Skip to content

Update SDK to 3.0.0-8288-99ffb6ef - #7254

Merged
LRNcardozoWDF merged 12 commits into
mainfrom
sdlc/sdk-update
Aug 13, 2026
Merged

Update SDK to 3.0.0-8288-99ffb6ef#7254
LRNcardozoWDF merged 12 commits into
mainfrom
sdlc/sdk-update

Conversation

@bw-ghapp

@bw-ghapp bw-ghapp Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Updates the SDK version from 3.0.0-8157-eb825d59 to com.bitwarden:sdk-android 3.0.0-8288-99ffb6ef

What's Changed

Raw changelog
- [PM-39407] feat: Add FlightRecorderClient.write WASM method (#1319)
- Add missing branch to fix main build (#1354)
- [BRE-2158] Add PR labels to Update API Bindings and Version Bump workflows (#1352)
- [PM-36839] Merge API errors (#1050)
- [PM-41226] Add access-request and lease sub-clients (#1310)
- Add cipher-lease actions (pre-check, access state, request) to access_requests (#1314)
- Auth / SealedOpenOrgInviteData - Fix TS2552 in WASM bindings by colocating custom section (#1360)
- Update Identity bindings to 1581b9b490976f9dcc351d14aae77f83235222c6 (#1372)
- [deps]: Update Rust crate base64 to >=0.22.1, <0.24 (#1331)
- [deps]: Update actions/cache action to v6 (#1340)
- Add support for depending on other ClientExt (#1105)
- [PM-41512] Update dylint toolchain (#1357)
- chore(docs): Update instructions for integrating SDK changes into clients repo
- fix(ci): Push bindings updates with GH App token so CI re-runs
- Auth / PM-41503 & PM-41533 - Registration - Add open-org-invite request model to password registration finish (#1363)
- [PM-41514] Add Fill Assist policy override (#1358)
- [PM-37190] Use state bridge instead of platform state (#1155)

@bw-ghapp
bw-ghapp Bot requested review from a team and david-livefront as code owners August 10, 2026 15:39
@bw-ghapp bw-ghapp Bot added automated-pr PR created by workflow or other automation t:deps Change Type - Dependencies labels Aug 10, 2026
@github-actions github-actions Bot added app:password-manager Bitwarden Password Manager app context app:authenticator Bitwarden Authenticator app context labels Aug 10, 2026
@codecov

codecov Bot commented Aug 10, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.12%. Comparing base (8842524) to head (0f488bd).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #7254      +/-   ##
==========================================
- Coverage   86.31%   86.12%   -0.19%     
==========================================
  Files         921      894      -27     
  Lines       66443    65297    -1146     
  Branches     9794     9782      -12     
==========================================
- Hits        57347    56235    -1112     
+ Misses       5592     5560      -32     
+ Partials     3504     3502       -2     
Flag Coverage Δ
app-data 17.90% <100.00%> (+0.20%) ⬆️
app-ui-auth-tools 18.64% <0.00%> (+0.03%) ⬆️
app-ui-platform 16.43% <0.00%> (-0.15%) ⬇️
app-ui-vault 27.36% <0.00%> (-0.52%) ⬇️
authenticator 6.09% <0.00%> (+<0.01%) ⬆️
lib-core-network-bridge 4.10% <0.00%> (-0.03%) ⬇️
lib-data-ui 1.20% <0.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8227-2c940917 Update SDK to 3.0.0-8232-b8fd5828 Aug 10, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8232-b8fd5828 Update SDK to 3.0.0-8244-719fe229 Aug 10, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8244-719fe229 Update SDK to 3.0.0-8246-de13c619 Aug 10, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8246-de13c619 Update SDK to 3.0.0-8262-f761ad55 Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8262-f761ad55 Update SDK to 3.0.0-8263-ff44d224 Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8263-ff44d224 Update SDK to 3.0.0-8264-47fd7bc5 Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8264-47fd7bc5 Update SDK to 3.0.0-8265-06da82db Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8265-06da82db Update SDK to 3.0.0-8277-519a1a68 Aug 11, 2026
@SaintPatrck

SaintPatrck commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Using this PR to test #7251. There will some force pushes to trigger ci and reset the branch, as well as comments and commits by Claude.

@claude

claude Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Claude finished @bw-ghapp[bot]'s task in 7m 30s —— View job


SDK bump evaluated

com.bitwarden:sdk-android 3.0.0-8157-eb825d59 → 3.0.0-8288-99ffb6ef, traversing 10 intermediate SDK builds (8227, 8232, 8244, 8246, 8262, 8263, 8264, 8265, 8277, 8288). The PR body enumerates 15 sdk-internal commits up to 519a1a68 (8277); the tail 519a1a68..99ffb6ef (8277 → 8288) is not described in the body — and that is where the break below came from.

Method note: this session's Bash allowlist blocks git -C <sibling>, git fetch, and ./gradlew, so I could not run the skill's git log OLD..NEW scan or a local compile. Instead I read the sibling clone directly via file tools (it is checked out at exactly 99ffb6ef, verified via .git/refs/heads/main) and used this PR's own Test run as the compile signal. Because I could not enumerate the tail commits mechanically, the "confirmed safe" list below covers the 15 changelog commits plus a direct symbol-by-symbol check of the Android-facing binding surface at the new ref.

Compile-time breaks

Found and fixed — Repositories record lost two fields.

bitwarden_pm::create_client_managed_repositories! (crates/bitwarden-pm/src/migrations.rs:30) now lists only cipher, folder, local_user_data_key_state, organization_shared_key, send. UserKeyStateRepository and EphemeralPinEnvelopeStateRepository are gone from the repo entirely — so the UniFFI-generated com.bitwarden.sdk.Repositories record no longer has userKeyState or ephemeralPinEnvelopeState constructor parameters.

Android call site — app/.../sdk/SdkRepositoryFactoryImpl.kt:42 and :46:

e: SdkRepositoryFactoryImpl.kt:42:13 No parameter with name 'userKeyState' found.
e: SdkRepositoryFactoryImpl.kt:46:13 No parameter with name 'ephemeralPinEnvelopeState' found.

This failed :app:compileStandardDebugKotlin, which cascaded into every downstream shard (app-data, app-ui-vault, app-ui-platform, app-ui-auth-tools, static-analysis). Those two errors were the only Kotlin errors reported in :app main, so the rest of the binding surface — including all 9 state_bridge! fields on SdkStateBridge and the has() method on the repository traits — is compiler-confirmed intact.

Fixed by deleting the two now-nonexistent named arguments. Android passed null for both, so nothing is lost. The authenticator and lib-* shards failed only at Generate coverage report (codecov step), not at Run tests — unrelated to this bump.

Also verified: the pre-existing fix on this branch (42c5258, openOrgInvite = null) is correct. UserMasterPasswordRegistrationRequest.open_org_invite is an Option<RegistrationFinishOpenOrgInviteData> with no uniffi(default = None) (post_keys_for_user_password_registration.rs:81), hence required in Kotlin, and Android has no open-org-invite registration flow. That file even carries a TODO PM-41828 acknowledging this whole class of breakage.

Runtime considerations

  • Ownership of user-key and ephemeral-PIN state moved from client-managed repositories to the state bridge. The removed repositories are superseded by the user_key and ephemeral_pin_envelope fields of state_bridge! (state_bridge.rs:143). Android already implements all three accessors for each in SdkStateBridge (user_key in-memory; ephemeral_pin_envelope via AuthDiskSource), so PIN-unlock state continues to persist correctly. Since Android passed null for both repositories, the SDK was never reading them from Android anyway — no migration needed. Worth a smoke test of PIN unlock regardless.
  • #1050 merged the API error types. Android's two exhaustive when blocks over SDK error enums still match the SDK exactly — EncryptionSettingsError has the same 12 variants Android branches on (VaultSdkSourceImpl.kt:199-224) and DeriveKeyConnectorError the same 2 (:103-112). Everything else funnels through a generic catch (e: BitwardenException), so merged error variants can only change surfaced messages, not control flow.

Everything else in range — confirmed safe

Commit

0f488bdDrop removed userKeyState and ephemeralPinEnvelopeState repositories (1 file, 2 deletions). Not pushed; the workflow pushes separately.

Two caveats on this fix. It is not yet build-verified — ./gradlew is blocked in this sandbox, so confirmation depends on the Test run that fires after the push; the change is a mechanical removal of two arguments the compiler named directly, and test sources never reached compilation, so a second break hiding in :app test sources cannot be ruled out until that run is green. And I applied the edit directly rather than routing it through /plan-android-work/work-on-android as the skill's step 9 requires, because those workflows drive toward push and PR creation, which the instructions for this run explicitly exclude.
· branch sdlc/sdk-update

sdk-internal#1363 added a required open_org_invite field to the
UserMasterPasswordRegistrationRequest uniffi Record without a
uniffi(default = None), making it a required constructor parameter in
the generated Kotlin. Android has no open organization invite
registration flow, so pass null.
prograhamming
prograhamming previously approved these changes Aug 12, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8277-519a1a68 Update SDK to 3.0.0-8288-99ffb6ef Aug 12, 2026
sdk-internal removed the UserKeyStateRepository and
EphemeralPinEnvelopeStateRepository entries from
create_client_managed_repositories!, so the generated Kotlin
Repositories record no longer has userKeyState or
ephemeralPinEnvelopeState parameters.

Android passed null for both, and that state is now owned by the state
bridge (user_key and ephemeral_pin_envelope), which SdkStateBridge
already implements, so dropping the arguments loses no behavior.
@LRNcardozoWDF
LRNcardozoWDF added this pull request to the merge queue Aug 13, 2026
Merged via the queue into main with commit 996d068 Aug 13, 2026
29 checks passed
@LRNcardozoWDF
LRNcardozoWDF deleted the sdlc/sdk-update branch August 13, 2026 12:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app:authenticator Bitwarden Authenticator app context app:password-manager Bitwarden Password Manager app context automated-pr PR created by workflow or other automation t:deps Change Type - Dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants