# 0.3.0 — bounded file workflows

DROIDLESS 0.3.0 adds staged, package-confined file output and completes the
unchanged Notepad APK's database backup/restore work through exact recovery.
This remains an experimental macOS ARM64 preview with a limited Android API
profile.

## The real app flow

The SHA-256-pinned Notepad 1.0.0 APK writes `external/notepad_backup.nbu` from
its own Backup data callback. The file is byte-identical to its private SQLite
database (24,576 bytes in the checked seed). Replay then alters a note on a
disposable copy and uses the app's Restore data picker and confirmation. The
restored database bytes, SQLite integrity, Note rows and Folder row match the
backup; a fresh process renders the recovered notes and folder.

After the write is complete, this APK calls unsupported `System.exit(0)`, so the
restore replay reports that guest shutdown boundary. The seed is never modified.
This proves this app's tested database workflow; it does not establish general
Java serialization, broad file APIs or complete app compatibility. Physical
folder/dialog input remains unverified.

## Runtime additions

- Bounded `FileOutputStream` String/File constructors, append mode, byte-array
  writes and atomic flush/close commits, capped at 64 MiB.
- Shared FileOutputStream/FileChannel position and close state, with bounded
  `transferFrom`/`transferTo`; `File.listFiles(FileFilter)` uses guest callbacks
  over package-confined entries.
- Mounted Views for `FragmentTransaction.add(containerId, fragment)` and a
  bounded same-runtime reference path for custom Bundle Serializable values.
- APK-local declared-field access, Toast logging, UTF-8 form URL encoding,
  `MimeTypeMap` extension lookup and a few missing Context/String methods.

Writes stay inside the package's private or virtual external directory. Paths
reject traversal, symlinks, hard links, special files and host paths. Unclosed
staged output does not replace a prior file. Custom Serializable values retain
object identity only while staying in this runtime; no Java serialization bytes
or cross-process persistence are produced.

## Download and validation

The macOS ARM64 archive contains the CLI, license, five authored APK fixtures,
three upstream APK fetch/check helpers, README and `RELEASE.json` provenance.
The checksum file verifies the archive. No Apple developer signature or
notarization is provided; public APKs are fetched unchanged and are not bundled.

All checks run locally; GitHub Actions remain disabled. `sh tools/ci.sh` passes
150 Rust tests, warning-free Clippy, optimized builds, 4,096 seeded mutations
and five AppKit checks. The full optimized public replay passes with one
unchanged CLI (SHA-256 `c793225d9963e1186774eca5b0a5b0488963d14cbcc1f5aba3b236c514fdc438`).
Packaging extracts into a clean temporary directory and verifies the installed
executable and guest flows.

```sh
shasum -a 256 -c SHA256SUMS
tar -xzf droidless-0.3.0-macos-arm64.tar.gz
cd droidless-0.3.0-macos-arm64
./droidless run --headless --ephemeral fixtures/counter.apk --click Increment
sh tools/fetch-notepad.sh
./droidless run --headless --size 390x844 --data-dir ./test-apps \
  --click "＋" --input "Hello, desktop" --back artifacts/apks/notepad-v1.0.0.apk
```

The 50% project checkpoint remains an active milestone, not a measured API
coverage claim. Linux builds/native UI, broad AndroidX/Compose, JNI, networking,
JIT and games remain future work. Use trusted APKs; this is not an audited
security sandbox.

[Download v0.3.0](https://github.com/OthmaneBlial/droidless/releases/tag/v0.3.0) ·
[Website](https://othmaneblial.github.io/droidless/) ·
[Verification](../verification.md) · [Compatibility](../compatibility.md) ·
[Security](../security.md) · [Storage](../storage.md)
