E2E_DISABLE_SYSTEM_UI does not disable SystemUI: pm disable-user is set, survives, and is not acted on #246
Open
opened 2026-09-06 13:52:33 +00:00 by JMR-dev
·
0 comments
No Branch/Tag Specified
main
fix/102-picker-back-press-overshoot
fix/268-saf-picker-determinism
feat/ogg-vorbis-libvorbis
feat/expedited-conversion-work
fix/gate-cache-in-worktrees
chore/gate-runs-shellcheck
test/publish-delete-arm-real-provider
docs/e8-instrumented-coverage
docs/api37-carrier-count-drift
docs/e7-second-constraint
test/publish-to-a-real-saf-destination
fix/api37-report-match-line
fix/api37-task-snapshot-crash
test/join-failure-message-on-device
docs/e2e-read-findings-e7
test/cancelling-a-running-export
test/reattach-to-a-running-job
test/content-uri-reaches-ffmpeg
fix/launcher-wiring-waits-for-the-pick
fix/cancel-tests-need-a-slower-encode
test/cancelling-a-running-join
test/cancelling-a-running-session
test/notification-cancel-action
test/ffmpeg-progress-is-observed
test/fallback-asserts-the-path
test/flac-and-opus-assert-their-format
docs/e2e-read-findings
docs/wave4-coverage-numbers
fix/injectable-startup-sweep-scope
test/session-outcome-seam
test/launcher-callback-identity
test/theme-follows-system-dark
test/audio-drop-arm
fix/rotation-waits-for-recreation
fix/convert-guards-on-ready
test/retry-save-mime
test/hardware-progress-reaches-workmanager
test/ffprobe-mapping-seam
test/device-codec-enumeration-seam
test/unknown-container-row
test/null-message-fallbacks
test/cancel-reaches-workmanager
docs/coverage-wave3-recovery
test/concat-engine-seam
docs/coverage-wave3
test/mediaprobe-merge-seam
test/adaptive-shell-wiring
test/aac-audio-args
test/notification-progress-text
test/media3-muxer-guard
test/hardware-fallback-and-cancellation
test/unprobeable-join-clip
test/one-branch-outcomes
test/foreground-type-regimes
fix/bound-wedge-diagnostics
docs/coverage-wave2
test/screen-wiring
test/viewmodel-setters
test/join-state-mapping
test/conversion-state-mapping
test/dedupe-user-messages
fix/restore-stack-merges
test/refused-jobs
test/concatworker-failure-arms
test/container-capabilities-audio
test/readspec-enum-fallbacks
test/outputpublisher-seams
test/mediaprobe-track-seam
test/outputpublisher-partial-branches
test/fake-provider-scaffolding
docs/coverage-read-findings
chore/gitignore-kotlin
test/bound-the-hangs
docs/coverage-remeasure
ci/baseline-counter-precision
fix/invalid-suggestion-chip
ci/wedged-leg-report
fix/reattachment-overwrites-pick
test/theme-live-branches
fix/failed-save-retry
fix/empty-composition-crash
ci/advisory-failure-report
docs/seven-run-counts
test/release-permission-guard
ci/build-workflow-permissions
docs/api37-point-release
docs/benchmark-populate-path
fix/dead-assertion-probe-test
ci/actionlint
test/device-codecs-encode-consequence
fix/sdkmanager-pipefail
docs/readme-restart-claim
fix/saf-picker-root-discovery
fix/probe-dispatcher-seam
test/media3engine-mime-tables
test/mediaprobe-pure-helpers
fix/codec-vocabulary-drift
docs/robolectric-rationale-correction
docs/api37-advisory-counts
test/r38-8-saf-e2e
test/r38-7-join-states
test/r38-6-conversion-states
test/r38-5-state-seam
fix/jacoco-robolectric-coverage
docs/instrumented-tests-correction
test/r38-2-filecard
test/r38-4-advanced-picker
test/r38-3-pickers
tools/file-issue-script
tools/api-37-emulator
fix/review-app-gaps
docs/review-corrections
No results found.
Labels
Clear labels
above-cut
accessibility
backlog
bug
confirmed
documentation
duplicate
enhancement
good first issue
help wanted
invalid
plausible
question
sev:high
sev:low
sev:medium
wontfix
Worked autonomously overnight: local, JVM-verifiable, no product decision
Barrier affecting people with disabilities
Held for manual review: product/UX call, CI/workflow, hardware, or unverifiable here
Something isn't working
Reviewer demonstrated the defect
Improvements or additions to documentation
This issue or pull request already exists
New feature or request
Good for newcomers
Extra attention is needed
This doesn't seem right
Reviewer could not fully demonstrate it; treat as unproven
Further information is requested
High severity
Low severity
Medium severity
This will not be worked on
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: JMR-dev/LibreMediaConverter#246
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Split out of #245, which stops the harness claiming otherwise but does not fix this.
E2E_DISABLE_SYSTEM_UIexists to removeRegionSamplingThread, the nav-bar luma sampler thatreaches this image's gralloc mapper and aborts
surfaceflinger(
docs/api-37-emulator-crash.md). It has never done that, for two independent reasons, andboth were measured on 2026-09-05.
1. The framework restart never ran
adb shell stopandadb shell startare root-only and adbd is not root on a booted emulator.All three copies of the logic called them without
adb root, so every API 37 leg ever runprinted
Must be roottwice — green legs and red alike — between lines that read as if therestart had happened:
Neither number was an observation: the
pidofloop breaks when the process is gone andotherwise falls out at its last iteration, and the old code printed the iteration count either
way.
tools/local-emulator/run-e2e.shwas worse — it sent both to/dev/null, so itsMust be rootwas never even visible.2. And
pm disable-userdoes not keep SystemUI down anywayThis is the part that matters, because it is the one a restart would not have fixed.
On CI, gating leg of run 34006456986.
pm disable-useris accepted at 02:28:37.9 and thepackage really is in
pm list packages -dat 02:29:33 — and SystemUI is started at 02:28:39.5and again at 02:28:52.3, the second of which (pid 4275) is alive for the whole instrumentation
run, logging
WindowManagerShell … app=com.android.systemuiminutes after the harness printsfinal state: SystemUI disabled. The two restarts are the image's own gralloc aborts killingthe framework; SystemUI comes back through both, disabled or not.
Locally on
android-37.0, with the package verifieddisabled-userbefore and after adeliberate, working
stop; start:So the flag is set, survives, and is not acted on.
What #245 already did, and what it deliberately did not
It removed the restart from all three copies rather than repairing it, because making it real
is worse than leaving it broken:
api37-debugrun 34010167885 shows astoplanding ~2 safter the
pmcall killingsystem_serverbefore PackageManager flushes its delayed write ofpackage restrictions, so the state is lost (
NOT DISABLED after the restart, three rounds) andthe leg reported
expected: 0, received: 0—Starting 0 tests. A 15 s pause before the stopdoes make the state survive (bisected locally) and still does not help, per §2.
It kept the
pm disable-usercall, because every green leg and every number quoted about thisrow was measured with it applied, and kept the 45-second no-new-aborts window, which is the part
that was always doing the work: in 34006456986 the boot aborts land at 02:28:18 and 02:28:43 and
that wait is what puts instrumentation at 02:32:42, after them rather than inside one. The log
now prints the true thing beside the misleading one, verified on run 34011072884:
Why this is still worth a ticket
Two reasons, and the first is not about API 37.
pm disable-user. Candidates not evaluated:pm disablerather thandisable-user,am force-stopafter boot completes, killing the process and letting the disabled state stopthe restart, or leaving SystemUI alone and disabling only the nav bar. If one works, the
region-sampling trigger really can be removed and the abort rate on this leg falls — which is
the thing the 45-second wait is currently working around rather than fixing.
E2E_DISABLE_SYSTEM_UI, thedisable_region_samplingfunction andapi37-debug.yml'sdisable_system_uiinput all namesomething that does not happen. #245 keeps the names and documents them, because a rename
touches the matrix row, both workflows and two documents; that trade is worth revisiting
separately rather than inside a flake fix.
Done means
Either a mechanism that demonstrably keeps
com.android.systemuiout ofpsacross a frameworkrestart on
android-37.0— with the abort rate measured before and after, since that is the onlyreason to want it — or a recorded decision that the 45-second quiet window is the answer and the
three knobs get renamed to say so.
Do not accept
pm list packages -das evidence on its own. That is exactly what made thislook like it worked for two weeks;
pidof com.android.systemuiis the check that bites.