Android push reliability — foreground service and Doze survival #59
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#59
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Promote the live
NotificationService.Subscribeconsumer (added in #58) into a foreground service. Make Android push work when the app is closed, and survive Doze and aggressive OEM battery management.Depends on
#58 — the self-contained streaming consumer. That issue delivers live notifications while the app is open and keeps the 15-minute poll as the background fallback. This issue replaces that fallback with a real always-on connection.
The problem
Android does not let a background app hold a socket open through Doze. A self-held push connection needs a foreground service with a persistent notification. This is the exact cost that FCM and UnifiedPush avoid by sharing one system wakeup channel across all apps. We chose the self-contained route in ADR 0028 and accept this cost.
This is where the risk sits. The work is not the happy path. It is the failure modes.
Scope
Subscribeconsumer inside a foreground service with a persistent notification.InboxPollWorkeronce the foreground service is reliable, or keep it as a last-resort safety net. Decide during implementation.appLocale()).Open questions
Definition of done
make checkpasses. Behavior verified on a physical device over a multi-hour idle window.