Skip to content

POS Hardware Acceptance Report

Use one report for each exact terminal, printer or scanner SKU considered for the pilot. A product-family name, web listing, “eTIMS ready” label or successful vendor demo of another application is not sufficient evidence.

Purchase snapshot

Field Evidence
Test date and location
Vendor and quotation reference
Country/market
Exact manufacturer, model and variant
Quoted price and currency
VAT, delivery and integration support included?
Warranty, return window and replacement lead time
Included charger, battery, cradle, SDK and paper

Do not place activation codes, access tokens, private keys, customer contact details, card data or complete device fingerprints in this report.

Current physical checkpoint — 17 July 2026

The Samsung SM-P619 test tablet runs Android 14/API 34 and has com.emali2.pos v0.1.0 installed. The current country-neutral hardware-UAT APK matches SHA-256 a700276eb60e4f57d76ff0b45729987e083add04762f1efdbb64e09decfa4c4f. It passed 76 unit tests in both debug and release variants, full debug lint and both APK assemblies. Its signing identity matched the installed UAT app before Android replace/data-preserving installation. MainActivity started as the top activity, the process remained running and the cleared launch log contained no fatal event. The pulled installed APK and the published immutable APK match byte-for-byte. The image is pinned at ghcr.io/mainamartin/emali2-pos-apk@sha256:f6c32767ddaa4b7d45db0fe1be4fa286db0e94c3bc7ed27c7592027aeb1a07cd. The public latest alias now points to the separately verified terminal-revocation recovery candidate. The earlier USB-printer immutable URL still matches its original 9625f5756e6c63a87bb3ef9be231b914b2a4c0cc9bead4bfbc6214b136734f14 hash. The device advertises Android USB host support; no physical printer has been accepted yet.

Recovery APK installation checkpoint — 24 July 2026

The terminal-revocation recovery APK was installed on the same Samsung SM-P619 through Android's data-preserving package replacement. Before installation, the local build matched the published immutable SHA-256 eaaa2e18372a81a509508ac1f72188546e5d145ef0f9b099a7aa13bfefa2c5cd, and apksigner showed that its signing-certificate SHA-256 matched the previously installed package. Android returned Success for the replacement. The explicit MainActivity cold start then returned Status: ok, and the application process remained running behind the device lock screen.

The post-install sanitized audit reports Android 14/API 34, security patch 2025-05-01, 3,505 MiB RAM, 50,207 MiB total data storage with 23,152 MiB available, GMS, Wi-Fi, telephony, Bluetooth, camera/autofocus and USB-host capability. com.emali2.pos remains version 0.1.0/code 1, and the pulled installed base APK exactly matches the expected recovery SHA-256. Battery was 88%. The audit emits no ADB serial, device fingerprint, customer data, application secret or peripheral identity.

This advances the terminal/application baseline only. Bluetooth remained disabled, and no USB printer-class, USB HID, external keyboard, scanner or printer was connected. Physical printer/scanner qualification, screen-led merchant sign-in, terminal activation, reboot persistence, revocation and a real customer-approved payment remain open.

Audited cash-drawer candidate — 24 July 2026

The current debug APK adds software-only cash sale/refund drawer control without claiming physical acceptance. Automatic opening is disabled until an operator sends one qualification pulse and explicitly confirms that the exact drawer opened. Each enabled business event is written to Room before hardware I/O under a unique SHA-256 event digest. Duplicate calls and crash-ambiguous REQUESTED rows never send a second pulse. The audit records only store, terminal, shift, sale/refund linkage, safe outcome and printer reference—no customer or payment-routing data.

All 86 unique Android unit tests pass in debug and release variants; debug lint, debug/release APK assembly, five isolated Room migration tests and the installed database upgrade test pass. The Samsung tablet was upgraded in place from Room v17 to v18 with three existing store rows preserved. MainActivity started and the process remained running. The local, live latest and immutable cash-drawer candidate all match SHA-256 3a28a81476aa61253f704986a4e2851d123012817917d2d66f7ba94c7f579117. The artifact image is pinned to ghcr.io/mainamartin/emali2-pos-apk@sha256:50786cb1c89b4b4cda4224f7a91ae77ffc50c09e7b99e941babd4d77da1b3d15. The download pod is Ready with zero restarts, and the previous terminal-revocation installer remains byte-identical at its immutable URL.

No drawer was connected, no qualification pulse was sent, and automatic cash-event opening therefore remains disabled. Wiring voltage, pin, pulse timing, open behavior, paper-out interaction, reboot behavior and operator procedure remain physical acceptance items.

Supervisor no-sale software checkpoint — 24 July 2026

The shift screen now offers an online-only supervisor no-sale action. The POS service accepts a cashier request only after a matching approved override, limits it to the same organization, store, terminal, open shift, cashier and action for five minutes, records an immutable zero-value NO_SALE movement, and prevents that approval from authorizing a second movement. Android then uses the server movement UUID as the duplicate-suppressed drawer business event. With automatic drawer actions disabled, the server record is retained and no hardware pulse is sent.

All 88 Android unit tests pass in debug and release variants; debug lint and both APK assemblies pass. Five Room migration tests passed on the Samsung SM-P619, and a targeted installed-app schema test passed. The debug APK SHA-256 is 3dcc2600a0c94f0086398df93a63a6f42d7c021a770511b5b5e03850cc04b224. The live latest alias and immutable supervisor no-sale candidate match that digest and are pinned to ghcr.io/mainamartin/emali2-pos-apk@sha256:10c6ba0136f5ea455d0a03b6269b546995bb9bad322e9b67465b084cafabb980.

The Gradle connected-test lifecycle removed the target package after the first update-in-place check and therefore removed its app sandbox. No backup of the previous three-row demo/store database was available. The APK was reinstalled, the targeted test was rerun manually without uninstalling the target package, and a fresh Room v18 schema remains installed with the app process launchable. This checkpoint does not claim preservation of the preceding tablet data; future managed-device checks must use manual instrumentation or take a verified app-data backup before any Gradle connected-test task.

No printer or drawer was attached, no qualification was performed, and no drawer pulse was sent.

The refreshed repeatable read-only audit recorded 3,505 MiB RAM, 50,207 MiB total data storage with at least 22,966 MiB available, security patch 2025-05-01, GMS, Wi-Fi, telephony, Bluetooth, camera/autofocus and USB-host capability. Bluetooth was disabled, NFC was absent, and no USB printer-class interface, USB HID interface or external keyboard device was present. The audit emits counts and capability state only: it does not emit the ADB serial, USB/Bluetooth identity, customer data or application secrets. Its four fake-device guard scenarios cover identifier suppression, exact-device selection, APK mismatch and an absent application.

On the same physical runtime, six application instrumentation tests passed for the foreground scan-intent adapter, bundled EAN-13 camera decoder, CameraX rear camera readiness, Android Keystore activation proof, per-request proof and signed close-pack verification. Three Room device tests passed for migrations 13-to-14, 14-to-15 and 15-to-16. Instrumentation cleanup removed the target package as expected; the immutable APK was hash-verified, reinstalled and the sanitized baseline passed again afterward.

This is a partial checkpoint, not hardware acceptance. Bluetooth was off and the Android Bluetooth manager listed no bonded printer. No external HID scanner or cash drawer was connected, and no merchant login, terminal activation or customer payment prompt was attempted. The terminal remains conditionally unaccepted until the tables below are completed with the exact printer/scanner SKU and merchant-led UAT evidence.

Android terminal identity

Check Observed value Pass/Fail
Model/variant identifier Samsung SM-P619; unnecessary device fingerprints omitted Pass for tablet baseline
Android version and API level Android 14 / API 34 Pass
OS build and security-patch date Build fingerprint omitted; patch 2025-05-01 Pass for baseline
RAM and usable storage 3,505 MiB RAM; 50,207 MiB data, at least 22,966 MiB available Pass
Google Play/GMS state GMS installed Pass
Wi-Fi, Bluetooth and cellular options Wi-Fi and telephony present; Bluetooth present but disabled Pass for capability; Bluetooth UAT open
Hardware scan engine fitted? No integrated engine claimed; no external HID scanner connected Open
Printer width, roll diameter and transport/API No printer connected; generic Bluetooth, USB and private-LAN ESC/POS software paths only Open
Printer SDK/AAR name, version and firmware compatibility No vendor SDK selected Open
SDK source, license/redistribution terms and sample-app hash Not applicable until a vendor SDK is selected Open
Printer status channel (paper/cover/job complete) No physical status channel qualified Open

Minimum pilot decision: Android 11 or newer, working P-256 Android Keystore, signed-APK installation outside a seller-controlled allow-list, enough free storage for offline catalog/sales, and a documented reset/recovery path.

Emali2 application and security

Test Expected result Pass/Fail / evidence reference
Install current UAT APK Package installs without vendor modification Pass; immutable APK restored after device tests
Verify APK SHA-256 Matches the release note before installation Pass; installed base APK matches the published hash
Cold start Sign-in gate renders without crash Pass; current build checkpoint
OIDC/PKCE redirect Opens the configured test identity origin Pass; remote identity origin reached without credentials
Terminal key generation Non-exportable P-256 key is created in Keystore Pass; physical instrumentation test
One-time activation Proof-bound activation succeeds once Open; local proof passed, no merchant code consumed
Request proof Protected mutations reject missing/replayed proof Partial; exact request signing/tamper rejection passed on device; enrolled API UAT open
Reboot and sign in Terminal binding survives; private key is not exported Open; requires merchant enrollment
Revocation Revoked terminal can no longer heartbeat or mutate Open; requires merchant enrollment

Enter the one-time code directly on the device. Never copy it into the report.

Printer qualification

Record whether the path is generic Bluetooth ESC/POS, USB/network ESC/POS, or a specific signed vendor SDK/AAR and version.

For network ESC/POS, record the printer's local hostname/IP allocation method, raw TCP port and merchant LAN/VLAN evidence. Do not record public addresses, Wi-Fi credentials or unrelated internal network details. Public destinations must be rejected by the app, and raw printing must not be exposed through an internet-facing router rule.

For a vendor SDK, verify the package against the exact terminal OS build and firmware. A guide or binary for an older model/Android release is evaluation material only. Record how initialization, command acceptance, job completion, paper-out, cover-open, high-temperature and low-voltage responses map into the country-neutral Emali2 adapter; do not expose vendor status codes to checkout.

Test Expected result Pass/Fail / evidence reference
Test receipt Correct 58 mm or 80 mm layout
Network destination guard Public destination is rejected; approved private hostname/IP connects on the configured raw port
Delivery confidence Generic one-way transport is shown as unconfirmed; only a status-capable device/SDK is shown as confirmed
Text and currency Store currency and representative accented text render
Logo and QR Legible without clipping
25 consecutive receipts No missing, duplicated or truncated job
Paper out Status-capable SDK reports paper-out; one-way SPP remains unconfirmed and never fabricates completion
Cover/temperature/voltage Status-capable SDK reports the safe mapped failure; no false device confirmation
Reload and retry Explicit retry prints once and is marked as a reprint
Sleep/wake Transport reconnects without losing the queued job
Printer power cycle Queued job survives and can be retried
Terminal reboot Local spool remains consistent
Replacement supplies Paper, battery, charger and print head are obtainable

The cash-drawer pulse remains disabled until the exact printer/drawer voltage, connector and pulse timing are qualified. Never infer a successful payment from a print or drawer event.

For Bluetooth SPP, USB bulk OUT or network raw TCP, a successful transport write is not proof of paper output. For USB, additionally verify USB host/OTG support, the temporary Android permission dialog, printer-class interface and bulk OUT endpoint, reconnect identity behavior, powered-hub requirements and whether the terminal can charge while hosting the printer. Verify that Emali2 records SUBMITTED_UNCONFIRMED, does not set printedAt, and does not automatically resend the receipt. A vendor integration may claim device-confirmed delivery only when the exact SDK exposes and passes a truthful completion/status contract on this SKU.

Scanner qualification

Test Expected result Pass/Fail / evidence reference
EAN-8 and EAN-13 labels Correct single decode
Code 128 test item Correct single decode
On-screen QR Correct decode when 2D is supported
Ten rapid scans No missed or duplicate delivery
Damaged/low-contrast label Defined failure or correct decode; no wrong item
Slow manual keyboard input Not classified as a scanner event
Background/foreground cycle Intent/HID delivery resumes safely
Reboot Configured intent profile or HID mode is restored

Record the intent action, category and extra names for integrated scanners, but do not record device secrets or identifiers that are unnecessary for support.

Connectivity, battery and offline recovery

Test Expected result Pass/Fail / evidence reference
Wi-Fi and cellular handover Heartbeat reports the new network safely
Offline cash sale Locally committed and queued exactly once
Reconnect replay Dependency-ordered batch applies exactly once
Electronic tender while offline Customer/provider prompt is refused locally
Full-shift battery test Meets the agreed shift duration with printing/scanning
Low battery and charging Health state is visible; no sale corruption

Regulatory and payment boundary

  • The selected country's fiscal adapter must pass its own sandbox/certification; this hardware report does not certify eTIMS or another tax authority.
  • A card-capable or “PDQ” terminal may handle live cards only through a licensed acquirer-approved application and integration. Emali2 must not receive PAN, PIN, track data, keys or EMV cryptograms.
  • Customer/payment-routing evidence must follow the applicable privacy, retention and processor/controller obligations.

Decision

Outcome Select one
Accepted for pilot
Conditionally accepted with listed adapter work
Rejected

Open defects, required adapter version, owner and target date: