IdleService runs continuously as a FOREGROUND_SERVICE_TYPE_DATA_SYNC
foreground service (push is on by default). With targetSdk 37, Android 14+'s
dataSync FGS runtime cap (~6h per rolling 24h) calls Service.onTimeout(...)
and then force-stops the service — throwing a system FGS-timeout exception —
if it doesn't stop itself. IdleService overrode onStartCommand/onDestroy/onBind
but not onTimeout, so after ~6 cumulative hours push silently died and the app
hit the exception; on API 35+ the budget is cumulative and a restart can't
recover it until the next 24h window.
Override both onTimeout(startId) (deprecated, API 34) and
onTimeout(startId, fgsType) (API 35+); both route to a clean shutdown that
re-asserts the already-scheduled 15-minute periodic sync, swaps the persistent
notification to a degraded "paused" text and DETACHes it so it survives, then
stopForeground(DETACH) + stopSelf so we never leave a dataSync FGS running past
its cap (the exact condition the platform kills on). This mirrors the existing
low-battery PushMode.POLLING fallback.
The push-status text choice is pulled into a pure PushStatusNotification.statusTextRes
seam and unit-tested on the JVM; the built notification's new timed-out text is
covered by PushStatusNotificationInstrumentedTest.
Closes#302
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The wrapper jar path was resolved from the script's own location, but
gradlew picks the *project* to build from the process's current
directory, not from its own script location. Invoking the helper from
a CWD outside its tree (e.g. another worktree) silently built the
wrong repo's :app, once observed as a ClassNotFoundException for a
test class that only existed in the intended worktree.
cd to the already-resolved repo/worktree root before invoking gradlew
so connectedDebugAndroidTest always targets the correct tree
regardless of the caller's CWD. Update the README's usage note to
match.
Closes#284
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
LocalClipboardManager/ClipboardManager are deprecated in Compose in favor
of LocalClipboard's suspend Clipboard API. Migrates the one call site,
ReportReviewScreen's "Copy report" action: LocalClipboardManager.current
becomes LocalClipboard.current, and the synchronous
clipboard.setText(AnnotatedString(...)) becomes a suspend
clipboard.setClipEntry(ClipEntry(ClipData.newPlainText(...))) run inside
the existing rememberCoroutineScope(). The clipboard interaction is
pulled into a small internal suspend function, copyReportPayloadToClipboard,
so it's unit-testable against a mocked Clipboard without an emulator.
Closes#237.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Coverage lane 4 (#249) flagged reporting/push classes as unreachable by tests.
Add minimal, behaviour-preserving seams and the tests they unblock (issue #257):
- ReportUploadScheduler: inject Provider<WorkManager> (mirroring SyncScheduler)
instead of calling the WorkManager.getInstance static that MockK can't stub on
the abstract WorkManager (AbstractMethodError). New ReportUploadSchedulerTest
pins the per-report unique-work name + REPLACE policy.
- ReportUploadWorker: take the ingest endpoint via a new @DebugReportEndpoint
qualifier (provided from BuildConfig.DEBUG_REPORT_ENDPOINT in ReportingModule)
rather than reading the BuildConfig static inline. New ReportUploadWorkerHttpTest
drives the transmit path against an in-process JDK HttpServer on loopback and
covers 2xx success + delete, 4xx failure, 5xx retry/attempt-cap, and network
error. Production value is unchanged (empty by default).
- IdleService: extract the foreground-notification channel + push-mode-to-text
logic into PushStatusNotification. New PushStatusNotificationInstrumentedTest
asserts channel importance and the IDLE/POLLING notification text with a real
application Context (never a mocked Context).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Guards the SQLCipher cold-start crash fixed in 592a797 (bug #210): a cold
process opening an already-encrypted cache with nothing to convert reached
Room's keyed nativeOpen with the native .so unloaded and crash-looped with
UnsatisfiedLinkError. Every existing on-device test (DatabaseEncryptionTest,
DatabaseProvisionerInstrumentedTest, DatabaseModuleInstrumentedTest,
AccountDataMigratorTest) runs a conversion first, which loads the process-global
library in-process, masking the bug exactly as production did.
System.loadLibrary is process-global, so the instrumentation process can no
longer observe a cold open once it has minted the encrypted fixture. This adds
ColdOpenCacheProbe -- a debug-only ContentProvider declared with
android:process=":coldopen" -- to host the open in a separate, pristine app
process. The test mints the encrypted fixture in the instrumentation process
(a file created by a prior encrypted DB instance) and drives the cold open in
the :coldopen process via ContentResolver.call, mirroring DatabaseProvisioner's
encrypted branch + DatabaseModule's open lambda against the real DatabaseEncryption,
DeferredOpenHelperFactory and SupportOpenHelperFactory. A cold probe (a keyed open
with no preceding load, asserted to throw UnsatisfiedLinkError) makes the isolation
self-verifying: the test fails rather than passing hollow if the library was
already loaded in the harness process.
Verified locally on an API 36 emulator (connectedDebugAndroidTest): 1 test,
0 failures.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Local Gradle Managed Device tasks (apiXXDebugAndroidTest) fail on this machine:
GMD's AVD snapshot step times out under AEHD 2.2
(AvdSnapshotHandler$EmulatorSnapshotCannotCreatedException), though the emulator
itself boots fine. CI is unaffected (it uses connectedDebugAndroidTest, not GMD).
Add .claude/skills/preflight/local_instrumented.sh, which cold-boots ONE emulator
by hand (-no-snapshot, no GMD) and runs :app:connectedDebugAndroidTest filtered to
a targeted set of test classes -- the same technique CI and api37_e2e.py already use.
The helper is deliberately targeted (the full ~114-test suite tends to wedge mid-run
on this box) and enforces emulator hygiene: it force-kills stray qemu/emulator
processes before booting, tears the emulator down afterward, and exits non-zero if an
orphaned qemu-system-x86_64-headless.exe survives -- accumulated orphans have frozen
this machine. Ships with a documented header and a short sibling README.
Closes#269
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds instrumented Compose UI tests for the screens #250/#274 left uncovered,
so lane 6's ui-package coverage ratchet (#251, >=95%) can pass:
- ColorSwatchRow (compose/format): none entry + swatch rendering, selection
callbacks, and selected-state semantics.
- LockScreen: locked title/body, optional error text, unlock callback.
- AddAnotherAccountScreen: confirmation + both onboarding choices.
- SignatureEditScreen: real ViewModel over an in-memory Room-backed
SignatureRepository — new-vs-edit title, create/update round-trips.
- ReportReviewScreen: real ViewModel over a file-backed ReportStore (submitter
stubbed disabled) — disclaimer/fields render, Submit gated on comment length
+ email validity, discard deletes and leaves.
- AppPasswordSetupScreen: real ViewModel over FakeAccountRepository — provider
chrome + credential add, and the app-password help link asserted via
Espresso-Intents (mirrors AccountPickerScreenTest) so no real browser opens.
All 23 tests pass locally on an API 36 emulator.
Closes#275
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The compose FAB does not render reliably under a never-completing refresh==Loading pager (flaked as not-displayed, not-found, then waitForText-timeout across CI runs). Drop the positive FAB anchor; assert only mailbox_empty.assertDoesNotExist() — the actual #219 gate behavior, which is stable and idle-completes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Poll for the compose FAB via waitForText instead of a one-shot assert: under refresh==Loading the LazyPagingItems presenter settles non-deterministically, and the FAB flaked as both not-displayed and not-found across CI runs. Keeps the stable mailbox_empty assertDoesNotExist gate check (#219).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
DatabaseProvisionerTest (mocked) and DatabaseProvisionerInstrumentedTest
(real SQLCipher) both pin that prepareCache() loads SQLCipher's native
library for the encrypted branch, but neither exercises
DatabaseModule.provideDatabase itself — the instrumented one opens
through a hand-rolled SupportOpenHelperFactory, bypassing the branch
that actually maps CacheOpenMode to a real factory. A regression that
breaks that wiring would slip through both existing guards.
Adds DatabaseModuleInstrumentedTest, calling provideDatabase directly
and driving the first real open through its own
DeferredOpenHelperFactory lambda: the encrypted branch loads the
native lib and opens a genuinely-encrypted file, the plaintext branch
never touches the native lib, and a fault-injected load failure
proves the keyed open is causally gated on the load rather than just
usually preceded by it.
Closes#220
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Extends #274's AccountPickerScreenTest with an Espresso-Intents check that
tapping Outlook fires AppAuth's authorization intent. AppAuth always routes
through its own AuthorizationManagementActivity before it ever reaches a
real browser, so that component name is the one characteristic of the
launch that's both guaranteed and installed-browser-independent; matching
it also lets the test stub a canceled result so no real browser opens.
Verified against the real OutlookAuthManager + AppAuth 0.11.1 on a
google_apis API 29 emulator (the same image CI's managed devices use).
Redirect handling, token exchange, and account creation stay out of scope
per #276.
Closes#276
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
emptyState_isHidden_whileTheInboxPagerIsStillLoading asserted the compose
FAB with assertIsDisplayed(), but MailboxScreen renders no loading
affordance in this exact scenario (isSyncingFolder only flips true from
selectFolder(), which this test never calls), so there is nothing else
guaranteed visible while refresh == Loading. The FAB is unconditionally
composed in Scaffold's floatingActionButton slot regardless of loading
state, so its role here is only to prove the screen composed rather than
crashing or rendering blank. Swap to assertExists(), which checks presence
in the semantics tree without requiring on-screen visibility, and keep the
core assertion (mailbox_empty assertDoesNotExist()) that verifies the
actual issue #219 behavior.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Rebase collision with the accountRepository param added to DiagnosticsCollector's
constructor broke :app:compileDebugAndroidTestKotlin. Mirrors the #245
CrashReporterInstallTest fix: mock AccountRepository.observeAccounts() to an empty flow.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>