Continue Android file manager implementation from typed APK baseline #69
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Continuation handoff: complete the Android file manager implementation
Original user goal (still active)
Read
~/jdrive-for-android.mdand implement all of it injerboa-drive.Use the local Android emulator to test every feature and every GUI function with
real assertions. Open a pull request only after 100% of the requirements and
tests are complete, with CI green. Do not redefine completion around the
currently working subset.
The authoritative source checkout
/Users/user/mine/jerboa-drivemust remainuntouched. Current implementation work is in the dedicated checkout
/Users/user/work/jerboa-drive-android-implementation, branchfeat/android-file-manager. There is no commit or pull request yet.What is implemented in the current worktree
All of the following are uncommitted changes in the worktree:
VERSIONbumped from2.0.23to2.0.24.Makefiletargets/help forandroid,android-release, andandroid-smoke.scripts/build-android.sh: compiler/runtime fetch, clean generated output,encrypted asset provisioning, safe staging cleanup, debug APK build, and
checksum output.
scripts/sign-android.sh: release-signing path (requires an externalkeystore; do not treat debug APKs as releases).
support/fetch-android-compiler.sh: pinned jerboa-android acquisition.tools/android-embed.ss: typed Jerboa host provisioner for the JDAE envelope(scrypt N=65536/r=8/p=2, AES-256-GCM, bounded payload, JSON validation).
android/app.ss: typed Jerboa Android app containing:cleanup, device ID, biometric enrollment/removal/unlock wrapper using
AndroidKeyStore, and recovery handling.
LIST pagination, HEAD/GET/PUT, bounded multipart initiation/parts/complete/
abort, retries, prefix handling, and v2 name/frame codecs.
codec self-tests, malformed-frame safeguards, and transfer journals.
filtering, local copy/rename/delete, downloads, backup/restore reports,
cache cleanup, cancellation, Sharesheet/FileProvider, and locked-state
gating.
androidx.work:work-runtime-ktx:2.11.2),generated
BackupWorker, and generatedBackupSchedulerwith a unique15-minute plan/cancel operation. The worker deliberately records
waiting-for-unlockand exits successfully when no live session exists;it does not pretend to perform an authenticated background transfer.
generated scheduler and persisting
backup-plan-statusasscheduledorcancelled.test/android-smoke.sh: fresh uninstall/install smoke harness with ADBretries, dynamic UI node taps, password/picker race handling, secret-sentinel
APK scan, SAF picker flows, backup/schedule/cancel state checks, biometric
fallback, lock/cache/recovery checks, local operations, v2 upload terminal
result, codec, inspect, filter, and Sharesheet assertions.
docs/android.md: build/use/recovery documentation and explicit statement ofthe remaining limitations; it must stay honest until the gates below pass.
typed-android-workmanager-periodic(typed Worker/scheduler syntax and therequired
getSharedPreferences(name, mode)extern arity).Verified evidence
Latest generated debug APK built successfully with SHA-256:
414ac4ad49270cdcaab283d538519fadd53049d8a8f462bc0c2a138ba0541dd2.Build command used:
The synthetic profile/password are disposable local test inputs only; do not
print or commit them. The build compiled generated
DriveActivity.kt,BackupWorker.kt, andBackupScheduler.ktsuccessfully.make securitypassed (package_security_status=pass,secret_scan_status=pass).git diff --checkpassed. Shell syntax checkspassed for the scripts.
A complete pre-WorkManager full emulator run passed all existing GUI checks,
including unlock/wrong-password/biometric fallback, background lock,
encrypted backup marker, SAF folder/upload pickers, local operations, v2
upload terminal result, transfer cancellation/journal/cache, codec, inspect,
restart/recovery/device-ID/tree persistence, local filter, and Sharesheet.
After adding scheduler UI, a later emulator run reached and passed the new
backup-scheduledandbackup-cancelledassertions. That run later failedat a flaky post-picker “Unlocked” assertion; a one-second keyboard-dismiss
delay was added to the harness afterward, but the entire updated run was not
re-run before handoff. Re-run it before relying on the latest smoke result:
jerboa_verifycould not run because the MCP server points at stale/Users/user/mine/jerboa/bin/jerboaand a missing Chez cache. This is atooling/runtime issue, not a source verification success; the Android build
itself is the current compile evidence.
Important implementation lessons
.ss/.slswith shell editors, Python, sed, or apply_patch. All.ssedits were made withjerboa_balanced_replace/jerboa_balanced_insert,followed by
jerboa_check_balance. Continue this rule.LinearLayout.LayoutParams(MATCH_PARENT, WRAP_CONTENT); otherwise lateraction buttons are clipped on the emulator.
separate
typed-kotlin-fileforms,Workersubclass withdoWork, and ascheduler using
PeriodicWorkRequest.Builder,WorkManager, andenqueueUniquePeriodicWork.scheduler generated
backup_schedule/backup_cancel; cross-file calls fromDriveActivitymust import/call those generated names, not assume aBackupSchedulerKtclass symbol.getSharedPreferencesrequires explicit(name, mode)parameters in thetyped extern; omitting them gives a Kotlin arity error.
button is tapped and only its status is being asserted, do not tap an old
coordinate again (the old helper accidentally invoked “Backup now” twice).
adb shell run-as ... cat shared_prefs/*.xmldoes not reliably expand thewildcard; enumerate files with
findand read each one.runtime is repaired. Do not “fix” this by editing the authoritative checkout.
Remaining work: do not open the PR until all of this is complete
The current app is explicitly not 100% complete. The next agent must use
~/jdrive-for-android.mdas the authority and close every gate, not merely makethe synthetic smoke green.
~/.embed/allowlisted profile/AWS mapping and profile selector, confined regular-file
and symlink/path checks, expired-token handling, separate vault/YubiKey
export path, independent envelope vectors (including Unicode, duplicate
JSON keys, malformed/oversized inputs), normal release signing/key setup,
provenance artifacts, and default
make androidbehavior without relyingon a hand-created normalized JSON file.
compare desktop↔Android names, headers, frames, empty/boundary/Unicode
files, tamper/truncation/reordering/wrong-path rejection, and >4 GiB
streaming. Preserve the exact desktop v2 contract.
the 16 MiB source limit (
readBytes/readNBytescurrently bound upload anddownload bodies). Implement 64-bit offsets, bounded frame/part buffers,
multipart sizing up to 10,000 parts, range GET validation, ETag/version
preconditions, cancellation/deadlines/backoff, ambiguous completion
reconciliation, orphan cleanup, non-seekable/unknown-size staging, and
measured heap evidence. Current multipart still accepts one
Bytesbody.desktop-created data, >1000-object pagination, custom HTTPS/path/virtual
host, session tokens, redirects/TLS/errors, concurrent modification, and
desktop readback of Android uploads. The current synthetic endpoint is empty,
so network actions only prove terminal failure handling.
rows, breadcrumb/back, size/type/date, sort, scoped search, multi-select,
responsive/cancellable loading, upload/download/open/share, conflict choices
(skip/replace/keep-both), path-safe recursive moves with re-encryption,
partial move reporting, and foreign-object preservation. Current UI is a
linear action list with limited selected-object behavior.
queued/running/waiting/failed/completed states, retry/partial details,
foreground long-transfer service/notification/cancel path, notification
permission denial handling, Doze/network/low-storage/reboot/process-kill,
Android 15 service timeout/checkpoint handling, and proper structured
manifest service types/permissions. Current Worker only records
waiting-for-unlockand performs no backup transfer.labels, exclusions, destination plan IDs, schedule/constraints/conflict
policy/history), hashed encrypted manifests, additive deletion semantics,
honest completed/skipped/failed/unreadable/cancelled totals, source mutation,
resume/recovery, fresh-unlock handoff, verified file/subtree/full restore,
conflict/free-space handling, temp destination publication, and interruption
safety. Current backup is a marker/report workspace, not a complete engine.
settings and redacted diagnostics UI; test rotation, screen-off authorized
transfer, Doze, notification denial, service timeout, current API and min
SDK emulator, physical arm64 device, upgrade/reinstall/enrollment-change,
stale callbacks, and all release-signature checks.
android-test/android-integrationtargets and run the complete provisioning, secret containment, envelope,
v2, S3, file-manager, biometric, backup, restore, platform/build matrix in
section 11 of the handoff. Every visible action must have a real emulator
assertion and real operations must be byte/hash verified.
make test, security, nativebuild/smoke gates plus Android build/smoke; create a feature commit in this
worktree, push it, open a Forgejo PR targeting the default branch, poll CI
with
fj -H git.jerboa.sh pr status ober/jerboa-drive#<number>, fix all redchecks, and report the direct PR URL. Never self-approve or self-merge.
Suggested continuation sequence
Use disposable synthetic credentials and a disposable prefix. Never inspect,
print, commit, or publish real secrets. Keep all feature work under
~/work/;leave
/Users/user/mine/jerboa-driveunchanged. Only after the remaining gatesare actually implemented and tested should the continuation agent commit,
push, open the PR, and wait for human review.