Expose owner-keyed cleanup for rejected or unknown PackageInstaller outcomes, so a failed confirmation cannot leave a sealed session behind. Preserve the terminal receipt and notification state without retrying the APK.
Deliver install confirmation, live core status, location foreground-service state and WallpaperService metadata. Add the SDK instrumentation smoke across API 26/29/30/33/36, keep size debt within the existing manifest, and document Android consent and provider-URI custody.
Keep pending PackageInstaller consent reachable through an Android notification, preserve incomplete outcomes, and serialize receipt admission before commit. Exercise callbacks with a JVM harness. Report live core health separately from saved process records after reboot, and document the actual rootfs storage boundary.