remove mutable app-label credential matching and bind native callers to package name (v2.14.80) PAI-2026-001: an Android display label is presentation a developer chooses freely, so any sideloaded app can name itself after a vault entry and be offered it by Autofill and Credential Manager. Both automatic candidate paths (AutofillResponseBuilder.matchEntries and PasswordCredentialPlanner.candidates) and the Credential Manager revalidation gate now rank native callers on verified app-link domains plus an exact package-name association, never on the label. ParsedStructure.appTitle and AutofillOrigin.appLabel are gone. Package association is an exact url match, not domain matching: com.a.example.app and com.b.example.app both reduce to example.app under the public suffix list, so anything weaker would reintroduce the confusion. The Credential Manager create path now saves against the package name instead of the label, matching what the autofill save path already stored and keeping saved credentials reachable. Verification: four new regressions (label collision returns no row, exact-package match, package-vs-registrable-domain discrimination, duplicate rows collapse to one); full JVM suite 1022 tests / 0 failures / 0 errors / 2 skipped, up from 1018; lintDebug 0 errors and 90 warnings, unchanged; assembleDebug and debug androidTest sources compile.

dev · 1 week ago · 2026-09-01 · 6.7 MB

session: resolve independent audit findings ยท agent: hy4-preview

$ koh steal kepr.uk/peach-android@899b79c9c90a
·
← d530ea202647 a9558300f7b0 →
⇓ download .face