0.3.0 — bounded file workflows
DROIDLESS 0.3.0 adds staged, package-confined file output and completes the
unchanged Notepad APK's database backup/restore work through exact recovery.
This remains an experimental macOS ARM64 preview with a limited Android API
profile.
The real app flow
The SHA-256-pinned Notepad 1.0.0 APK writes external/notepad_backup.nbu from
its own Backup data callback. The file is byte-identical to its private SQLite
database (24,576 bytes in the checked seed). Replay then alters a note on a
disposable copy and uses the app's Restore data picker and confirmation. The
restored database bytes, SQLite integrity, Note rows and Folder row match the
backup; a fresh process renders the recovered notes and folder.
After the write is complete, this APK calls unsupported System.exit(0), so the
restore replay reports that guest shutdown boundary. The seed is never modified.
This proves this app's tested database workflow; it does not establish general
Java serialization, broad file APIs or complete app compatibility. Physical
folder/dialog input remains unverified.
Runtime additions
- Bounded
FileOutputStreamString/File constructors, append mode, byte-array
writes and atomic flush/close commits, capped at 64 MiB. - Shared FileOutputStream/FileChannel position and close state, with bounded
transferFrom/transferTo;File.listFiles(FileFilter)uses guest callbacks
over package-confined entries. - Mounted Views for
FragmentTransaction.add(containerId, fragment)and a
bounded same-runtime reference path for custom Bundle Serializable values. - APK-local declared-field access, Toast logging, UTF-8 form URL encoding,
MimeTypeMapextension lookup and a few missing Context/String methods.
Writes stay inside the package's private or virtual external directory. Paths
reject traversal, symlinks, hard links, special files and host paths. Unclosed
staged output does not replace a prior file. Custom Serializable values retain
object identity only while staying in this runtime; no Java serialization bytes
or cross-process persistence are produced.
Download and validation
The macOS ARM64 archive contains the CLI, license, five authored APK fixtures,
three upstream APK fetch/check helpers, README and RELEASE.json provenance.
The checksum file verifies the archive. No Apple developer signature or
notarization is provided; public APKs are fetched unchanged and are not bundled.
All checks run locally; GitHub Actions remain disabled. sh tools/ci.sh passes
150 Rust tests, warning-free Clippy, optimized builds, 4,096 seeded mutations
and five AppKit checks. The full optimized public replay passes with one
unchanged CLI (SHA-256 c793225d9963e1186774eca5b0a5b0488963d14cbcc1f5aba3b236c514fdc438).
Packaging extracts into a clean temporary directory and verifies the installed
executable and guest flows.
shasum -a 256 -c SHA256SUMS
tar -xzf droidless-0.3.0-macos-arm64.tar.gz
cd droidless-0.3.0-macos-arm64
./droidless run --headless --ephemeral fixtures/counter.apk --click Increment
sh tools/fetch-notepad.sh
./droidless run --headless --size 390x844 --data-dir ./test-apps \
--click "+" --input "Hello, desktop" --back artifacts/apks/notepad-v1.0.0.apkThe 50% project checkpoint remains an active milestone, not a measured API
coverage claim. Linux builds/native UI, broad AndroidX/Compose, JNI, networking,
JIT and games remain future work. Use trusted APKs; this is not an audited
security sandbox.
Download v0.3.0 ·
Website ·
Verification · Compatibility ·
Security · Storage