Summary
Formulus can leave a device on a blank/black Home after an app-bundle update when local storage (or memory) is exhausted. Install does not check free space, and the “atomic” swap deletes the live app/forms dirs before moving the staging extract into place. Home only checks that app/index.html exists, so a partial tree can load a broken WebView with no user-facing error.
Current behavior
- Download zip → unzip to cache staging → unlink live dirs →
moveFile staging into Documents.
- No free-disk preflight;
ENOSPC / OOM are not mapped to a clear message (generic Sync Alert at best).
@appVersion / bundleUpdated only after success — good — but a failed mid-swap still wipes the previous bundle.
- Home: missing
index.html → placeholder; present-but-incomplete → silent blank WebView.
Proposed fix
- Detect insufficient space (and surface related I/O failures) with an explicit Sync error prompt.
- Make install truly atomic (keep the old bundle until the new one is fully in place / safely committed; roll back or leave old intact on failure).
- Skip extra integrity checks and Home WebView fallback if atomic install + clear space errors are in place.
Acceptance criteria
Summary
Formulus can leave a device on a blank/black Home after an app-bundle update when local storage (or memory) is exhausted. Install does not check free space, and the “atomic” swap deletes the live app/forms dirs before moving the staging extract into place. Home only checks that
app/index.htmlexists, so a partial tree can load a broken WebView with no user-facing error.Current behavior
moveFilestaging into Documents.ENOSPC/ OOM are not mapped to a clear message (generic Sync Alert at best).@appVersion/bundleUpdatedonly after success — good — but a failed mid-swap still wipes the previous bundle.index.html→ placeholder; present-but-incomplete → silent blank WebView.Proposed fix
Acceptance criteria
@appVersion/bundleUpdatedonly after commit.