Repository navigation
Conversation
Combine the completion time, optional POD photo, and final confirmation in one flow while preserving the existing server event and media contracts. Constraint: The selected time is actual completion evidence and must stay separate from Rolling ETA. Rejected: Separate completion and proof dialogs | They split one delivery decision across two confirmations. Confidence: high Scope-risk: moderate Directive: Keep completion time and predicted arrival labels distinct in future UI changes. Tested: npm run check:workspace; git diff --check Not-tested: Physical camera and gallery selection; production proof upload.
Keep reset credential entry on the DSV HTTPS page while exposing login help and invalidated-session cleanup in the app. Constraint: Approved server contract uses administrator-issued 30-minute one-time HTTPS links and no SMS OTP or app reset endpoint Rejected: Add app reset API or deep-link handling | no approved contract Confidence: high Scope-risk: narrow Directive: Keep reset token handling on DSV web unless the server contract changes Tested: npm run check:workspace; npm run lint; npx expo install --check; npm run build; git diff --check Not-tested: physical-device interaction
Present the persisted last stop arrival and server pickup-to-arrival duration on the Driver delivery screen while preserving the existing next-stop ETA and completion flow. Constraint: The deployed DSV contract owns stop ETA, pickup time, route sequence, and timezone Rejected: Calculate ETA from device time, distance, or final service time | those inputs are not an approved completion ETA contract Confidence: high Scope-risk: narrow Directive: Keep this value labeled as final-stop arrival until the server exposes a completion ETA Tested: npm run check:workspace; npm run lint; npx expo install --check; npm run build; git diff --check Not-tested: physical device or emulator UI because none was connected or booted
Advance the public version beyond the deployed Play build and keep Android and iOS build identifiers explicit for local validation. Constraint: Google Play already serves versionCode 25 and App Store Connect already received build 14. Rejected: Reusing 0.1.14 or a versionCode below 26 | Store uploads require monotonically increasing identifiers. Confidence: high Scope-risk: narrow Directive: Do not lower versionCode or buildNumber when regenerating native projects. Tested: npm run check:workspace; npm run lint; npx expo install --check; git diff --check Not-tested: Signed store builds and device installation.
Enable durable R8 minification, optimized defaults, and resource shrinking through the Expo prebuild boundary. Constraint: The Android directory is generated and must remain reproducible from app configuration. Rejected: Edit generated Gradle files directly | Expo prebuild would discard the optimization settings. Confidence: high Scope-risk: narrow Directive: Preserve the template guard when upgrading Expo and review any generated ProGuard default change explicitly. Tested: Clean Expo prebuild proof; workspace typecheck and 170 tests; lint; Expo dependency check; git diff check. Not-tested: Signed production AAB awaits the EAS remote build because local native compilation exceeded the 8 GB host budget.
Constraint: Local release validation must protect an 8 GB host and stay distinct from Play candidates. Rejected: Hardcode generated .cxx paths and targets | They change across generated native builds. Confidence: high Scope-risk: narrow Directive: Stop native builds at the documented fan-out and memory-pressure boundaries before retrying. Tested: npm run check:workspace; npm run lint; npx expo install --check; git diff --check Not-tested: Production Play AAB remains blocked by the exhausted EAS Android quota.
Lock and display the accepted completion time during proof retries. Align Expo SDK 56 patch dependencies and update the existing brace-expansion override without changing audit gates. Refs #1 and EVNSolution/clever-change-control#240. Constraint: Delivery completion and proof upload use separate server operations. Rejected: Resubmit completion after proof failure | It duplicates accepted delivery events. Confidence: high Scope-risk: moderate Directive: Preserve the accepted completion time during retries and keep audit failures visible. Tested: Node 20.19.4; typecheck; 174 tests; lint; Expo alignment; Android export with one Metro worker; git diff --check. Known-failure: npm audit reports 20 high findings from unpatched braces and node-forge advisories; no audit exemption or SDK downgrade applied. Not-tested: Physical-device camera and proof roundtrip; signed native/store artifacts; iOS export.
Unresolved notification clicks and small user commands survive recovery without converting reads into business events or applying stale work to another assignment. Constraint: PR483 is unmerged and undeployed; D05 and Issue62 remain gates. Rejected: Legacy start fallback after unknown atomic result | can duplicate partial business events. Confidence: high Scope-risk: moderate Directive: Keep new APIs OFF until server, policy, security and device gates are cleared. Tested: Typecheck, 253 tests, lint, Expo alignment, Android Hermes export, diff check and independent review. Not-tested: Real FCM, native candidate installation, production server integration and iOS.
Separate inbox receipts from business reads and defer navigation until the user finishes protected work. Recheck authority before moving and consume clicks only after a fresh visible destination commit. Reject malformed operational identities. Constraint: Driver PR64 management review R1-R3; dev remains the integration base Rejected: Discarding drafts or consuming unresolved clicks | interrupts driver work and hides unresolved authority Confidence: high Scope-risk: moderate Directive: Preserve the pending lease during editing, dialogs, saving and proof; never bypass Issue62 Tested: TypeScript; 319 tests; lint; Expo alignment; whitespace; independent review 66 tests Not-tested: New native APK; real FCM; new candidate device screens; server runtime integration
Constraint: Native integration checks must not replace the business package, Firebase configuration, or production API endpoint. Rejected: Install the PR candidate with the production application ID | This could overwrite the business install and reuse real provider configuration. Confidence: high Scope-risk: narrow Directive: Use build:android:integration:apk only with an isolated local server; FCM delivery remains a separate unverified gate. Tested: Targeted project convention tests and Expo config resolution for production and isolated modes. Not-tested: Native APK build and device installation are pending the coordinated heavy-build window.
The Expo android config field did not reach the release manifest. Apply cleartext access through an isolated-only config plugin while production keeps its existing Firebase and network configuration. Constraint: Only the suffix integration package may use loopback HTTP. Rejected: android.usesCleartextTraffic app config field | Expo omitted it from the generated release manifest. Confidence: high Scope-risk: narrow Directive: Keep this plugin behind CLEVER_DRIVER_ISOLATED_ANDROID and never enable cleartext in the business package. Tested: project convention 4/4; isolated Expo prebuild; release manifest inspection; arm64 APK build and device login. Not-tested: Real FCM delivery because the isolated build intentionally has no Firebase provider config.
Capture the fresh audit blocker, actual PostgreSQL client replay proof, native APK provenance, suffix installation, device login recovery, and remaining provider limits. Constraint: Keep export, debug APK, installed device evidence, and real FCM evidence distinct. Rejected: Treating runtime bundle absence as an audit waiver | Issue62 remains blocked by unpatched upstream advisories. Confidence: high Scope-risk: narrow Directive: Do not describe this isolated result as production activation or release-signing evidence. Tested: CI 37570524933; actual PostgreSQL client flow; APK manifest/signature/ABI; suffix install; synthetic device login and relaunch recovery. Not-tested: Real FCM, release signing, native camera and permission flow, production GPS, deployment.
Apply the cleartext policy in both modes and use a guarded prebuild helper. The helper cleans only managed mode transitions or Firebase residue, preserves same-mode caches, and verifies package, manifest, and Firebase output before recording the mode. Constraint: Preserve business Firebase and signing material while keeping operational features and custom API overrides off in release builds. Rejected: Unconditional clean prebuild | It discards valid same-mode native generation and conflicts with the persistent release workspace. Confidence: high Scope-risk: narrow Directive: Use the mode-aware helper for Android APK generation; do not bypass its generated-output checks. Tested: Actual isolated-to-production nonclean prebuild; mode transition and residue guards; targeted policy tests 12/12; workspace tests 325/325, typecheck, lint, Expo alignment; diff check. Not-tested: Business Firebase credentials, release signing, Play submission, or production deployment.
The isolated APK needs an OS notification tap that exercises the production response classifier and resolver. The scheduler accepts only authenticated inbox identities under the integration package and loopback verification guard. Constraint: Keep FCM registration and foreground push receipts restricted to the production package. Rejected: Add a deep link or Android broadcast backdoor | It would bypass the production notification response path. Confidence: high Scope-risk: narrow Directive: Count this path as synthetic local notification evidence, never as actual FCM receipt evidence. Tested: Targeted notification tests 17/17, targeted ESLint, full workspace checks by root, and git diff --check passed. Not-tested: Final rebuilt APK installation and physical notification shade tap are owned by the device verification lane.
Constraint: D05 operational reasons remain unapproved and default empty Rejected: Enable synthetic reasons for normal installs | would treat a fixture as operational policy Confidence: high Scope-risk: narrow Directive: Keep the explicit verification flag and loopback API fence together Tested: Driver typecheck, 325 tests, lint, Expo alignment, isolated APK build Not-tested: Real FCM, live GPS, operational policies, production signing
Render the deferred-notification banner as a bottom SafeArea overlay and place both decisions in visible 44-point action buttons. This keeps the active workspace mounted while making the required actions reachable on tall Android devices. Constraint: Preserve the pending notification, active input, and navigation acknowledgement rules. Rejected: A normal-flow banner below the workspace | The Note20 layout clipped both actions outside the authenticated safe area. Confidence: high Scope-risk: narrow Directive: Keep deferred-notification actions inside a bottom SafeArea container and retain minimum touch height. Tested: driverNotificationWorkProtection 52/52; rendered alert safe-area edges, absolute bounds, and both 44-point actions; diff check; independent re-review APPROVE. Not-tested: Rebuilt APK and final Note20 tap evidence; root runs these sequentially.
Constraint: Preserve PR61, business app data and the Issue62 audit gate. Confidence: high Scope-risk: narrow Directive: Synthetic Android notification taps do not prove FCM or production activation. Tested: Actual Note20 UI flows with PostgreSQL/API correlation; fixed protected actions; 325 tests; typecheck; lint; native APK and installed hash. Not-tested: Real FCM, live vehicle GPS, production signing, camera/POD and unapproved operational policies.
…vigation Constraint: Combine Driver PR61 and PR64 without modifying either source branch Rejected: Navigate immediately from proof modal | Loses active completion input and selected media Confidence: high Scope-risk: moderate Directive: Keep Issue62 audit gate and isolated package flags; do not add a full photo offline queue Tested: 99 integration regressions; package contamination guard; native generation isolation Not-tested: Real FCM, vehicle GPS, production policies, release signing and P7
Constraint: Completion and proof uploads use the existing server idempotency contracts. Rejected: Generating a new command ID for each retry | A lost accepted response creates duplicate completion and proof records. Confidence: high Scope-risk: narrow Directive: Preserve completion identity and selected-photo key until their transaction ends; do not add a full offline photo queue. Tested: Typecheck and 360 workspace tests; 99 connected protection regressions; 9 API tests; lint; Expo alignment; whitespace. Not-tested: Physical-device acceptance of this source and production FCM, vehicle GPS, signing, deployment, and P7.
Constraint: Original PR61 and PR64, business app data, and signing material must remain unchanged. Confidence: high Scope-risk: narrow Directive: Retain Issue62 audit gate and distinguish APK source from documentation-only commits. Tested: Physical Android acceptance; one completion event, one proof record/file, four fresh destination resolves; independent review; 360 app tests and 65 PostgreSQL HTTP tests. Not-tested: Camera-captured photo upload, real FCM, vehicle GPS, production systems, release signing, and P7.
Confidence: high Scope-risk: narrow Directive: Preserve the unchanged APK source and the Issue62 audit block. Tested: Documentation against completed cleanup records and CI 37600176843; executable diff unchanged. Not-tested: No new native build for this documentation-only update.
Constraint: A destination command can commit stops separately and lose its response. Rejected: Unlocking every HTTP 4xx | A previous attempt can already be committed. Confidence: high Scope-risk: moderate Directive: Trust only explicit no-apply results before the first unknown outcome; recover through the original account result contract. Tested: Driver workspace 398/398, lint, Expo alignment, and diff checks. Not-tested: This source APK and isolated runtime acceptance are pending.
Constraint: Even an exact duplicate approval can follow assignment changes. Rejected: Automatically uploading proof after an unknown command succeeds | Captured route finalization can be stale. Confidence: high Scope-risk: narrow Directive: Preserve the original time and photo until explicit close, then reload current assignment before further work. Tested: Driver workspace 401/401, lint, Expo alignment, focused unknown-result and photo-only retry regressions, diff check. Not-tested: Exact APK device acceptance is pending.
Constraint: Recovery must preserve the selected photo and approved completion time Rejected: Hide the photo to expose the close action | Evidence must remain reviewable Confidence: high Scope-risk: narrow Directive: Keep protected-work actions outside the scrollable proof body Tested: TypeScript; 401 tests; lint; Expo alignment; whitespace Not-tested: Updated APK device acceptance follows this commit
Constraint: The executable APK source and later documentation HEAD must remain distinct Confidence: high Scope-risk: narrow Directive: Preserve the private raw evidence, original PRs, and Issue62 audit block Tested: Final f560952 device flows, linked HTTP/DB/proof records, independent APPROVE, documentation accuracy, owned cleanup, whitespace Not-tested: Real FCM, vehicle GPS, captured-camera upload, production policy, deployment, and P7
Carry PR65 completion and notification protection into the approved PR488 report contract, retain legacy queued bodies, and prepare formal build flags. Pin the official SDK56 Android template because Expo56 bundles SDK57 files. Constraint: Server PR488 b3710cad is the approved app contract; device operations and publication are excluded. Rejected: Mutating legacy queue payloads | Replays must retain the original command fingerprint. Rejected: Forced Expo44 audit fix | It violates the Expo56 and RN0.85 support contract. Confidence: high Scope-risk: moderate Directive: Keep Issue62 blocking release until upstream fixes pass the unchanged audit gate; recheck EAS numbering before building. Tested: 418 tests, typecheck, lint, Expo alignment, Android candidate export, native generation isolation, 6 real isolated API scenarios, independent review. Not-tested: New native candidate on a device, signed APK/AAB, actual FCM or email, production server deployment.
Remove the notification-target diagnostic banner and synthetic scheduler from both production and isolated inbox UI while preserving routing and draft protection. Use Android code 28 after the baseline production build consumed code 27. Constraint: User requires the UI correction before any store release. Directive: Keep test notification controls out of the delivery inbox. Confidence: high Scope-risk: narrow Tested: 105 focused regressions, TypeScript, and git diff whitespace. Not-tested: Updated native artifacts and device verification are still pending.
Record signed version 28 artifacts, current source and API checks, partial physical evidence, and the Issue62 toolchain investigation. Correct native clean rules and keep final UI evidence separate from the earlier device run. Constraint: No publication or production changes; device checks pause on new use conflicts. Rejected: Treating bundle exclusion or build success as security clearance | The unchanged audit still fails. Confidence: high Scope-risk: narrow Directive: Complete final-candidate device checks and resolve Issue62 before release. Tested: 418 tests, typecheck, lint, Expo alignment, UI regressions, 6 isolated API cases, AAB/APK signatures and bytecode. Not-tested: Final UI on the device, camera/album retries, valid synthetic notification click, Play-signed update, real FCM/email/GPS.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DSV 확정 정책에 따라 미배송 사유를 필수 자유 텍스트로 받습니다. 앞뒤 공백 제거 후 최대 1,000자를 검증하고, 새 보고는 reason만 전송합니다. 접수는 “미배송 보고가 접수되었습니다”로 표시합니다. PREPARED는 메일 발송 완료로 표시하지 않습니다. 보고는 배송 상태를 바꾸지 않습니다.
초안과 명령 ID·시각·배정·버전·본문을 복구하고, 접수 대기 본문은 그대로 재시도합니다. 기존 reasonCode/explanation 큐와 완료 결과 복구·선택 사진·알림 목적지 및 입력 보호를 유지합니다. 배송 화면의 “알림 배송지” 확인 배너와 알림함의 합성 알림 예약 버튼·설명은 일반 앱과 격리 앱 모두에서 제거했습니다.
최종 소스와 산출물
4618905e19ee8229b5baab059d3527ceb34585aa.1b1bc7a5d765bac77434e07360b91c8503c85c25. 이후 최종 HEAD 차이는 문서와 버전 규약 테스트뿐입니다. 실행 코드·설정·lockfile은 같습니다.b3710cad863a8c12d2a7e38a90486cc8010c5722. 서버는 병합·배포하지 않았습니다.0.2.0, versionCode28.com.evnsolution.clever.driver. 승인 upload 인증서 SHA25610cc172641cb6c83e1761c6afef7053ea8160632ff6c3c06b7aa6c6b1f893be4.com.evnsolution.clever.driver.integration. 인증서 SHA256fac61745dc0903786fb9ede62a962b399f7348f0bb6f899b8332667591033b9c.f485aa84df3da9473c9973e33e3e7e2026519ee1eaa5a6055d25d9cddc8d4cd4eab6e8fd3364c030a390d150893defd22559bd968663f757d37b5780cbf74dfd5a6990be7008b930ac0ee82c5dc331eec159c044d8633bc565a282430211c757서명, manifest·권한·SDK·ABI, 승인 Firebase 일치, 공식 API와 operational=true, 신규 업무 기능을 검사했습니다. 실제 정식/격리 Hermes에서 UI 문구6개와 알림함 예약 handler가 없습니다. 내부 합성 adapter는 package·flag·loopback guard를 유지합니다. AAB JAR 경고는 숨기지 않았고, 별도 JarFile로 payload1,062개 전체 서명을 확인했습니다. 파생 APK는 Drive 게시용 서명·ABI 계약의 파일이 아닙니다.
직접 실행한 검증
차단과 미검증
Issue62 보안 차단은 유지합니다. braces3.0.3/node-forge1.4.0은 새 Android source map에 없었습니다. 실제 export·watcher 호출과 EAS/Expo 서명 의존 경로를 확인했습니다. 미병합 upstream 수정 후보의 취약 재현·회귀는 별도 복사본에서 통과했지만 공식 수정 릴리스가 아닙니다. 지원 릴리스 또는 별도 검토한 유지보수 fork/상위 도구 변경이 필요합니다. audit 기준·lockfile·CI를 낮추거나 실패를 숨기지 않았습니다.
기기 입력 중 foreground가 홈/Play로 변경되는 새 사용 충돌 징후가 있어 기기 검사만 대기했습니다. 사용자 사용 가능 확인 이후 재개해야 합니다. 최종 UI 수정 APK28은 설치하지 않았습니다. 최종 화면·초안/명령 복구·완료 복구·카메라/앨범·업로드 재시도·합성 알림 실제 클릭/입력 보호는 미검증입니다. 이전27의 클릭 시도는 탭 경합이 있어 유효 증거에서 제외했습니다. API 검사로 실기기 결과를 대체하지 않습니다.
기존 정식 Play 설치본0.1.15(26)의 인증서는 upload 키와 다릅니다. 정식 업데이트 경로는 미검증이며 삭제·초기화·downgrade로 우회하지 않았습니다. 서버 API·마이그레이션 선배포, 기존 앱 전환·무손실 롤백, 보안 차단 해결과 최종 후보 실기기 검증이 출시 판단에 필요합니다.
Play/Drive 게시, 스토어 제출, 실제 FCM·메일, 병합·운영 배포를 실행하지 않았습니다. 서버 최신/최소 지원 버전과 GPS 실발송 설정도 변경하지 않았습니다. 실차 GPS는 후속 범위이며 C1은 재조사하지 않았습니다. 소유 테스트 서버는 snapshot/dump를 보존한 뒤 종료했습니다.
상세: 출시 사전검사, Issue62, Android 런북. 이전 초기 후보 기록은 이 기록으로 대체됩니다.
Refs #66, #62
Change-control: EVNSolution/clever-change-control#315