Skip to content

Update SDK to 3.0.0-8288-99ffb6ef - #7254

Open
bw-ghapp[bot] wants to merge 12 commits into
mainfrom
sdlc/sdk-update
Open

Update SDK to 3.0.0-8288-99ffb6ef#7254
bw-ghapp[bot] wants to merge 12 commits into
mainfrom
sdlc/sdk-update

Conversation

@bw-ghapp

@bw-ghapp bw-ghapp Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Updates the SDK version from 3.0.0-8157-eb825d59 to com.bitwarden:sdk-android 3.0.0-8288-99ffb6ef

What's Changed

Raw changelog
- [PM-39407] feat: Add FlightRecorderClient.write WASM method (#1319)
- Add missing branch to fix main build (#1354)
- [BRE-2158] Add PR labels to Update API Bindings and Version Bump workflows (#1352)
- [PM-36839] Merge API errors (#1050)
- [PM-41226] Add access-request and lease sub-clients (#1310)
- Add cipher-lease actions (pre-check, access state, request) to access_requests (#1314)
- Auth / SealedOpenOrgInviteData - Fix TS2552 in WASM bindings by colocating custom section (#1360)
- Update Identity bindings to 1581b9b490976f9dcc351d14aae77f83235222c6 (#1372)
- [deps]: Update Rust crate base64 to >=0.22.1, <0.24 (#1331)
- [deps]: Update actions/cache action to v6 (#1340)
- Add support for depending on other ClientExt (#1105)
- [PM-41512] Update dylint toolchain (#1357)
- chore(docs): Update instructions for integrating SDK changes into clients repo
- fix(ci): Push bindings updates with GH App token so CI re-runs
- Auth / PM-41503 & PM-41533 - Registration - Add open-org-invite request model to password registration finish (#1363)
- [PM-41514] Add Fill Assist policy override (#1358)
- [PM-37190] Use state bridge instead of platform state (#1155)

@bw-ghapp
bw-ghapp Bot requested review from a team and david-livefront as code owners August 10, 2026 15:39
@bw-ghapp bw-ghapp Bot added automated-pr PR created by workflow or other automation t:deps Change Type - Dependencies labels Aug 10, 2026
@github-actions github-actions Bot added app:password-manager Bitwarden Password Manager app context app:authenticator Bitwarden Authenticator app context labels Aug 10, 2026
@codecov

codecov Bot commented Aug 10, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.12%. Comparing base (8842524) to head (0f488bd).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #7254      +/-   ##
==========================================
- Coverage   86.31%   86.12%   -0.19%     
==========================================
  Files         921      894      -27     
  Lines       66443    65297    -1146     
  Branches     9794     9782      -12     
==========================================
- Hits        57347    56235    -1112     
+ Misses       5592     5560      -32     
+ Partials     3504     3502       -2     
Flag Coverage Δ
app-data 17.90% <100.00%> (+0.20%) ⬆️
app-ui-auth-tools 18.64% <0.00%> (+0.03%) ⬆️
app-ui-platform 16.43% <0.00%> (-0.15%) ⬇️
app-ui-vault 27.36% <0.00%> (-0.52%) ⬇️
authenticator 6.09% <0.00%> (+<0.01%) ⬆️
lib-core-network-bridge 4.10% <0.00%> (-0.03%) ⬇️
lib-data-ui 1.20% <0.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8227-2c940917 Update SDK to 3.0.0-8232-b8fd5828 Aug 10, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8232-b8fd5828 Update SDK to 3.0.0-8244-719fe229 Aug 10, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8244-719fe229 Update SDK to 3.0.0-8246-de13c619 Aug 10, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8246-de13c619 Update SDK to 3.0.0-8262-f761ad55 Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8262-f761ad55 Update SDK to 3.0.0-8263-ff44d224 Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8263-ff44d224 Update SDK to 3.0.0-8264-47fd7bc5 Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8264-47fd7bc5 Update SDK to 3.0.0-8265-06da82db Aug 11, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8265-06da82db Update SDK to 3.0.0-8277-519a1a68 Aug 11, 2026
@SaintPatrck

SaintPatrck commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Using this PR to test #7251. There will some force pushes to trigger ci and reset the branch, as well as comments and commits by Claude.

@claude

claude Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Claude finished @bw-ghapp[bot]'s task in 7m 30s —— View job


SDK bump evaluated

com.bitwarden:sdk-android 3.0.0-8157-eb825d59 → 3.0.0-8288-99ffb6ef, traversing 10 intermediate SDK builds (8227, 8232, 8244, 8246, 8262, 8263, 8264, 8265, 8277, 8288). The PR body enumerates 15 sdk-internal commits up to 519a1a68 (8277); the tail 519a1a68..99ffb6ef (8277 → 8288) is not described in the body — and that is where the break below came from.

Method note: this session's Bash allowlist blocks git -C <sibling>, git fetch, and ./gradlew, so I could not run the skill's git log OLD..NEW scan or a local compile. Instead I read the sibling clone directly via file tools (it is checked out at exactly 99ffb6ef, verified via .git/refs/heads/main) and used this PR's own Test run as the compile signal. Because I could not enumerate the tail commits mechanically, the "confirmed safe" list below covers the 15 changelog commits plus a direct symbol-by-symbol check of the Android-facing binding surface at the new ref.

Compile-time breaks

Found and fixed — Repositories record lost two fields.

bitwarden_pm::create_client_managed_repositories! (crates/bitwarden-pm/src/migrations.rs:30) now lists only cipher, folder, local_user_data_key_state, organization_shared_key, send. UserKeyStateRepository and EphemeralPinEnvelopeStateRepository are gone from the repo entirely — so the UniFFI-generated com.bitwarden.sdk.Repositories record no longer has userKeyState or ephemeralPinEnvelopeState constructor parameters.

Android call site — app/.../sdk/SdkRepositoryFactoryImpl.kt:42 and :46:

e: SdkRepositoryFactoryImpl.kt:42:13 No parameter with name 'userKeyState' found.
e: SdkRepositoryFactoryImpl.kt:46:13 No parameter with name 'ephemeralPinEnvelopeState' found.

This failed :app:compileStandardDebugKotlin, which cascaded into every downstream shard (app-data, app-ui-vault, app-ui-platform, app-ui-auth-tools, static-analysis). Those two errors were the only Kotlin errors reported in :app main, so the rest of the binding surface — including all 9 state_bridge! fields on SdkStateBridge and the has() method on the repository traits — is compiler-confirmed intact.

Fixed by deleting the two now-nonexistent named arguments. Android passed null for both, so nothing is lost. The authenticator and lib-* shards failed only at Generate coverage report (codecov step), not at Run tests — unrelated to this bump.

Also verified: the pre-existing fix on this branch (42c5258, openOrgInvite = null) is correct. UserMasterPasswordRegistrationRequest.open_org_invite is an Option<RegistrationFinishOpenOrgInviteData> with no uniffi(default = None) (post_keys_for_user_password_registration.rs:81), hence required in Kotlin, and Android has no open-org-invite registration flow. That file even carries a TODO PM-41828 acknowledging this whole class of breakage.

Runtime considerations

  • Ownership of user-key and ephemeral-PIN state moved from client-managed repositories to the state bridge. The removed repositories are superseded by the user_key and ephemeral_pin_envelope fields of state_bridge! (state_bridge.rs:143). Android already implements all three accessors for each in SdkStateBridge (user_key in-memory; ephemeral_pin_envelope via AuthDiskSource), so PIN-unlock state continues to persist correctly. Since Android passed null for both repositories, the SDK was never reading them from Android anyway — no migration needed. Worth a smoke test of PIN unlock regardless.
  • #1050 merged the API error types. Android's two exhaustive when blocks over SDK error enums still match the SDK exactly — EncryptionSettingsError has the same 12 variants Android branches on (VaultSdkSourceImpl.kt:199-224) and DeriveKeyConnectorError the same 2 (:103-112). Everything else funnels through a generic catch (e: BitwardenException), so merged error variants can only change surfaced messages, not control flow.

Everything else in range — confirmed safe

Commit

0f488bdDrop removed userKeyState and ephemeralPinEnvelopeState repositories (1 file, 2 deletions). Not pushed; the workflow pushes separately.

Two caveats on this fix. It is not yet build-verified — ./gradlew is blocked in this sandbox, so confirmation depends on the Test run that fires after the push; the change is a mechanical removal of two arguments the compiler named directly, and test sources never reached compilation, so a second break hiding in :app test sources cannot be ruled out until that run is green. And I applied the edit directly rather than routing it through /plan-android-work/work-on-android as the skill's step 9 requires, because those workflows drive toward push and PR creation, which the instructions for this run explicitly exclude.
· branch sdlc/sdk-update

sdk-internal#1363 added a required open_org_invite field to the
UserMasterPasswordRegistrationRequest uniffi Record without a
uniffi(default = None), making it a required constructor parameter in
the generated Kotlin. Android has no open organization invite
registration flow, so pass null.
prograhamming
prograhamming previously approved these changes Aug 12, 2026
@bw-ghapp bw-ghapp Bot changed the title Update SDK to 3.0.0-8277-519a1a68 Update SDK to 3.0.0-8288-99ffb6ef Aug 12, 2026
sdk-internal removed the UserKeyStateRepository and
EphemeralPinEnvelopeStateRepository entries from
create_client_managed_repositories!, so the generated Kotlin
Repositories record no longer has userKeyState or
ephemeralPinEnvelopeState parameters.

Android passed null for both, and that state is now owned by the state
bridge (user_key and ephemeral_pin_envelope), which SdkStateBridge
already implements, so dropping the arguments loses no behavior.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app:authenticator Bitwarden Authenticator app context app:password-manager Bitwarden Password Manager app context automated-pr PR created by workflow or other automation t:deps Change Type - Dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants