Skip to content

Android physical premium acceptance (hardware gated) #146

Description

@jim80net

Purpose

Durable shelf item for the physical-device rung of #123. Emulator evidence is tracked in #144; this issue must not be closed from emulator results.

Named prerequisites

  • Operator acceptance phone reports Android 9 / API 28 or newer
  • Reviewed acceptance APK uses the stable release signer and the update-continuity handoff is complete
  • The underlying Design Android thin client #85 thin-client pairing, Library, and offline Reader surfaces are functional
  • Device has Tailscale installed, correct tailnet membership, and access to a managed Serve engine URL
  • A reviewed development premium origin/certificate is composed into the acceptance build
  • Controlled free and premium test identities/entitlements are available
  • Controlled plain-text house inventory is available
  • No new device, lab, or paid testing capacity is purchased without an operator money gate

Physical acceptance checklist

  • Home-engine pairing and premium sign-in coexist without credential crossover
  • RFC 8628 uses the system browser; the user code is protected in app/recents and cancellation/process death leaves no resumable secret state
  • Local mode and offline local reading produce zero premium/ad requests
  • Fresh online-free truth shows eligible native text only in Library/Jobs
  • Premium, stale, expired, offline, malformed, and unavailable truth shows no remote ad
  • Refresh/revoke/sign-out failure clears only premium state and preserves home pairing/local reading
  • Disconnect/reconnect, background/restore, rotation, force-stop/relaunch, and OEM recents behavior conform
  • Physical K4 sweep covers redacted adb logs, package ciphertext, dumpsys state/intents/clipboard, screenshots/recents, crash output, and controlled request observations
  • Evidence records device/API, APK commit and SHA-256, environment, pass/fail/not-run results, and redacted links

Boundary

Status remains not run until every prerequisite is satisfied. No production credential or raw secret may appear in evidence. Any product defect found here becomes a separate code increment and independently gated PR.

Refs #123
Depends on #144

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions