POS Hardware Acceptance Report
Use one report for each exact terminal, printer or scanner SKU considered for the pilot. A product-family name, web listing, “eTIMS ready” label or successful vendor demo of another application is not sufficient evidence.
Purchase snapshot
| Field | Evidence |
|---|---|
| Test date and location | |
| Vendor and quotation reference | |
| Country/market | |
| Exact manufacturer, model and variant | |
| Quoted price and currency | |
| VAT, delivery and integration support included? | |
| Warranty, return window and replacement lead time | |
| Included charger, battery, cradle, SDK and paper |
Do not place activation codes, access tokens, private keys, customer contact details, card data or complete device fingerprints in this report.
Android 16/API 36 source checkpoint — 26 July 2026
The current source compiles and targets API 36 while retaining minSdk 26.
Resource processing and Kotlin compilation pass with the Android 36 SDK. The
activity explicitly enables edge-to-edge before Compose content; cashier,
sign-in and camera controls apply status/navigation/safe-drawing insets; and
the manifest contains no orientation, non-resizable or temporary large-screen
compatibility escape.
Application backup is disabled. Both legacy and Android 12+ extraction rules exclude the full credential, preference, database, file, device-protected and external domains from cloud backup and device transfer. A CI guard enforces this platform boundary. The current API 36-targeting candidate has now replaced the previous APK on the Android 14 Samsung tablet, but that does not substitute for an install and UI acceptance pass on a physical API 36 device.
Current APK physical checkpoint — 27 July 2026
The current debug APK was installed on the Samsung SM-P619 test tablet through
Android's data-preserving package replacement. Before installation,
apksigner proved that the installed package and candidate had the same
signing certificate. Android returned Success; no uninstall or application
data clear was performed. An explicit cold launch returned Status: ok, and
the application process remained running afterward.
The pulled installed base APK now exactly matches the locally verified
SHA-256
b0ea9bcdaac32f4d5767a9b416ec732b79978957a256fe12b58c498be0266afb.
The sanitized post-install audit reports baseline_pass=true on Android
14/API 34 with security patch 2025-05-01, 3,505 MiB RAM, 50,207 MiB total
data storage and 23,560 MiB available. GMS, Wi-Fi, cellular, Bluetooth,
camera/autofocus and USB-host capability are present. Bluetooth was disabled.
No USB printer-class interface, HID interface, external keyboard, scanner or
printer was connected, so no peripheral acceptance is claimed.
A connected Samsung SM-S938B provided a separate read-only Android 16/API 36 capability audit. It has GMS, USB host, Bluetooth, camera/autofocus, NFC, cellular and Wi-Fi, but the POS package is not installed. No installation or customer-application interaction was performed. This is useful compatibility inventory only; API 36 install, edge-to-edge, rotation, split-screen and merchant workflow acceptance remain open.
Both audits suppress ADB serials and USB/Bluetooth identities and read no customer data or application secrets.
Current physical checkpoint — 17 July 2026
The Samsung SM-P619 test tablet runs Android 14/API 34 and has
com.emali2.pos v0.1.0 installed. The current country-neutral hardware-UAT APK
matches
SHA-256
a700276eb60e4f57d76ff0b45729987e083add04762f1efdbb64e09decfa4c4f.
It passed 76 unit tests in both debug and release variants, full debug lint and
both APK assemblies. Its signing identity matched the installed UAT app before
Android replace/data-preserving installation. MainActivity started as the top
activity, the process remained running and the cleared launch log contained no
fatal event. The pulled installed APK and the
published immutable APK
match byte-for-byte. The image is pinned at
ghcr.io/mainamartin/emali2-pos-apk@sha256:f6c32767ddaa4b7d45db0fe1be4fa286db0e94c3bc7ed27c7592027aeb1a07cd.
The public latest alias now points to the separately verified
terminal-revocation recovery candidate.
The earlier USB-printer immutable URL still matches its original
9625f5756e6c63a87bb3ef9be231b914b2a4c0cc9bead4bfbc6214b136734f14
hash. The device advertises Android USB host support; no physical printer has
been accepted yet.
Recovery APK installation checkpoint — 24 July 2026
The terminal-revocation recovery APK was installed on the same Samsung
SM-P619 through Android's data-preserving package replacement. Before
installation, the local build matched the published immutable SHA-256
eaaa2e18372a81a509508ac1f72188546e5d145ef0f9b099a7aa13bfefa2c5cd,
and apksigner showed that its signing-certificate SHA-256 matched the
previously installed package. Android returned Success for the replacement.
The explicit MainActivity cold start then returned Status: ok, and the
application process remained running behind the device lock screen.
The post-install sanitized audit reports Android 14/API 34, security patch
2025-05-01, 3,505 MiB RAM, 50,207 MiB total data storage with 23,152 MiB
available, GMS, Wi-Fi, telephony, Bluetooth, camera/autofocus and USB-host
capability. com.emali2.pos remains version 0.1.0/code 1, and the pulled
installed base APK exactly matches the expected recovery SHA-256. Battery was
88%. The audit emits no ADB serial, device fingerprint, customer data,
application secret or peripheral identity.
This advances the terminal/application baseline only. Bluetooth remained disabled, and no USB printer-class, USB HID, external keyboard, scanner or printer was connected. Physical printer/scanner qualification, screen-led merchant sign-in, terminal activation, reboot persistence, revocation and a real customer-approved payment remain open.
Audited cash-drawer candidate — 24 July 2026
The current debug APK adds software-only cash sale/refund drawer control without
claiming physical acceptance. Automatic opening is disabled until an operator
sends one qualification pulse and explicitly confirms that the exact drawer
opened. Each enabled business event is written to Room before hardware I/O
under a unique SHA-256 event digest. Duplicate calls and crash-ambiguous
REQUESTED rows never send a second pulse. The audit records only store,
terminal, shift, sale/refund linkage, safe outcome and printer reference—no
customer or payment-routing data.
All 86 unique Android unit tests pass in debug and release variants; debug lint,
debug/release APK assembly, five isolated Room migration tests and the installed
database upgrade test pass. The Samsung tablet was upgraded in place from Room
v17 to v18 with three existing store rows preserved. MainActivity started and
the process remained running. The local, live latest and
immutable cash-drawer candidate
all match SHA-256
3a28a81476aa61253f704986a4e2851d123012817917d2d66f7ba94c7f579117.
The artifact image is pinned to
ghcr.io/mainamartin/emali2-pos-apk@sha256:50786cb1c89b4b4cda4224f7a91ae77ffc50c09e7b99e941babd4d77da1b3d15.
The download pod is Ready with zero restarts, and the previous
terminal-revocation installer remains byte-identical at its immutable URL.
No drawer was connected, no qualification pulse was sent, and automatic cash-event opening therefore remains disabled. Wiring voltage, pin, pulse timing, open behavior, paper-out interaction, reboot behavior and operator procedure remain physical acceptance items.
Supervisor no-sale software checkpoint — 24 July 2026
The shift screen now offers an online-only supervisor no-sale action. The POS
service accepts a cashier request only after a matching approved override,
limits it to the same organization, store, terminal, open shift, cashier and
action for five minutes, records an immutable zero-value NO_SALE movement,
and prevents that approval from authorizing a second movement. Android then
uses the server movement UUID as the duplicate-suppressed drawer business
event. With automatic drawer actions disabled, the server record is retained
and no hardware pulse is sent.
All 88 Android unit tests pass in debug and release variants; debug lint and
both APK assemblies pass. Five Room migration tests passed on the Samsung
SM-P619, and a targeted installed-app schema test passed. The debug APK SHA-256
is 3dcc2600a0c94f0086398df93a63a6f42d7c021a770511b5b5e03850cc04b224.
The live latest alias and
immutable supervisor no-sale candidate
match that digest and are pinned to
ghcr.io/mainamartin/emali2-pos-apk@sha256:10c6ba0136f5ea455d0a03b6269b546995bb9bad322e9b67465b084cafabb980.
The Gradle connected-test lifecycle removed the target package after the first update-in-place check and therefore removed its app sandbox. No backup of the previous three-row demo/store database was available. The APK was reinstalled, the targeted test was rerun manually without uninstalling the target package, and a fresh Room v18 schema remains installed with the app process launchable. This checkpoint does not claim preservation of the preceding tablet data; future managed-device checks must use manual instrumentation or take a verified app-data backup before any Gradle connected-test task.
No printer or drawer was attached, no qualification was performed, and no drawer pulse was sent.
The refreshed repeatable read-only audit recorded 3,505 MiB RAM, 50,207 MiB total data
storage with at least 22,966 MiB available, security patch 2025-05-01, GMS,
Wi-Fi, telephony, Bluetooth, camera/autofocus and USB-host capability. Bluetooth
was disabled, NFC was absent, and no USB printer-class interface, USB HID
interface or external keyboard device was present. The audit emits counts and
capability state only: it does not emit the ADB serial, USB/Bluetooth identity,
customer data or application secrets. Its four fake-device guard scenarios
cover identifier suppression, exact-device selection, APK mismatch and an
absent application.
On the same physical runtime, six application instrumentation tests passed for the foreground scan-intent adapter, bundled EAN-13 camera decoder, CameraX rear camera readiness, Android Keystore activation proof, per-request proof and signed close-pack verification. Three Room device tests passed for migrations 13-to-14, 14-to-15 and 15-to-16. Instrumentation cleanup removed the target package as expected; the immutable APK was hash-verified, reinstalled and the sanitized baseline passed again afterward.
This is a partial checkpoint, not hardware acceptance. Bluetooth was off and the Android Bluetooth manager listed no bonded printer. No external HID scanner or cash drawer was connected, and no merchant login, terminal activation or customer payment prompt was attempted. The terminal remains conditionally unaccepted until the tables below are completed with the exact printer/scanner SKU and merchant-led UAT evidence.
Android terminal identity
| Check | Observed value | Pass/Fail |
|---|---|---|
| Model/variant identifier | Samsung SM-P619; unnecessary device fingerprints omitted | Pass for tablet baseline |
| Android version and API level | Android 14 / API 34 | Pass |
| OS build and security-patch date | Build fingerprint omitted; patch 2025-05-01 |
Pass for baseline |
| RAM and usable storage | 3,505 MiB RAM; 50,207 MiB data, at least 22,966 MiB available | Pass |
| Google Play/GMS state | GMS installed | Pass |
| Installed APK target/min SDK | Current installed candidate is built with target 36/min 26 and passed the API 34 tablet baseline | Pass for API 34 candidate; API 36 physical install open |
| Wi-Fi, Bluetooth and cellular options | Wi-Fi and telephony present; Bluetooth present but disabled | Pass for capability; Bluetooth UAT open |
| Hardware scan engine fitted? | No integrated engine claimed; no external HID scanner connected | Open |
| Printer width, roll diameter and transport/API | No printer connected; generic Bluetooth, USB and private-LAN ESC/POS software paths only | Open |
| Printer SDK/AAR name, version and firmware compatibility | No vendor SDK selected | Open |
| SDK source, license/redistribution terms and sample-app hash | Not applicable until a vendor SDK is selected | Open |
| Printer status channel (paper/cover/job complete) | No physical status channel qualified | Open |
Minimum pilot decision: Android 11 or newer, working P-256 Android Keystore, signed-APK installation outside a seller-controlled allow-list, enough free storage for offline catalog/sales, and a documented reset/recovery path.
Emali2 application and security
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| Install current UAT APK | Package installs without vendor modification | Pass; current APK installed in place on 27 July 2026 |
| Verify APK SHA-256 | Matches the release note before installation | Pass; installed base APK matches b0ea9bcd…26e6afb |
| Cold start | Sign-in gate renders without crash | Pass; explicit launch returned Status: ok and process remained running |
| Edge-to-edge and rotation | No clipped controls in portrait/landscape, gesture/three-button navigation, tablet/split-screen widths | Open for API 36 physical candidate |
| OIDC/PKCE redirect | Opens the configured test identity origin | Pass; remote identity origin reached without credentials |
| Terminal key generation | Non-exportable P-256 key is created in Keystore | Pass; physical instrumentation test |
| One-time activation | Proof-bound activation succeeds once | Open; local proof passed, no merchant code consumed |
| Request proof | Protected mutations reject missing/replayed proof | Partial; exact request signing/tamper rejection passed on device; enrolled API UAT open |
| Reboot and sign in | Terminal binding survives; private key is not exported | Open; requires merchant enrollment |
| Revocation | Revoked terminal can no longer heartbeat or mutate | Open; requires merchant enrollment |
| Backup/device-transfer exclusion | Replacement install receives no restored Room, OIDC, terminal binding, spool or operational evidence | Open for managed reset/replacement test |
Enter the one-time code directly on the device. Never copy it into the report.
Printer qualification
Record whether the path is generic Bluetooth ESC/POS, USB/network ESC/POS, or a specific signed vendor SDK/AAR and version.
For network ESC/POS, record the printer's local hostname/IP allocation method, raw TCP port and merchant LAN/VLAN evidence. Do not record public addresses, Wi-Fi credentials or unrelated internal network details. Public destinations must be rejected by the app, and raw printing must not be exposed through an internet-facing router rule.
For a vendor SDK, verify the package against the exact terminal OS build and firmware. A guide or binary for an older model/Android release is evaluation material only. Record how initialization, command acceptance, job completion, paper-out, cover-open, high-temperature and low-voltage responses map into the country-neutral Emali2 adapter; do not expose vendor status codes to checkout.
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| Test receipt | Correct 58 mm or 80 mm layout | |
| Network destination guard | Public destination is rejected; approved private hostname/IP connects on the configured raw port | |
| Delivery confidence | Generic one-way transport is shown as unconfirmed; only a status-capable device/SDK is shown as confirmed | |
| Text and currency | Store currency and representative accented text render | |
| Logo and QR | Legible without clipping | |
| 25 consecutive receipts | No missing, duplicated or truncated job | |
| Paper out | Status-capable SDK reports paper-out; one-way SPP remains unconfirmed and never fabricates completion | |
| Cover/temperature/voltage | Status-capable SDK reports the safe mapped failure; no false device confirmation | |
| Reload and retry | Explicit retry prints once and is marked as a reprint | |
| Sleep/wake | Transport reconnects without losing the queued job | |
| Printer power cycle | Queued job survives and can be retried | |
| Terminal reboot | Local spool remains consistent | |
| Replacement supplies | Paper, battery, charger and print head are obtainable |
The cash-drawer pulse remains disabled until the exact printer/drawer voltage, connector and pulse timing are qualified. Never infer a successful payment from a print or drawer event.
For Bluetooth SPP, USB bulk OUT or network raw TCP, a successful transport write
is not proof of paper output. For USB, additionally verify USB host/OTG support,
the temporary Android permission dialog, printer-class interface and bulk OUT
endpoint, reconnect identity behavior, powered-hub requirements and whether the
terminal can charge while hosting the printer.
Verify that Emali2 records SUBMITTED_UNCONFIRMED, does not set printedAt, and
does not automatically resend the receipt. A vendor integration may claim
device-confirmed delivery only when the exact SDK exposes and passes a truthful
completion/status contract on this SKU.
Scanner qualification
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| EAN-8 and EAN-13 labels | Correct single decode | |
| Code 128 test item | Correct single decode | |
| On-screen QR | Correct decode when 2D is supported | |
| Ten rapid scans | No missed or duplicate delivery | |
| Damaged/low-contrast label | Defined failure or correct decode; no wrong item | |
| Slow manual keyboard input | Not classified as a scanner event | |
| Background/foreground cycle | Intent/HID delivery resumes safely | |
| Reboot | Configured intent profile or HID mode is restored |
Record the intent action, category and extra names for integrated scanners, but do not record device secrets or identifiers that are unnecessary for support.
Connectivity, battery and offline recovery
| Test | Expected result | Pass/Fail / evidence reference |
|---|---|---|
| Wi-Fi and cellular handover | Heartbeat reports the new network safely | |
| Offline cash sale | Locally committed and queued exactly once | |
| Reconnect replay | Dependency-ordered batch applies exactly once | |
| Electronic tender while offline | Customer/provider prompt is refused locally | |
| Full-shift battery test | Meets the agreed shift duration with printing/scanning | |
| Low battery and charging | Health state is visible; no sale corruption |
Regulatory and payment boundary
- The selected country's fiscal adapter must pass its own sandbox/certification; this hardware report does not certify eTIMS or another tax authority.
- A card-capable or “PDQ” terminal may handle live cards only through a licensed acquirer-approved application and integration. Emali2 must not receive PAN, PIN, track data, keys or EMV cryptograms.
- Customer/payment-routing evidence must follow the applicable privacy, retention and processor/controller obligations.
Decision
| Outcome | Select one |
|---|---|
| Accepted for pilot | ☐ |
| Conditionally accepted with listed adapter work | ☐ |
| Rejected | ☐ |
Open defects, required adapter version, owner and target date: