@@ -2314,6 +2314,21 @@ leaving them buried in prose elsewhere.
23142314 itself is a direct code-reading result (no ADR needed); the interpretive reading above (that
23152315 this narrows away from, rather than confirms, ` gjv.p() ` as the connect-time burst's trigger)
23162316 is accepted for recording at 🟡 HYPOTHESIS.
2317+ ** Confirmed from the trigger side, 2026-09-16 (` ai-sessions/0025 ` , `lambda_dispatcher_resolver
2318+ resolve-all --class gag` , implementing ` ai-sessions/0024`'s own recommended "free win").**
2319+ ` gag ` 's own discriminator-15 construction site (the branch feeding ` ftw(_,9) ` /` gjv.p() ` ) is now
2320+ found: ` gjy.java:38 ` , inside a ` gjy ` method operating on a local variable literally named
2321+ ` otaApplyWorker2 ` — an independent, second confirmation (from the construction/trigger side,
2322+ not only the ` ftw.smali ` /response side already documented) that this whole chain is
2323+ OTA-apply-lifecycle-scoped throughout. ** Also corrects a separate, previously-recorded static-
2324+ analysis misattribution** (2026-09-13, ` REVERSE_ENGINEERING.md ` 's same entry): a ` 604800000 ` ms
2325+ (~ 7-day) staleness-check literal, earlier associated with this same discriminator-15 branch via
2326+ a partial JADX fragment, actually belongs to a structurally different ` gag ` branch
2327+ (discriminator 10, ` HearingWellnessNotificationWorker ` 's own unrelated notification throttle)
2328+ — ` gag ` 's discriminator-15 branch itself contains no staleness check of any kind. No periodic/
2329+ weekly gate exists on the ` GetSoftwareInfo ` /` fxm.i() ` OTA-completion path; that reading is
2330+ withdrawn. See ` REVERSE_ENGINEERING.md ` 's ` frb ` /` fuh ` /` glk ` /` gjv ` entry's 2026-09-16 update for
2331+ the full trace (command + smali evidence, all 21 of ` gag ` 's cases read, no sampling).
23172332 ** Byte-level correlation against existing capture data, 2026-09-08
23182333 (` ai-sessions/0003_MAINTENANCE_RESULT_2026_09_08.md ` Phase 4 item 2) — a plausible structural
23192334 match found, not a confirmed one; full closure still needs a fresh capture.** Per this
@@ -2433,11 +2448,25 @@ leaving them buried in prose elsewhere.
24332448 category, ` CATEGORY_RV_BLOCK_AUTO_TEST ` ). Case 2104 also fires a second, non-` qhr ` write to the
24342449 same "Feature A" mechanism as case ` 2115 ` — 🟡 plausible, unconfirmed lead that toggling
24352450 Multipoint here disables a mutually-exclusive feature (Spatial Audio is a plausible, unevidenced
2436- candidate). ** Head gestures (field 29) is NOT among these 6 mappings** — none of the 6 cases
2451+ candidate). ** Update (2026-09-16, ` ai-sessions/0025 ` , cross-referencing ` ai-sessions/0024 ` 's
2452+ own ` esk ` discriminator-18 finding against this item):** the "Feature A" mechanism's own write
2453+ call site is now located at the code level — ` ftf.java:312 ` (` esk ` discriminator 18), logging
2454+ ` "Disabling Feature A for %s" ` /` "Failed to disable Feature A for %s" ` and writing through
2455+ ` ftf.f.f(deviceId, false) ` — the same accessor class (` ftf ` ) already used throughout this
2456+ pipeline. This is the same mechanism this item already names, now with a concrete file+line
2457+ citation rather than only case IDs 2104/2115 — still 🟡 HYPOTHESIS/code-level, no wire capture
2458+ has observed this specific write firing; see ` REVERSE_ENGINEERING.md ` 's ` esk ` entry.
2459+ ** Head gestures (field 29) is NOT among these 6 mappings** — none of the 6 cases
24372460 route to ` fyo ` 's field-29 write path; this specific lead is now a checked negative, not merely
24382461 still open. Two ` qhr ` field-register corrections surfaced as a byproduct: field 6 has a real
2439- write site (previously wrongly recorded as "not found"); field 32 (new) is now registered. Full
2440- trace: ` REVERSE_ENGINEERING.md ` 's ` MaestroDeviceSettingsProviderService ` entry. Field 2's
2462+ write site (previously wrongly recorded as "not found"); field 32 (new) is now registered.
2463+ ** Field 6's own caller, left unfound by this update, was found 2026-09-16 (` ai-sessions/0025 ` ,
2464+ ` structural_index refs ` ): ` guy.java ` 's ` b() ` /` c() ` OOBE-mode lifecycle toggle, logging
2465+ ` "Enable OOBE mode" ` /` "Disable OOBE mode" ` ** — 🟡 HYPOTHESIS (code-level only): field 6 is
2466+ plausibly a transient "OOBE mode active" state flag, distinct from field 3's already-documented
2467+ completion flag; see ` REVERSE_ENGINEERING.md ` 's ` qhr ` entry's own 2026-09-16 update for the full
2468+ trace (via the same abstract-interface-indirection technique that found ` gjv.p() ` 's caller).
2469+ Full trace: ` REVERSE_ENGINEERING.md ` 's ` MaestroDeviceSettingsProviderService ` entry. Field 2's
24412470 promotion above and the case-2104/` fpm.ENABLED_HEAD_GESTURES ` naming tension were both reviewed
24422471 directly by the maintainer in the chat session that authored this task's own prompt
24432472 (` ai-sessions/0003_MAINTENANCE_PROMPT_2026_09_08.md ` ); the naming tension was left open, not
@@ -2476,6 +2505,24 @@ leaving them buried in prose elsewhere.
24762505 ` com.google.android.apps.pixel.dcservice ` — a genuinely new, incidental finding, out of scope
24772506 for this project's own Bluetooth focus). Full trace: ` REVERSE_ENGINEERING.md ` 's
24782507 ` MaestroEndpointService ` entry.
2508+ ** Update (2026-09-16, ` ai-sessions/0025 ` , ` structural_index refs ` ) — the multibinding assembly
2509+ site remains unfound; a promising-looking new lead checked and ruled out.** ` ofd ` 's 3
2510+ implementations (` mie ` /` oex ` /` ofb ` ) are confirmed to be the only ones in this APK version, and
2511+ 3 new classes holding ` ofd ` -typed fields were found (` ofh ` /` ofi ` /` ofj ` ) — but reading them
2512+ shows they are generic ` io.grpc ` -shaped transport-builder plumbing (a default-policy field on
2513+ a transport factory), not ` MaestroEndpointService ` 's own specific service-registration map.
2514+ 🔴 still open. Full trace: ` REVERSE_ENGINEERING.md ` 's ` MaestroEndpointService ` entry's own
2515+ 2026-09-16 update.
2516+ - [ ] ** Added 2026-09-16 (` ai-sessions/0025 ` , Phase 3 item L — full ` AndroidManifest.xml `
2517+ re-review).** A previously-uncatalogued exported broadcast receiver,
2518+ ` com.google.android.apps.wearables.maestro.companion.phone.bluetoothpriority.BluetoothPriorityReceiver ` ,
2519+ handles a custom action (` ACTION_TRIGGER_CLASSIC_CONNECTION_PRIORITY ` , extras ` EXTRA_BD_ADDR ` /
2520+ ` EXTRA_PRIORITY ` /` EXTRA_DATA_DIRECTION ` ) and holds a direct field of type ` fzd `
2521+ (` InternalRfcommUuidRegistry ` , already used by ` gbm ` 's socket-selection logic, ` PROTOCOL.md `
2522+ §2.2a). 🔴 ** OPEN QUESTION** : what sends this broadcast, what it accomplishes on the wire, and
2523+ whether it relates to Multipoint or RFCOMM-channel-priority behavior — none of this determined
2524+ by static analysis alone; no capture correlation attempted. See ` REVERSE_ENGINEERING.md ` 's new
2525+ ` BluetoothPriorityReceiver ` entry.
24792526
24802527### Behavior
24812528
0 commit comments