Repository navigation
fix(harmonyos): recover watch provisioning after interrupted login - #3295
Merged
Merged
Conversation
wgqqqqq
marked this pull request as ready for review
October 8, 2026 08:16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A phone returning from cloud account authorization can become foreground before its session is saved, leaving watch provisioning inactive. This change starts the listener after login completes and persists an encrypted watch registration identity before contacting the relay so an interrupted handoff can replay the same request and key.
Draft: the recovery lifecycle needs further work before merge.
Type and Areas
Type: Bug fix
Areas: HarmonyOS phone account login and watch provisioning
Motivation / Impact
Verification
Passed:
node --test src/apps/mobile/harmonyos/tools/tests/watch-login-lifecycle.test.cjs src/apps/mobile/harmonyos/tools/tests/watch-provision-recovery.test.cjs— 13 tests.pnpm run harmony:architecture.src/apps/mobile/harmonyos:source scripts/ohos-env.shfollowed by"$HVIGORW" --mode module -p product=default -p module=entry@default assembleHap --no-daemon— signed HAP build succeeds.git diff --check.pnpm run mobile:architecturefails on existing shared-core contracts: one JVM test reference to the HarmonyOS tree and three public constructors with default arguments. Those files and the checker are unchanged by this PR.Additional cross-repository verification:
node --test tools/tests/device-account.test.cjsfrom/Users/user/bitfun_wearable— 8 tests passed, including v1 credential interpretation, relay public-key verification, encrypted persistence and legacy-session handling. The wearable working tree was read without modification.Remote coverage: mocked relay registration and phone-to-watch outcomes only. No live phone/watch handoff, old-relay integration, desktop provisioning fallback, compact/wide/fold transition, remote workspace, Peer Device Mode or Detached Dispatch verification was performed.
Reviewer Notes
Merge blockers / follow-up:
/Users/user/bitfun_wearableconfirms that each watch attempt uses a fresh handoff request ID and ephemeral key, while its device ID survives logout. The phone correctly reuses the original relay registration ID but answers/seals to the current handoff request. Do not delete the phone identity simply after handoff success: watch logout clears local credentials without unregistering its relay device.CloudAccountClient.provisionDevicenow clears its owned private-key copy on request/response failure while retaining ownership transfer on success. Tests cover HTTP failure and mismatched response identity.Existing wire protocol version remains 1. Local signing configuration, certificate paths, provisioning profiles and signing passwords are excluded.
Checklist