-07-08 07:07:35 -05:00
Jason Ross b5b789f6c7 Merge branch 'main' into fix-319-uidplus-fallback 2026-07-08 06:49:27 -05:00
mergify[bot] d9e0d6410c Merge pull request #429 from JMR-dev/perf-322-batched-persistbatch
perf(data): route MailBackfiller.persistBatch through batched updateHeaderContents
2026-07-08 06:04:46 +00:00
mergify[bot] 1d17f76b15 Merge branch 'main' into perf-322-batched-persistbatch 2026-07-08 05:43:43 +00:00
mergify[bot] d55a1c3fae Merge pull request #430 from JMR-dev/feat-390-imap-disabled-detection
feat(auth): detect "IMAP disabled" AUTHENTICATE failures and prompt the user to enable IMAP
2026-07-08 05:43:40 +00:00
mergify[bot] d6665fe8c3 Merge branch 'main' into feat-390-imap-disabled-detection 2026-07-08 05:23:50 +00:00
mergify[bot] 9095cf190f Merge branch 'main' into perf-322-batched-persistbatch 2026-07-08 05:11:32 +00:00
mergify[bot] 63c0d5f9f9 Merge pull request #427 from JMR-dev/fix-403-idleservice-credential-race
fix(push): persist credentials before IdleService watches a new account (#403)
2026-07-08 05:05:40 +00:00
JMR-dev 8f7926886c Merge origin/main into feat-390-imap-disabled-detection (resolve additive strings.xml conflict; keep both #390 imap_disabled_* and #426 outlook_imap_* strings) 2026-07-08 00:00:39 -05:00
JMR-dev 60f822a63c feat(auth): detect "IMAP disabled" AUTHENTICATE failures and prompt to enable IMAP
When account setup obtains a valid credential but the IMAP AUTHENTICATE step is
rejected because IMAP access is switched off for the mailbox, surface an
actionable "turn on IMAP" dialog (with the provider's enable-IMAP help link)
instead of the opaque generic auth error (#390).

- ImapAuthError.isImapDisabled classifies the failure on two signals: explicit
  provider "IMAP is disabled/not enabled" server text (e.g. Gmail's "not enabled
  for IMAP use"), and -- for the Outlook XOAUTH2 path -- a valid-token
  AUTHENTICATE rejection, which outlook.office365.com reports only as a generic
  "AUTHENTICATE failed". Ordinary wrong-password / expired-token / network errors
  are deliberately not matched, so they keep the generic error.
- imapDisabledPromptFor resolves a provider-aware prompt (brand via
  MailProvider.brandFor; Outlook + Gmail enable-IMAP help URLs, generic
  otherwise).
- Shared ImapDisabledDialog reused by the Outlook picker, the app-password form,
  and manual setup -- the three points where the auth failure surfaces. The
  reactive complement to the pre-auth Outlook notice (#411/#426).
- PII-free AppLog breadcrumbs at the classification/prompt points (accountLogRef
  only; never the email/host/token).

Tests: ImapAuthErrorTest (provider text + OAuth inference + a real GreenMail
wrong-password negative), ImapDisabledPromptTest (brand/URL resolution),
ImapDisabledDialogJvmTest (Robolectric), per-view-model + per-screen wiring
tests, and an instrumented AppPasswordSetupScreenTest case driving the failure
end to end.

Closes #390
2026-07-07 23:54:57 -05:00