Skip to content

Task 13.3: default NDK symbol upload on for React Native - #38

Merged
krassx merged 5 commits into
mainfrom
feat/phase-13-3
Oct 2, 2026
Merged

krassx merged 5 commits into
mainfrom
feat/phase-13-3

Conversation

@krassx

@krassx krassx commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The generated root android/bugsee.properties now sets plugin.ndk.enabled=true beside the unprefixed app_token= key. The file stays gitignored.
  • The wrapper already depends on com.bugsee:bugsee-android-ndk, so the example does not declare it again. This does not upload symbols.

Test plan

  • yarn jest scripts/__tests__/write-credentials.test.ts (5 passed), including a fake token that asserts app_token= and plugin.ndk.enabled=true and rejects plugin.appToken
  • CI green on this head

Made with Cursor

Every RN app ships Hermes and libreactnative.so it did not write, so the
generated root bugsee.properties sets plugin.ndk.enabled beside the
unprefixed app_token. The wrapper already exposes bugsee-android-ndk as
an api dependency, so the example app does not declare it again.

Co-authored-by: Cursor <cursoragent@cursor.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Deep code review — Task 13.3 NDK symbol upload default

Reviewed 907fcec against plugin 4.0.7 (bugsee/bugsee-android-gradle-plugin: BugseePlugin.registerNativeUploadTask, NativeUploadTask, BugseeNdkExtension, CoreSdkAutoLoad) and AGP's ndk.debugSymbolLevel default. Diff is three files; the example already applies com.bugsee.android.gradle on :app and the wrapper already apis bugsee-android-ndk:7.3.0.

plugin.ndk.enabled=true is the correct properties key. It is not sufficient to make NDK symbol upload actually happen for this app.

Findings

  1. P1 High — examples/bare/scripts/write-credentials.mjs:81
    The flag registers uploadBugsee{Variant}Native, which only zips AGP's native_debug_metadata / native-debug-symbols output. AGP defaults debugSymbolLevel to 'none'; this example never sets it, so extract is empty and the task warns and skips. Hermes / libreactnative.so from Maven are also pre-stripped (RN #38568), so even SYMBOL_TABLE/FULL would not upload those two libraries the commit cites.

  2. P2 Medium — same file, generated properties
    BUGSEE_ENDPOINT is written to credentials.json only. Plugin uploads default to https://api.bugsee.com. The documented apidev flow therefore cannot attach symbols to the environment the SDK reports into.

  3. P2 Medium — write-credentials.mjs:17
    The new comment says the flag “only enables upload.” Plugin 4.0.7 auto-adds com.bugsee:bugsee-android-ndk:[7.2.0,8.0.0) on the app because the wrapper pin is transitive, not a direct :app dependency.

1. Overall risk: Medium

Runtime native-crash detection was already on via the wrapper. This change is unlikely to fail CI: NativeUploadTask warns and returns on missing symbols / bad token (CLI substantive failures do not throw). The 13.3 product goal — symbolicated RN native stacks — is not met.

2. Merge recommendation: Request changes

Do not mark 13.3 complete until a build of this example actually produces extract output (or the gap is documented and the checkbox stays open).

3. Most important issues to fix

  • Set ndk.debugSymbolLevel on the variants you intend to symbolicate (run-android.sh is assembleDebug). Treat Hermes/libreactnative.so symbolication as unsolved until there is an unstripped artifact source.
  • Write plugin.endpoint from BUGSEE_ENDPOINT when it is set.
  • Stop claiming the flag is upload-only; pin NDK on :app or accept the dynamic auto-add explicitly.

4. Positive observations

  • Unprefixed app_token= at the root Gradle project is the right token key; plugin.appToken is correctly avoided.
  • The new unit test pins the exact properties lines and that the token is not printed.
  • Wrapper api of bugsee-android-ndk is the right place for detection; this PR correctly does not redeclare it on the example module (the plugin may still auto-add it — see P2).

Did not run the new Jest file here (Yarn 4 / corepack not enabled in this environment). Did not wait for the in-progress android CI job; plugin upload paths are warn-and-skip, so a red assemble would be a surprise rather than the expected outcome of this diff.

Open in Web View Automation 

Sent by Cursor Automation: Bugsee code review

Comment thread examples/bare/scripts/write-credentials.mjs Outdated
Comment thread examples/bare/scripts/write-credentials.mjs Outdated
Comment thread examples/bare/scripts/write-credentials.mjs Outdated
AGP's debugSymbolLevel defaults to none, so the plugin's native upload
skips. SYMBOL_TABLE lets AGP emit symbols for code this app builds;
pre-stripped Hermes and libreactnative.so stay unsymbolicated. A set
endpoint is written as plugin.endpoint, and :app declares
bugsee-android-ndk at the native-versions pin so the plugin does not
substitute its version range.

Co-authored-by: Cursor <cursoragent@cursor.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Deep code review — Task 13.3 NDK symbol upload (877cefa)

Re-reviewed 877cefa against plugin 4.0.7 (NativeUploadTask, BugseePlugin.registerNativeUploadTask, autoAddModule, SymbolUploader, CliUploader) and the example's placeholder-token policy (endpoint.ts, .github/workflows/ci.yml). Prior threads reconciled below.

Prior findings

Prior Verdict Why
P1 AGP debugSymbolLevel default none partially_addressed Debug and release now set SYMBOL_TABLE. Extract runs; locally built JNI (bugsee-e2e-native) can upload. Maven Hermes / libreactnative.so remain pre-stripped (RN #38568); the new comments say so.
P2 plugin.endpoint not written fully_addressed Non-empty BUGSEE_ENDPOINT becomes plugin.endpoint with no /v2; empty is omitted. Tests cover both.
P2 NDK auto-add [7.2.0,8.0.0) fully_addressed :app declares com.bugsee:bugsee-android-ndk:${nativeVersions.android.sdk} directly, so autoAddModule skips. Comment no longer says the flag is upload-only.

New finding

  1. P2 Medium — examples/bare/scripts/write-credentials.mjs:82
    Unconditional plugin.ndk.enabled=true plus SYMBOL_TABLE means uploadBugseeDebugNative now has extract output. CI assembleDebug uses the placeholder token and the plugin default endpoint, so every android job downloads bugsee-cli and POSTs to production. Runtime already blocks that (isPlaceholderToken → DEAD_ENDPOINT).

1. Overall risk: Medium

The three knobs from the last review are in the right place for a real Android token: unprefixed app_token, plugin.endpoint, pinned NDK, SYMBOL_TABLE. The remaining issue is that the same path now fires in CI / placeholder builds, which this repo deliberately keeps off the real server.

Hermes / libreactnative.so symbolication is still an RN-ecosystem gap, not a missing Gradle switch. That residual is documented next to debugSymbolLevel and is not re-raised as blocking.

2. Merge recommendation: Request changes

Gate plugin.ndk.enabled=true on a non-placeholder Android token. Do not treat 13.3 as done until placeholder assembleDebug stops contacting api.bugsee.com.

3. Most important issues to fix

  • Write plugin.ndk.enabled=true only when BUGSEE_TOKEN_ANDROID is non-empty and not the placeholder UUID (same rule as isPlaceholderToken). Omit it for CI / local placeholder credentials.
  • Keep debugSymbolLevel and the :app pin; those are the correct product defaults for a real token.

4. Positive observations

  • SYMBOL_TABLE on both debug and release is the right AGP fix; run-android.sh is assembleDebug, so debug-only would have been wrong.
  • Direct :app NDK pin at native-versions.json's android.sdk matches how the wrapper avoids the plugin's dynamic range.
  • plugin.endpoint is written only when set, without a /v2 suffix, which matches SymbolUploader's $endpoint/apps/... URL shape and the README's https://apidev.bugsee.com.
  • Credentials tests pin app_token=, plugin.ndk.enabled=true, no plugin.appToken, and that neither token nor endpoint is printed.

Did not run yarn jest scripts/__tests__/write-credentials.test.ts here (node_modules was not installed). Did not wait for in-progress android CI; plugin upload failures usually warn-and-return, so a red assemble would more likely be a Kotlin-path timeout than a bad-token CLI exit.

Open in Web View Automation 

Sent by Cursor Automation: Bugsee code review

Comment thread examples/bare/scripts/write-credentials.mjs Outdated
krassx and others added 2 commits October 3, 2026 01:04
assembleDebug runs the native upload once symbols exist, and CI's
placeholder token would otherwise hit the plugin's default host. Write
plugin.ndk.enabled only for a non-empty Android token that
isPlaceholderToken does not match.

Co-authored-by: Cursor <cursoragent@cursor.com>
write-credentials.mjs runs under plain node, which rejects a .ts import.
Copy isPlaceholderToken's regex into the script so a CI placeholder still
leaves NDK upload off.

Co-authored-by: Cursor <cursoragent@cursor.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Deep code review — Task 13.3 NDK symbol upload (3c1fe1e)

Re-reviewed 3c1fe1e against plugin 4.0.7 (NativeUploadTask, BugseePlugin.registerNativeUploadTask, autoAddModule / withDependencies, BugseeNdkExtension.enabled default false, UploaderStrategy.CLI). Checked callers (run-android.sh assembleDebug, CI android job, endpoint.ts placeholder rule) and ran write-credentials.mjs for fake token, CI UUID, placeholder+endpoint, /v2 endpoint, and iOS-only. Prior threads reconciled below.

Prior findings

Prior Verdict Why
P1 AGP debugSymbolLevel default none partially_addressed Debug and release set SYMBOL_TABLE. Extract can run; locally built JNI (bugsee-e2e-native) can upload. Maven Hermes / libreactnative.so remain pre-stripped (RN #38568); the comments next to the level say so.
P2 plugin.endpoint not written fully_addressed Non-empty BUGSEE_ENDPOINT becomes plugin.endpoint with no /v2 appended; empty is omitted. Tests cover both.
P2 NDK auto-add [7.2.0,8.0.0) fully_addressed :app declares com.bugsee:bugsee-android-ndk:${nativeVersions.android.sdk} directly. Plugin autoAddModule runs in withDependencies (after the dependencies block) and skips a direct dep.
P2 unconditional plugin.ndk.enabled=true fully_addressed Flag is written only when BUGSEE_TOKEN_ANDROID is non-empty and isPlaceholderToken is false. CI UUID 00000000-0000-4000-8000-000000000000 omits the key, so the plugin default false stands and uploadBugseeDebugNative is not registered. fake-android-token still writes it. The regex in write-credentials.mjs is identical to endpoint.ts.

New findings

None that meet the P0–P3 bar. Placeholder assembleDebug no longer registers the native upload task, so CI does not download bugsee-cli or POST to api.bugsee.com on this path. Mapping upload remains registered but skips when there is no mapping.txt (debug does not minify). Build-info stays release-and-non-debuggable only.

Hermes / libreactnative.so symbolication is still an RN-ecosystem gap, not a missing Gradle switch. That residual is documented next to debugSymbolLevel and is not re-raised as blocking.

1. Overall risk: Low

The four knobs a real Android token needs are in the right place: unprefixed app_token, plugin.endpoint when set, pinned NDK on :app, SYMBOL_TABLE on debug and release. The CI placeholder path leaves NDK upload off.

2. Merge recommendation: Safe once CI is green

13.3 as an example-app Gradle default is complete. Do not treat Hermes / libreactnative.so dashboard stacks as proven; that waits on an unstripped artifact source (or 13.5 for JS).

3. Most important issues to fix

None remaining on this head.

4. Positive observations

  • Gating the flag on isPlaceholderToken matches runtime (endpoint.ts → DEAD_ENDPOINT) instead of inventing a second rule.
  • Copying the regex into plain JavaScript is the right constraint: write-credentials.mjs runs under node, which cannot import endpoint.ts. The two copies are byte-identical.
  • Direct :app NDK pin at native-versions.json's android.sdk is the same coordinate the wrapper uses, so plugin auto-add does not introduce a 7.x range.
  • plugin.endpoint is omitted when unset, which keeps production tokens on the plugin default https://api.bugsee.com.

Ran write-credentials.mjs directly for the cases above (node_modules / Jest were not installed here). Did not wait for in-progress CI 37058633966; with NDK upload unregistered, a red assembleDebug would come from the existing compile path, not from this flag.

Open in Web View Automation 

Sent by Cursor Automation: Bugsee code review

Co-authored-by: Cursor <cursoragent@cursor.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deep code review — Task 13.3 NDK symbol upload (7dd4dc7)

Re-reviewed 7dd4dc7 (merge of origin/main into 3c1fe1e) against plugin 4.0.7 (NativeUploadTask, BugseePlugin.registerNativeUploadTask, autoAddModule / withDependencies, BugseeNdkExtension.enabled default false, MappingUploadTask, UploaderStrategy.CLI). Callers checked: run-android.sh assembleDebug, CI android job, endpoint.ts placeholder rule. 13.3 production files are identical to 3c1fe1e; the merge only brought Task 9.7. Prior threads reconciled below.

Prior findings

Prior Verdict Why
P1 AGP debugSymbolLevel default none partially_addressed Debug and release set SYMBOL_TABLE. Extract can run; locally built JNI (bugsee-e2e-native) can upload. Maven Hermes / libreactnative.so remain pre-stripped (RN #38568); the comments next to the level say so.
P2 plugin.endpoint not written fully_addressed Non-empty BUGSEE_ENDPOINT becomes plugin.endpoint with no /v2 appended; empty is omitted. Tests cover both. Plugin ApiEndpoint.buildsUrl also strips a trailing /v2 if one is supplied.
P2 NDK auto-add [7.2.0,8.0.0) fully_addressed :app declares com.bugsee:bugsee-android-ndk:${nativeVersions.android.sdk} directly. Plugin autoAddModule scans declared dependencies and skips that GAV.
P2 unconditional plugin.ndk.enabled=true fully_addressed Flag is written only when BUGSEE_TOKEN_ANDROID is non-empty and isPlaceholderToken is false. CI UUID 00000000-0000-4000-8000-000000000000 omits the key, so the plugin default false stands and uploadBugseeDebugNative is not registered. fake-android-token still writes it. The regex in write-credentials.mjs is byte-identical to endpoint.ts.

New findings

None that meet the P0–P3 bar. Placeholder assembleDebug does not register the native upload task. Mapping upload remains registered but returns before CLI download when there is no mapping.txt (debug does not minify). Build-info stays release-and-non-debuggable only.

Hermes / libreactnative.so symbolication is still an RN-ecosystem gap, not a missing Gradle switch. That residual is documented next to debugSymbolLevel and is not re-raised as blocking.

1. Overall risk: Low

The four knobs a real Android token needs are in the right place: unprefixed app_token, plugin.endpoint when set, pinned NDK on :app, SYMBOL_TABLE on debug and release. The CI placeholder path leaves NDK upload off.

2. Merge recommendation: Safe once CI is green on this merge

13.3 as an example-app Gradle default is complete. Android CI 37058633966 on 3c1fe1e was SUCCESS: extractDebugNativeSymbolTables ran, uploadBugseeDebugMapping ran, uploadBugseeDebugNative did not. This head only merges main (Task 9.7). Do not treat Hermes / libreactnative.so dashboard stacks as proven; that waits on an unstripped artifact source (or 13.5 for JS).

3. Most important issues to fix

None remaining on this head.

4. Positive observations

  • Gating the flag on isPlaceholderToken matches runtime (endpoint.ts → DEAD_ENDPOINT) instead of inventing a second rule.
  • Copying the regex into plain JavaScript is the right constraint: write-credentials.mjs runs under node, which cannot import endpoint.ts.
  • Direct :app NDK pin at native-versions.json's android.sdk is the same coordinate the wrapper uses, so plugin auto-add does not introduce a 7.x range.
  • plugin.endpoint is omitted when unset, which keeps production tokens on the plugin default https://api.bugsee.com.

Ran write-credentials.mjs for fake token, CI UUID, hyphenless placeholder, placeholder+endpoint, real+endpoint, /v2 endpoint, and iOS-only (node_modules / Jest were not installed here). Decompiled plugin 4.0.7 from Maven Central. Did not wait for in-progress CI on 7dd4dc7; NDK upload is unregistered on the placeholder path, so a red assembleDebug would come from the merge (Task 9.7) or the existing compile path, not from this flag.

Open in Web View Automation 

Sent by Cursor Automation: Bugsee code review

@krassx
krassx merged commit 38c7b8f into main Oct 2, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant