Source: "same-class crash-state" audit (Finding 2 — the gating invariant is entirely untested; this is how the PruneWorker/BackfillWorker gap slipped in).
There is zero coverage of the EncryptedCacheGuard cache-lock gate: grep finds no EncryptedCacheGuard / isCacheLocked references in src/test or src/androidTest, and no *WorkerTest exists — so even the existing guards on SyncWorker / SendWorker / IdleService are unverified and can regress silently.
Add a parameterized unit suite over every pre-auth DB entry point — SyncWorker, SendWorker, PruneWorker, BackfillWorker, IdleService — asserting: with a mock EncryptedCacheGuard.isCacheLocked() == true, doWork() returns Result.retry() (the service stopSelf()s) AND the Lazy<DB-dep> is never resolved (verify.get() isn't called); with false, the job actually runs. Construct workers via their @AssistedInject constructors with mocks (no Hilt needed).
Plus a DatabaseProvisionerTest case: appLock = true with a resolvePassphrase stub that suspends on a CompletableDeferred, asserting prepareCache() does not complete until it resolves — proving the precondition the guard exists to avoid (DatabaseProvisionerTest currently only tests appLock = false with an instant passphrase). Depends on the worker-gating fix.
**Source:** "same-class crash-state" audit (Finding 2 — the gating invariant is entirely untested; this is how the `PruneWorker`/`BackfillWorker` gap slipped in).
There is **zero** coverage of the `EncryptedCacheGuard` cache-lock gate: grep finds no `EncryptedCacheGuard` / `isCacheLocked` references in `src/test` or `src/androidTest`, and no `*WorkerTest` exists — so even the existing guards on `SyncWorker` / `SendWorker` / `IdleService` are unverified and can regress silently.
**Add a parameterized unit suite** over every pre-auth DB entry point — `SyncWorker`, `SendWorker`, `PruneWorker`, `BackfillWorker`, `IdleService` — asserting: with a mock `EncryptedCacheGuard.isCacheLocked() == true`, `doWork()` returns `Result.retry()` (the service `stopSelf()`s) AND the `Lazy<DB-dep>` is **never resolved** (`verify` `.get()` isn't called); with `false`, the job actually runs. Construct workers via their `@AssistedInject` constructors with mocks (no Hilt needed).
Plus a `DatabaseProvisionerTest` case: `appLock = true` with a `resolvePassphrase` stub that suspends on a `CompletableDeferred`, asserting `prepareCache()` does not complete until it resolves — proving the precondition the guard exists to avoid (`DatabaseProvisionerTest` currently only tests `appLock = false` with an instant passphrase). Depends on the worker-gating fix.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Source: "same-class crash-state" audit (Finding 2 — the gating invariant is entirely untested; this is how the
PruneWorker/BackfillWorkergap slipped in).There is zero coverage of the
EncryptedCacheGuardcache-lock gate: grep finds noEncryptedCacheGuard/isCacheLockedreferences insrc/testorsrc/androidTest, and no*WorkerTestexists — so even the existing guards onSyncWorker/SendWorker/IdleServiceare unverified and can regress silently.Add a parameterized unit suite over every pre-auth DB entry point —
SyncWorker,SendWorker,PruneWorker,BackfillWorker,IdleService— asserting: with a mockEncryptedCacheGuard.isCacheLocked() == true,doWork()returnsResult.retry()(the servicestopSelf()s) AND theLazy<DB-dep>is never resolved (verify.get()isn't called); withfalse, the job actually runs. Construct workers via their@AssistedInjectconstructors with mocks (no Hilt needed).Plus a
DatabaseProvisionerTestcase:appLock = truewith aresolvePassphrasestub that suspends on aCompletableDeferred, assertingprepareCache()does not complete until it resolves — proving the precondition the guard exists to avoid (DatabaseProvisionerTestcurrently only testsappLock = falsewith an instant passphrase). Depends on the worker-gating fix.