Repository navigation
Conversation
Backgrounding should hide the wallet immediately, and resume authentication has to wait until Android will actually show the prompt. Co-authored-by: Cursor <cursoragent@cursor.com>
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
Smart E2E Test SelectionSelected E2E tags: ALL Selected Performance tags@PerformanceLaunch AI Confidence: 100 E2E reasoningExpand to readThis PR is a major refactoring of the app lock/privacy screen system that touches critical authentication and app lifecycle paths:
The lock/unlock mechanism is fundamental to the entire app. Every E2E test flow involves the app being in an unlocked state, and changes to how locking/unlocking works can break any test. The removal of the LockScreen route, the new native privacy cover, and the refactored authentication flow all represent critical changes that could affect:
The hard rule seed already selected ALL tags, and this analysis confirms that selection is appropriate given the critical nature of these changes. Performance reasoningExpand to readThe PR changes app startup (index.js now calls AppLockService.initialize() before Engine), which could affect cold start time and time-to-interactive (@PerformanceLaunch). The refactored lock/unlock mechanism (new AppLockService replacing LockManagerService + AppStateService, new native PrivacyCover modules, biometric unlock flow changes) could affect login and unlock performance (@PerformanceLogin). These are the most directly impacted performance scenarios. |
|
|
| Platform | Device | Reason | Recording |
|---|---|---|---|
| Android | Google Pixel 8 Pro (v14.0) | no_performance_metrics | 📹 Watch |
🔬 App profiling check · Current run 37576952055 · Baseline (last green on main) run 36822962196 @ 1bddfa4
Summary:
ℹ️ API calls unavailable:
Network logs API error: Bad Request
Full metric table (+10% variance rules)
Disclaimer — allowed variance: a +10% margin over the baseline is permitted.
- If
Current <= Baseline + 10%, treated as acceptable noise.- If
Current > Baseline + 10%, Current and variance % are highlighted with⚠️ .
| Metric | Baseline | Current | Δ |
|---|---|---|---|
| CPU avg | 10.4% | 8.97% | -1.43 (-13.8%) |
| CPU max | 22.58% | 20.69% | -1.89 (-8.4%) |
| Memory avg | 601.04 MB | 676.98 MB | +75.94 (+12.6%) |
| Memory max | 754.77 MB | 838.59 MB | +83.82 (+11.1%) |
| Slow frames | 32.77% | 38.9% | +6.13 (+18.7%) |
| Frozen frames | 0% | 0% | 0 (0%) |
| ANRs | 0 | 0 | 0 (0%) |
| Issues | 3 | 3 | 0 (0%) |
| Critical issues | 1 | 2 | +1 (+100%) |
| App size | 403.23 MB | 402.86 MB | -0.37 (-0.1%) |
@metamask-mobile-platform
Measure Warm Start: Warm Start to Login Screen
| Platform | Device | Reason | Recording |
|---|---|---|---|
| Android | Google Pixel 8 Pro (v14.0) | Quality gates exceeded | 📹 Watch |
🔬 App profiling check · Current run 37576952055 · Baseline (last green on main) run 37271155053 @ 8eac44c
Summary:
ℹ️ API calls unavailable:
Network logs API error: Bad Request
Full metric table (+10% variance rules)
Disclaimer — allowed variance: a +10% margin over the baseline is permitted.
- If
Current <= Baseline + 10%, treated as acceptable noise.- If
Current > Baseline + 10%, Current and variance % are highlighted with⚠️ .
| Metric | Baseline | Current | Δ |
|---|---|---|---|
| CPU avg | 6.97% | 7.34% | +0.37 (+5.3%) |
| CPU max | 21.23% | 21.61% | +0.38 (+1.8%) |
| Memory avg | 536.83 MB | 568.79 MB | +31.96 (+5.9%) |
| Memory max | 677.91 MB | 730.56 MB | +52.65 (+7.8%) |
| Slow frames | 5.91% | 31.29% | +25.38 (+429.4%) |
| Frozen frames | 0% | 0% | 0 (0%) |
| ANRs | 0 | 0 | 0 (0%) |
| Issues | 2 | 3 | +1 (+50%) |
| Critical issues | 1 | 1 | 0 (0%) |
| App size | 403.41 MB | 402.86 MB | -0.55 (-0.1%) |
✅ Passed Tests (4)
| Test | Platform | Device | Duration | Team | Recording |
|---|---|---|---|---|---|
| Cold Start: Measure ColdStart To Login Screen | Android | Google Pixel 8 Pro (v14.0) | 2.74s | @metamask-mobile-platform | 📹 Watch |
| Measure Warm Start: Login To Wallet Screen | Android | Google Pixel 8 Pro (v14.0) | 0.00s | @metamask-mobile-platform | 📹 Watch |
| Rewards tab time-to-content (onboarding or dashboard) | Android | Google Pixel 8 Pro (v14.0) | 0.60s | @performance-team | 📹 Watch |
| Measure Cold Start To Onboarding Screen | Android | Google Pixel 8 Pro (v14.0) | 0.30s | @metamask-mobile-platform | 📹 Watch |
Branch: refactor/940-privacy-screen · Build: E2E · Commit: 4c27ad5 · View full run




Description
The lock screen route is gone. Backgrounding the app now shows a native privacy cover (theme fill and the splash fox) and keeps it up until resume authentication finishes or the wallet is still unlocked and can continue.
Auto-lock is decided on return from wall-clock time. Immediate lock (
0) locks on background. Timed locks lock only if enough time has passed when the user comes back. Never (-1) does not lock. Deeplinks that arrive during that decision wait until it finishes.On Android, the biometric or device-credential prompt starts only after
onPostResume. Leaving again before the prompt appears cancels that attempt, and the next resume starts a new one. iOS starts the prompt when the app becomes active. The cover is not shown for iOSinactive(app switcher, Control Center, Face ID).Android 13+ blanks the Recents card with
setRecentsScreenshotEnabled(false). Android 12 and older holdFLAG_SECUREfrom login until logout.Card and Ramp still pause auto-lock during verification handoff. Those methods are named
dangerousPauseAutoLock/dangerousResumeAutoLockand marked deprecated. The cover still shows. Navigation persistence should replace them.Changelog
CHANGELOG entry: Added a privacy cover while the app is in the background and prompt unlock on return
Related issues
Fixes:
Refs: 940 privacy screen. No matching GitHub issue.
Manual testing steps
Screenshots/Recordings
Before
N/A
After
iOS and Android recordings to be added.
Pre-merge author checklist
Performance checks (if applicable)
trace()for usage andaddTokenfor an exampleFor performance guidelines and tooling, see the Performance Guide.
Pre-merge reviewer checklist