POS Hardware Acceptance Report
Use one report for each exact terminal, printer or scanner SKU considered for the pilot. A product-family name, web listing, “eTIMS ready” label or successful vendor demo of another application is not sufficient evidence.
Purchase snapshot
| Field | Evidence |
|---|---|
| Test date and location | |
| Vendor and quotation reference | |
| Country/market | |
| Exact manufacturer, model and variant | |
| Quoted price and currency | |
| VAT, delivery and integration support included? | |
| Warranty, return window and replacement lead time | |
| Included charger, battery, cradle, SDK and paper |
Do not place activation codes, access tokens, private keys, customer contact details, card data or complete device fingerprints in this report.
Current physical checkpoint — 17 July 2026
The Samsung SM-P619 test tablet runs Android 14/API 34 and has
com.emali2.pos v0.1.0 installed. The current country-neutral hardware-UAT APK
matches
SHA-256
a700276eb60e4f57d76ff0b45729987e083add04762f1efdbb64e09decfa4c4f.
It passed 76 unit tests in both debug and release variants, full debug lint and
both APK assemblies. Its signing identity matched the installed UAT app before
Android replace/data-preserving installation. MainActivity started as the top
activity, the process remained running and the cleared launch log contained no
fatal event. The pulled installed APK and the
published immutable APK
match byte-for-byte. The image is pinned at
ghcr.io/mainamartin/emali2-pos-apk@sha256:f6c32767ddaa4b7d45db0fe1be4fa286db0e94c3bc7ed27c7592027aeb1a07cd.
The public latest alias now points to the separately verified
terminal-revocation recovery candidate.
The earlier USB-printer immutable URL still matches its original
9625f5756e6c63a87bb3ef9be231b914b2a4c0cc9bead4bfbc6214b136734f14
hash. The device advertises Android USB host support; no physical printer has
been accepted yet.
Recovery APK installation checkpoint — 24 July 2026
The terminal-revocation recovery APK was installed on the same Samsung
SM-P619 through Android's data-preserving package replacement. Before
installation, the local build matched the published immutable SHA-256
eaaa2e18372a81a509508ac1f72188546e5d145ef0f9b099a7aa13bfefa2c5cd,
and apksigner showed that its signing-certificate SHA-256 matched the
previously installed package. Android returned Success for the replacement.
The explicit MainActivity cold start then returned Status: ok, and the
application process remained running behind the device lock screen.
The post-install sanitized audit reports Android 14/API 34, security patch
2025-05-01, 3,505 MiB RAM, 50,207 MiB total data storage with 23,152 MiB
available, GMS, Wi-Fi, telephony, Bluetooth, camera/autofocus and USB-host
capability. com.emali2.pos remains version 0.1.0/code 1, and the pulled
installed base APK exactly matches the expected recovery SHA-256. Battery was
88%. The audit emits no ADB serial, device fingerprint, customer data,
application secret or peripheral identity.
This advances the terminal/application baseline only. Bluetooth remained disabled, and no USB printer-class, USB HID, external keyboard, scanner or printer was connected. Physical printer/scanner qualification, screen-led merchant sign-in, terminal activation, reboot persistence, revocation and a real customer-approved payment remain open.
Audited cash-drawer candidate — 24 July 2026
The current debug APK adds software-only cash sale/refund drawer control without
claiming physical acceptance. Automatic opening is disabled until an operator
sends one qualification pulse and explicitly confirms that the exact drawer
opened. Each enabled business event is written to Room before hardware I/O
under a unique SHA-256 event digest. Duplicate calls and crash-ambiguous
REQUESTED rows never send a second pulse. The audit records only store,
terminal, shift, sale/refund linkage, safe outcome and printer reference—no
customer or payment-routing data.
All 86 unique Android unit tests pass in debug and release variants; debug lint,
debug/release APK assembly, five isolated Room migration tests and the installed
database upgrade test pass. The Samsung tablet was upgraded in place from Room
v17 to v18 with three existing store rows preserved. MainActivity started and
the process remained running. The local, live latest and
immutable cash-drawer candidate
all match SHA-256
3a28a81476aa61253f704986a4e2851d123012817917d2d66f7ba94c7f579117.
The artifact image is pinned to
ghcr.io/mainamartin/emali2-pos-apk@sha256:50786cb1c89b4b4cda4224f7a91ae77ffc50c09e7b99e941babd4d77da1b3d15.
The download pod is Ready with zero restarts, and the previous
terminal-revocation installer remains byte-identical at its immutable URL.
No drawer was connected, no qualification pulse was sent, and automatic cash-event opening therefore remains disabled. Wiring voltage, pin, pulse timing, open behavior, paper-out interaction, reboot behavior and operator procedure remain physical acceptance items.
Supervisor no-sale software checkpoint — 24 July 2026
The shift screen now offers an online-only supervisor no-sale action. The POS
service accepts a cashier request only after a matching approved override,
limits it to the same organization, store, terminal, open shift, cashier and
action for five minutes, records an immutable zero-value NO_SALE movement,
and prevents that approval from authorizing a second movement. Android then
uses the server movement UUID as the duplicate-suppressed drawer business
event. With automatic drawer actions disabled, the server record is retained
and no hardware pulse is sent.
All 88 Android unit tests pass in debug and release variants; debug lint and
both APK assemblies pass. Five Room migration tests passed on the Samsung
SM-P619, and a targeted installed-app schema test passed. The debug APK SHA-256
is 3dcc2600a0c94f0086398df93a63a6f42d7c021a770511b5b5e03850cc04b224.
The live latest alias and
immutable supervisor no-sale candidate
match that digest and are pinned to
ghcr.io/mainamartin/emali2-pos-apk@sha256:10c6ba0136f5ea455d0a03b6269b546995bb9bad322e9b67465b084cafabb980.
The Gradle connected-test lifecycle removed the target package after the first update-in-place check and therefore removed its app sandbox. No backup of the previous three-row demo/store database was available. The APK was reinstalled, the targeted test was rerun manually without uninstalling the target package, and a fresh Room v18 schema remains installed with the app process launchable. This checkpoint does not claim preservation of the preceding tablet data; future managed-device checks must use manual instrumentation or take a verified app-data backup before any Gradle connected-test task.
No printer or drawer was attached, no qualification was performed, and no drawer pulse was sent.
The refreshed repeatable read-only audit recorded 3,505 MiB RAM, 50,207 MiB total data
storage with at least 22,966 MiB available, security patch 2025-05-01, GMS,
Wi-Fi, telephony, Bluetooth, camera/autofocus and USB-host capability. Bluetooth
was disabled, NFC was absent, and no USB printer-class interface, USB HID
interface or external keyboard device was present. The audit emits counts and
capability state only: it does not emit the ADB serial, USB/Bluetooth identity,
customer data or application secrets. Its four fake-device guard scenarios
cover identifier suppression, exact-device selection, APK mismatch and an
absent application.
On the same physical runtime, six application instrumentation tests passed for the foreground scan-intent adapter, bundled EAN-13 camera decoder, CameraX rear camera readiness, Android Keystore activation proof, per-request proof and signed close-pack verification. Three Room device tests passed for migrations 13-to-14, 14-to-15 and 15-to-16. Instrumentation cleanup removed the target package as expected; the immutable APK was hash-verified, reinstalled and the sanitized baseline passed again afterward.
This is a partial checkpoint, not hardware acceptance. Bluetooth was off and the Android Bluetooth manager listed no bonded printer. No external HID scanner or cash drawer was connected, and no merchant login, terminal activation or customer payment prompt was attempted. The terminal remains conditionally unaccepted until the tables below are completed with the exact printer/scanner SKU and merchant-led UAT evidence.
Android terminal identity
| Check | Observed value | Pass/Fail |
|---|---|---|
| Model/variant identifier | Samsung SM-P619; unnecessary device fingerprints omitted | Pass for tablet baseline |
| Android version and API level | Android 14 / API 34 | Pass |
| OS build and security-patch date | Build fingerprint omitted; patch 2025-05-01 |
Pass for baseline |
| RAM and usable storage | 3,505 MiB RAM; 50,207 MiB data, at least 22,966 MiB available | Pass |
| Google Play/GMS state | GMS installed | Pass |
| Wi-Fi, Bluetooth and cellular options | Wi-Fi and telephony present; Bluetooth present but disabled | Pass for capability; Bluetooth UAT open |
| Hardware scan engine fitted? | No integrated engine claimed; no external HID scanner connected | Open |
| Printer width, roll diameter and transport/API | No printer connected; generic Bluetooth, USB and private-LAN ESC/POS software paths only | Open |
| Printer SDK/AAR name, version and firmware compatibility | No vendor SDK selected | Open |
| SDK source, license/redistribution terms and sample-app hash | Not applicable until a vendor SDK is selected | Open |
| Printer status channel (paper/cover/job complete) | No physical status channel qualified | Open |
Minimum pilot decision: Android 11 or newer, working P-256 Android Keystore, signed-APK installation outside a seller-controlled allow-list, enough free storage for offline catalog/sales, and a documented reset/recovery path.
Emali2 application and security
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| Install current UAT APK | Package installs without vendor modification | Pass; immutable APK restored after device tests |
| Verify APK SHA-256 | Matches the release note before installation | Pass; installed base APK matches the published hash |
| Cold start | Sign-in gate renders without crash | Pass; current build checkpoint |
| OIDC/PKCE redirect | Opens the configured test identity origin | Pass; remote identity origin reached without credentials |
| Terminal key generation | Non-exportable P-256 key is created in Keystore | Pass; physical instrumentation test |
| One-time activation | Proof-bound activation succeeds once | Open; local proof passed, no merchant code consumed |
| Request proof | Protected mutations reject missing/replayed proof | Partial; exact request signing/tamper rejection passed on device; enrolled API UAT open |
| Reboot and sign in | Terminal binding survives; private key is not exported | Open; requires merchant enrollment |
| Revocation | Revoked terminal can no longer heartbeat or mutate | Open; requires merchant enrollment |
Enter the one-time code directly on the device. Never copy it into the report.
Printer qualification
Record whether the path is generic Bluetooth ESC/POS, USB/network ESC/POS, or a specific signed vendor SDK/AAR and version.
For network ESC/POS, record the printer's local hostname/IP allocation method, raw TCP port and merchant LAN/VLAN evidence. Do not record public addresses, Wi-Fi credentials or unrelated internal network details. Public destinations must be rejected by the app, and raw printing must not be exposed through an internet-facing router rule.
For a vendor SDK, verify the package against the exact terminal OS build and firmware. A guide or binary for an older model/Android release is evaluation material only. Record how initialization, command acceptance, job completion, paper-out, cover-open, high-temperature and low-voltage responses map into the country-neutral Emali2 adapter; do not expose vendor status codes to checkout.
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| Test receipt | Correct 58 mm or 80 mm layout | |
| Network destination guard | Public destination is rejected; approved private hostname/IP connects on the configured raw port | |
| Delivery confidence | Generic one-way transport is shown as unconfirmed; only a status-capable device/SDK is shown as confirmed | |
| Text and currency | Store currency and representative accented text render | |
| Logo and QR | Legible without clipping | |
| 25 consecutive receipts | No missing, duplicated or truncated job | |
| Paper out | Status-capable SDK reports paper-out; one-way SPP remains unconfirmed and never fabricates completion | |
| Cover/temperature/voltage | Status-capable SDK reports the safe mapped failure; no false device confirmation | |
| Reload and retry | Explicit retry prints once and is marked as a reprint | |
| Sleep/wake | Transport reconnects without losing the queued job | |
| Printer power cycle | Queued job survives and can be retried | |
| Terminal reboot | Local spool remains consistent | |
| Replacement supplies | Paper, battery, charger and print head are obtainable |
The cash-drawer pulse remains disabled until the exact printer/drawer voltage, connector and pulse timing are qualified. Never infer a successful payment from a print or drawer event.
For Bluetooth SPP, USB bulk OUT or network raw TCP, a successful transport write
is not proof of paper output. For USB, additionally verify USB host/OTG support,
the temporary Android permission dialog, printer-class interface and bulk OUT
endpoint, reconnect identity behavior, powered-hub requirements and whether the
terminal can charge while hosting the printer.
Verify that Emali2 records SUBMITTED_UNCONFIRMED, does not set printedAt, and
does not automatically resend the receipt. A vendor integration may claim
device-confirmed delivery only when the exact SDK exposes and passes a truthful
completion/status contract on this SKU.
Scanner qualification
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| EAN-8 and EAN-13 labels | Correct single decode | |
| Code 128 test item | Correct single decode | |
| On-screen QR | Correct decode when 2D is supported | |
| Ten rapid scans | No missed or duplicate delivery | |
| Damaged/low-contrast label | Defined failure or correct decode; no wrong item | |
| Slow manual keyboard input | Not classified as a scanner event | |
| Background/foreground cycle | Intent/HID delivery resumes safely | |
| Reboot | Configured intent profile or HID mode is restored |
Record the intent action, category and extra names for integrated scanners, but do not record device secrets or identifiers that are unnecessary for support.
Connectivity, battery and offline recovery
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| Wi-Fi and cellular handover | Heartbeat reports the new network safely | |
| Offline cash sale | Locally committed and queued exactly once | |
| Reconnect replay | Dependency-ordered batch applies exactly once | |
| Electronic tender while offline | Customer/provider prompt is refused locally | |
| Full-shift battery test | Meets the agreed shift duration with printing/scanning | |
| Low battery and charging | Health state is visible; no sale corruption |
Regulatory and payment boundary
- The selected country's fiscal adapter must pass its own sandbox/certification; this hardware report does not certify eTIMS or another tax authority.
- A card-capable or “PDQ” terminal may handle live cards only through a licensed acquirer-approved application and integration. Emali2 must not receive PAN, PIN, track data, keys or EMV cryptograms.
- Customer/payment-routing evidence must follow the applicable privacy, retention and processor/controller obligations.
Decision
| Outcome | Select one |
|---|---|
| Accepted for pilot | ☐ |
| Conditionally accepted with listed adapter work | ☐ |
| Rejected | ☐ |
Open defects, required adapter version, owner and target date: