# Android IPC / Drozer experiment record

This is a blank template. It contains no observed device results.

## Environment

- Date / operator:
- Device or emulator / Android version / build fingerprint:
- User or work profile:
- Target package / version / targetSdk / APK SHA-256:
- Console / Agent versions and hashes:
- Agent UID / declared permissions / granted permissions / URI grants:
- Target app state and synthetic marker data:

## Exact entry point

- Component or full content URI:
- IPC method (Activity, broadcast, started Service, Messenger, AIDL, Provider operation):
- Manifest controls and code location:
- Expected authorization policy:

## Reproduction

1. Establish the documented initial state.
2. Run the exact command or test-client invocation below.
3. Record the result and relevant target-side logs.

```text
(exact invocation)
```

| Case | Caller and grants | Initial state | Input | Observed output/state | Expected result |
|---|---|---|---|---|---|
| Authorized control | | | | | |
| Unauthorized test | | | | | |
| Patched repeat | | | | | |
| Valid flow after patch | | | | | |

## Interpretation

- What this observation proves:
- What it does not prove:
- Root cause (input -> identity/permission -> resource -> sensitive operation):
- Scope limited by target process access and test data:
- Fix and regression coverage:
- Restore synthetic data / stop Agent / remove task-specific ADB forwarding:
