Skip to content

0.4.3: verified Android window ownership

Choose a tag to compare

@mobileAiDev mobileAiDev released this 07 Oct 02:33
· 9 commits to main since this release

Android foreground checks previously interpreted a client window title as package ownership. A host-owned window with a guest package in its title could therefore be rejected even when the caller supplied the intended allowlist.

0.4.3 resolves the focused WindowState's actual owner and Activity, verifies PackageManager UID and process lifetime, and compares that identity through observation and action dispatch. Ordinary Activity windows, app dialogs and explicitly identified non-Activity windows retain their package and UIA guards. Unlisted apps, replaced windows and restarted processes require a new observation or remain rejected.

All public components use 0.4.3: CLI/MCP, Android SDK, Gradle plugin and six executors, iOS Swift package, Flutter SDK/test helper and Web SDK. The internal native store remains 0.2.0.

Validation includes Host functional/performance suites, native package installation with compilers denied, Android builds/lint/JVM tests, Swift iPhoneOS build, Flutter analysis/66 tests, and Web 23 tests. A real Android 36 emulator reproduced the old failure in an ordinary app with a projected title, then passed the packaged CLI/MCP's observation, counter action, dialog and rejection scenarios. API36/37 owner queries also passed on existing devices. API25/30 dump formats were checked against AOSP and tested offline; those versions were not available for live validation in this release.