Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
160297 stories
·
33 followers

Why Mouse Jigglers Defeat Activity-Based Time Tracking

1 Share

Activity percentages on time-tracking dashboards are basically a compressed view of mouse and keyboard input. Hardware jigglers, software “movers,” and keep-awake scripts exist because they game that view: they keep the green bar green without proving anyone is working. Richer Windows endpoint data—apps, session state, files, network—can make fake presence look thin. Correlation still isn’t proof. If your company treats activity % as honesty, you’re measuring the wrong thing.


This got loud when remote and hybrid work turned “presence” into a management proxy. Billing fights, contractor timesheets, and always-on Slack status rewarded meters that look objective. A cheap USB gadget that nudges the cursor—or a script that fakes input—isn’t a clever attack on your stack. It’s a rational response to a bad metric. The dashboard isn’t broken. The metric was never presence.

Three questions managers keep collapsing into one

Most arguments about idle time and jigglers start the same way: leaders ask three different questions and expect one number to answer all of them.

  1. Was there input? Mouse moves, clicks, keypresses in a time window.
  2. Was the person actually working? Foreground apps, websites, documents, meeting context.
  3. Was there risk or a policy issue? USB copies, weird file paths, blocked sites, odd hours on sensitive data.


Activity % mostly answers question one—and not well. It can’t tell a human hand from a HID gadget that looks like a mouse, or from injected events. It also can’t tell “reading a long design doc on a second monitor” from “away from the desk.” Pure idle rules punish real work: light typing on video calls, long compiles, research that’s mostly scroll-and-think.


If the risk is payroll honesty, you need more than input volume. If the risk is data loss, mouse motion barely matters. Smash those goals into one green percentage, and jigglers win.

What SaaS “activity %” usually sees

A typical desktop agent for time tracking does some version of this:

HID / OS input events
        ↓
   Desktop agent
        ↓
  Time buckets (e.g. 1–10 min)
        ↓
   Activity percent
        ↓
     Dashboard


Windows already has basics for input idle detection. Microsoft’s GetLastInputInfo returns the time of the last input event for the session that called it—not magic proof that “the employee is working.” Agents may use last-input APIs, raw input hooks, or their own sampling of moves and keys. Same bottom line either way: the meter counts motion in a bucket, then paints a percentage.


That percentage does not prove:

  • real focus or meeting attention,
  • that someone’s at the desk,
  • that a human made the input,
  • that the work was billable or allowed by policy.

Jigglers win because they feed the same event class the meter counts. You don’t need a novel exploit. You need the sensor’s blind spot.

A short taxonomy (for detection—not a how-to)

ClassWhat it fakesWhat it usually fails to fake
USB HID “mouse” / moverSteady move or clickApp switching, file/network patterns, normal task hopping
Software mover / scriptPeriodic cursor wiggles or fake inputNatural timing, real typing, a believable app story
OS keep-awake / sleep blockersStops sleep / dimmingHigh activity % on its own—unless you also spoof input


This is a cheat sheet for ops and security, not a recipe book. The story is already public: banks and big employers have fired people over simulated keyboard activity and “mouse movers,” including Wells Fargo, as reported by the BBC. The takeaway isn’t “buy a detector.” It’s that if you treat input as proof of work, you create demand for tools that fake input.


Some monitoring vendors pitch dedicated “jiggler detection.” Treat that as marketing until you know which signals they use. Motion-only heuristics are brittle. Multi-signal context is where suspicion gets useful.

What richer endpoint telemetry can catch

Once you instrument a Windows PC beyond “how much did the mouse move,” you get a stack. Each layer does a different job. None of them is a courtroom.

LayerExamplesUseful against jigglers?
Input volume onlyMove/click/key countsNo—this is what jigglers target
Session stateLock/unlock, console vs remote, idle timeoutSomewhat—locked + “active” deserves a look
Process / app timelineForeground app, launch/exitYes—hours “active” on one junk process looks thin
Web / search (sensitive)URLs, queriesYes—heavy on privacy; policy first
File / USB / print / clipboardChannel activityStrong for fraud and DLP; different goal than time cheating
NetworkInterfaces, per-app trafficHelps separate real work from empty motion
Screens / live viewSpot checksHuman review; too sensitive for first-line payroll fights
Anomaly / rule hitsAlerts in a queueOps workflow—not a magic classifier


Hard truth: more signals raise suspicion. They don’t prove guilt. A quiet engineer on a call can look “idle.” A jiggler with a real IDE open can look “busy.” Treat multi-signal outliers as a review queue, not an auto-fire pipeline.


A simple investigation pattern:

  1. Flag — high activity with almost no app variety, or activity while the session is locked.
  2. Context — which apps and sites were up front? Any file/USB/web events? Was the agent offline earlier?
  3. Talk to a human — walk the timeline with a manager or the employee before you call it fraud.
  4. Decide — coaching, stop worshipping activity %, or escalate if the evidence holds.


Watch session boundaries too. Last-input APIs are session-specific. RDP and multi-session hosts (terminal servers / RDS) make “was this the interactive user?” a real engineering problem, not a dashboard footnote. On shared Windows hosts, per-session context beats one PC-wide activity bar. Sample the wrong session and you’ll mark someone idle forever—or credit them for activity that wasn’t theirs.

For the longer arc—from punch clocks to screenshots to “work intelligence”—see this Jon Stojan time tracking piece on HackerNoon. Vendors keep renaming the dashboard. The mistake stays the same when one thin sensor becomes a moral score.


Security teams that care about insider risk already think in layers. NIST SP 800-53 talks about continuous monitoring and audit as control families—not as one productivity percentage. Steal that mindset: pick controls that match the risk, then store as little as you can. Need attendance trends? Don’t keep keystroke content. Need DLP? Don’t pretend mouse percentages are your control set.

False positives, ethics, and policy

Obsessing over “catch jigglers” creates workplace theater. People learn to look busy. Trust drops. Then you get a second arms race: more invasive capture vs. smarter spoofing.


A healthier setup starts with a written policy:

  • What do you measure, and why?
  • Who can see raw screens or keystrokes, if anyone?
  • How long do you keep sensitive data vs. aggregates?
  • What happens on a flag—conversation, coaching, investigation—before HR?


Transparent monitoring (people know the scope) and stealth modes are policy choices, not moral absolutes. Time-tracking buyers usually want softer defaults. Security buyers often need channel visibility—files, USB, web—for insider risk. One product toggle won’t fix both cultures. That’s how you end up with dashboards that punish people who read and miss people who leak.


There’s a security angle that doesn’t get enough airtime: unknown USB HID devices on managed laptops aren’t just a “productivity cheat.” They’re an endpoint hygiene problem. If you already lock down flash drives, treat mystery HID gadgets with similar seriousness. That doesn’t mean hunting every accessibility tool or specialty mouse. It means inventory, allowlisting, and clear exceptions.


This isn’t legal advice. Notice, minimization, and retention rules vary by place. Put the employee-facing policy in writing before you turn agents on.

Practical checklist for security and ops

If the goal is payroll / billable honesty

  • Don’t use activity % alone in a dispute.
  • Cross-check app/website timelines, idle gaps, and calendar or ticket context when you have it—before you accuse anyone.
  • High activity + almost no app diversity → review queue, not auto-fire.
  • For knowledge work, prefer outcomes and deliverables. Use telemetry to explain weird patterns, not to grade people like machines.

If the goal is insider risk / DLP

  • Prioritize channel signals (files, USB, web, clipboard) and rule hits over mouse motion.
  • Use screen capture or live view after a signal—not as the default story of “how we manage people.”
  • Keep “was someone present?” separate from “did sensitive data leave?” in both tools and process.

Instrumentation hygiene

  • Log session lock, remote vs. console, and agent health. Offline gaps explain more than fake green bars.
  • Keep aggregates longer than raw keystrokes or wall-to-wall screen history when policy allows—less creep, still useful trends.
  • Write down what you measure in the employee-facing policy before deploy.
  • If hardware jigglers are a real concern, control unknown USB HID via endpoint policy—without turning every mouse into a witch hunt.

Conclusion

Mouse jigglers still fool time-tracking dashboards because those dashboards often measure input motion, then ask managers to treat the number as work. Endpoint telemetry across apps, session state, files, and network can make fake presence look thin—but only as correlation, and only if you respect false positives.


Measure the behavior that matches the business risk, not the easiest sensor.


What single metric does your company still treat as truth—and what would you replace it with? Drop it in the comments.


Read the whole story
alvinashcraft
54 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

AI's 'Creepy' Crawlers Criticized by Linux Foundation's IT Infrastructure Director

1 Share
The Linux Foundation's director of IT infrastructure says they now spend more CPU cycles "rendering commits for scrapers than we spend on all other kinds of legitimate access." At any one time, across 5 geo-distributed nodes, there are 14 CPU cores doing nothing but rendering git commits as html.... [W]hen a source is guaranteed to be LLM-free, like the entire history of kernel commits, it's worth its weight in gold as a source of training data... At the time of writing, linux.git is about 1.48 million commits. Oh, and we have about 922 forks of it on git.kernel.org — but don't worry, it's actually extremely efficient on the backend, since it's mostly the same objects in every fork. Unless, of course, you're a scraper, in which case you have, oh, several BILLION valid URLs you can scrape, only to get 922 duplicates of the same 1.48 million commits — which is exactly what the scrapers are doing. But wait, it's not just commits itself. You can also ask for patches, plain renders, diffs between arbitrary commits — cgit is happy to let you, which was perfect for the times when the Internet was for humans or crawlers who obeyed robots.txt, and is AWFUL right about now, because we can generate 1.2 METRIC BAJILLION valid URLs just for a single fork of linux.git. Initially, this was the solution — look through the logs, find out which IPs are obvious scraper bots, and fail2ban them. At first, this was easy, because the bots helpfully told you who they were via their user-agent. Then, they wised up and started pretending that they were random vanilla browsers. So, we started banning them by IP — after all, it's easy to figure out that an IP that is trying to grab every possible commit in a 8-year-old abandoned fork of linux is not really some lone Chrome on Windows user who is just furiously clicking every link that comes across their screen. The bots then started fanning out to entire subnets, but this was still meh, because obviously an IP coming from Google Compute is just pretending to be a Firefox user... And... that's when things turned really, really ugly. Suddenly, the crawlers were coming from millions of random residential or mobile IPs, all pretending to be random modern browsers. An IP like that would make 4-5 requests and then never show up in the logs again... They descended like swarms of locust, hit hard and fast until the system fell over and then moved on to the next target until you recovered. Then, they returned. Rinse. Repeat. They still do that — welcome to the wonderful world of "proxy SDK monetization." It's big business, and your TV is probably doing it... Today, git.kernel.org receives about 6M daily requests demanding to see random commits. Of these, 66% are still immediately batted away with the Anubis challenge, but 33% are now solving the math and getting through to the main site — because apparently what we have to offer is worth spending a ton of cycles to calculate the Anubis challenge... With a bunch of generous assumptions, legitimate requests are only about 2% of git.kernel.org traffic — everything else are scrapers... [W]e're turning off features to reduce the number of crawlable URLs and to gate off actions that are expensive for us to run. Expect to lose some functionality, at least when accessing our resources anonymously. Trust me, we hate it just as much as you, but at this point it's a necessity... [W]e promise to still offer all of our data for download to anyone who asks. You just may have to jump through more hoops to get it. Sorry.

Read more of this story at Slashdot.

Read the whole story
alvinashcraft
54 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Production Flutter Networking Without the Boilerplate: Reactive Repositories with BlocSignal

1 Share

The Networking Architecture Dilemma in Production Flutter

If you survey ten seasoned Flutter developers about how they structure networking in production, you will almost certainly see the same multi-tiered pipeline:

┌────────────────────────────────────────────────────────────────────────┐
│               Traditional Flutter Networking Pipeline                  │
├────────────────────────────────────────────────────────────────────────┤
│ [Dio / HTTP Client] ─▶ [API Service] ─▶ [Repository Layer] ─▶          │
│                      [Cubit / BLoC] ─▶ [UI Builders & Banners]         │
└────────────────────────────────────────────────────────────────────────┘

The underlying architectural principles are sound: separation of concerns, testability, and isolating network transport details from UI widgets.

However, in practice, this classical layered stack demands an enormous amount of repetitive boilerplate:

  1. Async State Union Ceremony: Defining four separate state classes (Initial, Loading, Success(data), Failure(error)) or union types for every single API endpoint.
  2. Race Conditions & In-Flight Cancellation: When users type queries or switch tabs rapidly, requests finish out of order. Preventing stale responses requires complex Dio CancelToken plumbing or heavy rxdart switchMap streams.
  3. Offline Caching & "Stale-While-Revalidate": Showing cached data on Frame 1 while fetching fresh updates in the background usually requires database synchronization and stream merging logic.
  4. The Repository vs. Controller Divide: Repositories hold data and caching logic, while BLoCs or Cubits hold reactive state. Because Dart only allows single inheritance, developers end up maintaining two separate class hierarchies connected by verbose dependency injection glue.

With bloc_signals, we can preserve complete separation of concerns while eliminating 70% of the friction.

Let us examine how to architect a modern, clean, production-ready networking layer using CubitSignalMixin, HydratedMixin, and .toAsyncBlocSignal().

⚡ 1. Symmetrical Async Projection with .toAsyncBlocSignal()

In many cases, a feature only needs to fetch data from an endpoint and present it in the UI with loading and error states.

Instead of writing a custom Cubit and four distinct state classes, any Dart Future<T> converts directly into a BlocSignalBase<AsyncState<T>> with a single method call:

class UserProfileService {
  UserProfileService(this._dio);
  final Dio _dio;

  Future<UserProfile> fetchUserProfile(String userId) async {
    final response = await _dio.get('/users/\$userId');
    return UserProfile.fromJson(response.data as Map<String, dynamic>);
  }
}

In your presentation layer or view model:

// Converts Future<UserProfile> into a synchronous BlocSignalBase<AsyncState<UserProfile>>
final userProfileBloc = profileService
    .fetchUserProfile('user_123')
    .toAsyncBlocSignal();

Declarative Exhaustive UI Binding

Because AsyncState<T> is a sealed class hierarchy (AsyncLoading, AsyncData, AsyncError), you get compile-time exhaustive pattern matching in your Flutter widgets:

BlocSignalBuilder<BlocSignalBase<AsyncState<UserProfile>>, AsyncState<UserProfile>>(
  bloc: userProfileBloc,
  builder: (context, state) => switch (state) {
    AsyncLoading() => const Center(
        child: CircularProgressIndicator(),
      ),
    AsyncData(:final value) => ProfileDetailsView(user: value),
    AsyncError(:final error) => ErrorCard(
        message: error.toString(),
      ),
  },
)

No custom state classes, no manual try/catch event plumbing, and no FutureBuilder rebuild bugs.

🧬 2. Reactive, Offline-Cached Repositories with CubitSignalMixin & HydratedMixin

In enterprise apps, repositories often need to extend an existing API client base class (such as BaseApiClient or AuthenticatedHttpService) while maintaining persistent local caches.

Because Dart only permits single inheritance, traditional repositories could not be state containers.

With CubitSignalMixin and HydratedMixin, your repository IS the reactive, persistent state container:

import 'package:bloc_signals/bloc_signals.dart';
import 'package:bloc_signals_hydrate/bloc_signals_hydrate.dart';
import 'package:dio/dio.dart';

/// A production domain repository extending BaseApiClient with 0ms reactivity & disk caching!
class ProductRepository extends BaseApiClient
    with
        CubitSignalMixin<AsyncState<List<Product>>>,
        HydratedMixin<AsyncState<List<Product>>> {
  ProductRepository(super.dio) {
    // 1. Initialize reactive signal container
    initCubitSignal(initialState: const AsyncLoading());

    // 2. Initialize Frame-1 persistent storage cache
    initHydrated(storageKey: 'cached_products_v1');
  }

  /// Refreshes data from the network using toFutureSignal to eliminate try-catch
  Future<void> refresh() async {
    emit(const AsyncLoading());

    // ⚡ toFutureSignal automatically projects success into AsyncData and exceptions into AsyncError!
    final fetchSignal = _fetchProducts().toFutureSignal();
    await fetchSignal.future;
    emit(fetchSignal.value);
  }

  Future<List<Product>> _fetchProducts() async {
    final response = await dio.get('/products');
    final rawList = response.data as List<dynamic>;
    return [
      for (final item in rawList) Product.fromJson(item as Map<String, dynamic>),
    ];
  }

  // 💾 Pattern matching for instant offline hydration:
  @override
  Object? toJson(AsyncState<List<Product>> state) => switch (state) {
        AsyncData(:final value) => [
            for (final product in value) product.toJson(),
          ],
        _ => null,
      };

  @override
  AsyncState<List<Product>>? fromJson(dynamic json) => switch (json) {
        {'products': List<dynamic> list} => AsyncData([
            for (final item in list) Product.fromJson(item as Map<String, dynamic>),
          ]),
        List<dynamic> list => AsyncData([
            for (final item in list) Product.fromJson(item as Map<String, dynamic>),
          ]),
        _ => null,
      };
}

What This Architecture Delivers:

  1. Instant Frame-1 Rendering: When the app opens, HydratedMixin restores the cached List<Product> synchronously before the first pixel renders. Zero loading flickers.
  2. Background Refresh: Calling repository.refresh() executes network I/O and updates the UI synchronously on emit(AsyncData(freshProducts)).
  3. Single Class Hierarchy: Extends BaseApiClient without needing an intermediate wrapper or proxy Cubit.

🛑 3. Eliminating Network Race Conditions with restartable()

One of the most insidious bugs in mobile networking is the out-of-order response.

If a user searches for "Fl", then "Flu", and finally "Flutter", the network request for "Fl" might take 800ms while "Flutter" takes 200ms. Without cancellation, the "Fl" response resolves last and overwrites the screen with stale data!

With BlocSignalMixin, solving this requires zero cancel tokens or Rx streams—just apply the built-in restartable() transformer:

sealed class SearchEvent {
  const SearchEvent();
}

final class SearchQueryChanged extends SearchEvent {
  const SearchQueryChanged(this.query);
  final String query;
}

class SearchRepository extends BaseApiClient
    with
        CubitSignalMixin<AsyncState<List<SearchResult>>>,
        BlocSignalMixin<SearchEvent, AsyncState<List<SearchResult>>> {
  SearchRepository(super.dio) {
    initCubitSignal(initialState: const AsyncData([]));

    // ⚡ Built-in concurrency control: automatically aborts prior in-flight queries!
    on<SearchQueryChanged>((event, emit) async {
      final query = event.query.trim();
      if (query.isEmpty) {
        emit(const AsyncData([]));
        return;
      }

      emit(const AsyncLoading());
      final searchSignal = _executeSearch(query).toFutureSignal();
      await searchSignal.future;
      emit(searchSignal.value);
    }, transformer: restartable());
  }

  Future<List<SearchResult>> _executeSearch(String query) async {
    final response = await dio.get('/search', queryParameters: {'q': query});
    final results = response.data as List<dynamic>;
    return [
      for (final item in results) SearchResult.fromJson(item as Map<String, dynamic>),
    ];
  }
}

🏛️ Summary Architecture Comparison

┌──────────────────────────────┬────────────────────────┬────────────────────────┐
│ Architectural Concern        │ Traditional Flutter    │ BlocSignal Ecosystem   │
├──────────────────────────────┼────────────────────────┼────────────────────────┤
│ Async State Representation   │ 4 custom classes/enums │ AsyncState<T> sealed   │
│ In-Flight Race Conditions    │ Dio CancelToken / Rx   │ restartable() builtin  │
│ Duplicate Tap Protection     │ Custom boolean flags   │ droppable() builtin    │
│ Frame-1 Offline Persistence  │ SQLite / SharedPreferences│ HydratedMixin frame-1│
│ Existing Base Class Interop  │ Proxy/Wrapper classes  │ CubitSignalMixin       │
└──────────────────────────────┴────────────────────────┴────────────────────────┘

By pairing pure Dart reactive signal primitives with composable mixins and higher-order concurrency transformers, your networking layer remains clean, testable, and robust—with a fraction of the traditional ceremony.

💬 Join the Discussion!

How do you currently handle cancellation, offline caching, and async state in your Flutter networking layer?

Share your architecture setups and thoughts in the comments below!

Read the whole story
alvinashcraft
55 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Designing Android's missing WorkManager test rule

1 Share

TL;DR - create a work manager rule to make your tests easier to write. It’s not hard to do, and it pays off.

I have been working quite a bit with WorkManager stuff these days, and while attempting to write tests for them, I realised there were things I was doing repeatedly.

Work Manager provides a helpful testing library - androidx.work:work-testing and they have a very nice guide on how to write tests for work manager - both integration tests, and testing worker implementation details1, and despite this, I found myself writing a couple of things over and over again.

This post is somewhere between bringing awareness to testing APIs available for WorkManager, and showcasing a test rule that I think can help lower the barrier to testing.


Before

Say I have a SyncDispatcher class that does sync, and sometimes, I want to keep existing work, and other times, I want to replace the existing work.

class SyncDispatcher(val workManager: WorkManager) {
  
  fun sync(params: SyncParams) {
    val existingWorkPolicy = if (params.syncAll) {
			ExistingWorkPolicy.REPLACE
    } else {
      ExistingWorkPolicy.APPEND_OR_REPLACE
    }
    
    val workRequest = OneTimeWorkRequestBuilder<SyncWorker>()
      .setConstraints(Constraints.Builder().setRequiredNetworkType(NetworkType.CONNECTED).build())
      .build()
    workManager.beginUniqueWork("sync-work", existingWorkPolicy, workRequest)
    	.enqueue()
  }
}

If I wanted to test this behaviour in an “integration-testing” style, I could use the TestDriver API2 of work manager to instrument the constraints that my work depends on, be it initial delay, network condition, period delay (for perioidic work), stopping the work with a reason, and so on.

// SyncDispatcherTest.kt
@Before {
  val config = Configuration.Builder().setExecutor(SynchronousExecutor()).build()
  WorkManagerTestInitHelper.initializeTestWorkManager(testContext, config)
}

@Test
fun `sync all drops all prior sync requests`() = runTest() {
  // given that we have previous sync work enqueued
  dispatch.sync(syncPartialParams)
  
  // when we receive a refresh all
  dispatch.sync(syncAllParams)
  
  // then when all constraints are met
  val requests = WorkManager.getInstance(context)
  	.getWorkInfosForUniqueWork("sync-work")
  	.get()
  val driver = WorkManagerTestInitHelper.getTestDriver(context)
  requests.forEach { driver?.setAllConstraintsMet(it.id)  }
  
  // then we verify that the syncer recorded only the "sync all" params
  assertEquals(
    listOf(syncAllParams), 
    fakeSyncer.recordedSyncParams,
  )
}

By the time I want test various combinations of work state, like failed sync, retries, etc, I will be doing a lot of these checks queries, and driver calls. Then, when I want to do it for another worker, I have to do the same scaffolding - initialising the work manager test init helper, and execute various APIs to enqueue work and query the work state.

Over time, I have found that these operations were finite, in some sense. I typically would do things like: make a certain work run (whether by tag, or unique name, or by id), confirm that a certain work is cancelled, and so on.

So, naturally, I started thinking about how to stop writing all these things over, without creating a BaseWorkManagerTest, because test rules are better for composition, than a base test class3.

I thought about simple top-level functions with the convenience APIs I wanted. That would work, but I would still have to copy-pasta a lot of the work manager test initialisation and test cleanup, and the retrieval API. Furthermore, I did not like that the top-level functions would not be scoped to anything.

I understand that it may be hard to find an API that covers everyone’s use-cases, so your mileage may vary, but I think an API like this should exist.

WorkManagerTestRule4

The rule itself is not a lot, the problems I wanted to solve were:

  1. Easy initialisation with the ability to override the configuration during setup.
  2. Unified API access to work manager test utilities. I noticed some of my test operations involved using the TestDriver to modify the work state, and some involved querying the work manager directly to verify the state. I would love a unified API to mess with work manager in my test environment.

Work Manager Initialisation in tests

class WorkManagerTestRule(
  private val context: Context = InstrumentationRegistry.getInstrumentation().targetContext
) : ExternalResource() {

  private val executor = SynchronousExecutor()

  /**
   * [Configuration.Builder] for the [WorkManager] used in the test.
   *
   * The default value sets the executor to be the [SynchronousExecutor]. To add more config or
   * change the builder, do so before your test setup returns.
   */
  var configBuilder: Configuration.Builder =
    Configuration.Builder().setExecutor(executor).setTaskExecutor(executor)

  val driver: TestDriver? by lazy {
    WorkManagerTestInitHelper.getTestDriver(context)
  }

  val workManager by lazy {
    WorkManager.getInstance(context)
  }

  override fun before() {
    super.before()
    WorkManagerTestInitHelper.initializeTestWorkManager(context, configBuilder.build())
  }

  override fun after() {
    super.after()
    WorkManagerTestInitHelper.closeWorkDatabase()
  }
}

If you’re using JUnit 5 already in your project (I’m jealous), then you can convert that into an extension and applying the corresponding test lifecycle callbacks.

Work Manager Convenience APIs for tests

To solve the problem of convenience APIs, I created a bunch of helper methods that mirror what I tend to do often.


/**
 * Enqueues a [WorkRequest]. The work request only runs if there are no constraints or all the
 * constraints are met.
 *
 * Shortcut for [WorkManager.enqueue]
 */
fun WorkManagerTestRule.enqueue(request: WorkRequest): Operation {
  return workManager.enqueue(request)
}

/**
 * Enqueues a list of [WorkRequest]s. The work requests only run if there are no constraints or all
 * the constraints are met.
 *
 * Shortcut for [WorkManager.enqueue]
 */
fun WorkManagerTestRule.enqueue(requests: List<WorkRequest>): Operation {
  return workManager.enqueue(requests)
}

/**
 * Enqueues a [WorkRequest], and then meets its constraints to execute it.
 *
 * Shortcut for [WorkManager.enqueue] and [TestDriver.setAllConstraintsMet]
 */
fun WorkManagerTestRule.execute(request: WorkRequest) {
  with(request) {
    workManager.enqueue(this)
    driver?.setAllConstraintsMet(id)
  }
}

/**
 * Enqueues a list of [WorkRequest]s, and then meets all their constraints to execute them.
 *
 * Shortcut for [WorkManager.enqueue] and [TestDriver.setAllConstraintsMet]
 */
fun WorkManagerTestRule.execute(requests: List<WorkRequest>) {
  requests.forEach { request ->
    execute(request)
  }
}

/** Executes all work that match the given [query] by meeting all their constraints to. */
fun WorkManagerTestRule.execute(query: WorkQuery) {
  val infos = workManager.getWorkInfos(query).get()
  infos.forEach { setAllConstraintsMet(it.id) }
}

/**
 * Sets all constraints on the WorkManager work with the given [workSpecId]. Shortcut for
 * [TestDriver.setAllConstraintsMet]
 */
fun WorkManagerTestRule.setAllConstraintsMet(workSpecId: UUID) {
  driver?.setAllConstraintsMet(workSpecId)
}

I couldn’t possibly figure out whatever everyone would like to do, so I decided to expose the driver, and the work manager as well, and if there’s some operation that the rule does not support, you could write your own extension and implement it.

The test rule helps me to hide the complexities involved in the work manager lifecycle - which in itself is complex, and tends to bring the complexity into the test code, and I suspect this is why I haven’t seen a lot of these integration tests in the project I’m working on.

After

With the test rule, the original SyncDispatcher scenario then looks like this:

// SyncDispatcherTest.kt
-@Before {
-  val config = Configuration.Builder().setExecutor(SynchronousExecutor()).build()
-  WorkManagerTestInitHelper.initializeTestWorkManager(testContext, config)
-}
+@get:Rule
+val workManagerTestRule = WorkManagerTestRule(context)

@Test
fun `sync all drops all prior sync requests`() = runTest() {
  // given that we have previous sync work enqueued
  dispatch.sync(syncPartialParams)
  
  // when we receive a refresh all
  dispatch.sync(syncAllParams)
  
  // then when all constraints are met
-  val requests = WorkManager.getInstance(context)
-  	.getWorkInfosForUniqueWork("sync-work")
-  	.get()
-  val driver = WorkManagerTestInitHelper.getTestDriver(context)
-  requests.forEach { driver?.setAllConstraintsMet(it.id)  }
+  val syncWorkQuery = WorkQuery.Builder.fromUniqueWorkNames(listOf("sync-work")).build()
+  workManagerTestRule.execute(syncWorkQuery)

  // then we verify that the syncer recorded only the "sync all" params
  assertEquals(
    listOf(syncAllParams), 
    fakeSyncer.recordedSyncParams,
  )
}

By the time you apply this to all the work manager states and behaviour you may be testing, all the other workers, etc, this simple rule starts to pay off in terms of test code size and complexity.

Footnotes

  1. WorkManager integration test guide 

  2. WorkManager TestDriver API for instrumenting the work manager workers 

  3. “Don’t be lazy, use @Rules” 

  4. WorkManagerTestRule - my take on the missing WorkManager test rule 

Read the whole story
alvinashcraft
55 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

How fast is .NET 11 Runtime Async?

1 Share

How fast is .NET 11 Runtime Async?
11 minutes by Kai Sawano

Runtime Async is a new asynchronous execution model arriving in .NET 11. Instead of having the C# compiler eagerly turn every async method into a state machine, it preserves the original asynchronous control flow until runtime, where the JIT can process and optimize it directly.

Cut AI Coding Token Costs by up to 36% with Sonar Vortex
sponsored by Sonar

Sonar Vortex operates inside your AI coding agent’s inner reasoning loop, supplying deep architectural context before code is written, then verifying the output in real time. In testing, software defects dropped by 92% and token consumption decreased. Build safer code while spending less on LLM calls.

Garbage collection fundamentals in .NET
11 minutes by Abdul Rahman

.NET developers never manually free memory. The runtime's Garbage Collector handles it automatically by tracking which objects are still in use and reclaiming the rest. It does this through three steps: marking live objects, sweeping dead ones, and compacting survivors to close memory gaps. Knowing how the stack, heap, and GC work together helps you write code that uses less memory and puts less pressure on the runtime.

Eventual consistency explained
7 minutes by Irina Scurtu

Distributed systems often show stale data briefly after an update. This is not a bug but a deliberate trade-off called eventual consistency, where systems prioritize staying available over guaranteeing every node agrees instantly. DNS, CDNs, and read replicas all work this way already. The real risk is not choosing this trade-off, but failing to design for it and discovering the gap when users notice their data has vanished.

What's new with CoreCLR GC handles
14 minutes by Austin Wise

.NET 9 and 10 brought major updates to GC handles in CoreCLR. Four new generic handle types were added as public APIs, offering better type safety, cleaner code, and a modest performance boost over the old GCHandle struct. Two new internal handle types were also introduced. Weak interior pointer handles track object locations across GC moves, while cross-reference handles solve a tricky problem of coordinating object lifetimes between the .NET and Java garbage collectors when running MAUI apps on Android.

Finding the total number of processors on a machine with .NET
11 minutes by Andrew Lock

Modern .NET has no built-in way to get the total CPU count of a host machine. Environment.ProcessorCount returns processor count available to the process, not the host total. The only solution is to call native system APIs on Windows and macOS, and read a system file on Linux. Each platform needs its own code, then a shared helper ties them together based on the current OS.

And the most popular article from the last issue was:

Read the whole story
alvinashcraft
55 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

OpenAI leaving Cursor: “Developers have to be prepared to adapt when it happens.”

1 Share
Abstract digital glitch art with neon pink, green, blue, purple, and white wavy distorted lines on a black background.

OpenAI stated on Friday that it has notified SpaceX that it intends to wind down its contract providing OpenAI models to Cursor, the Musk empire’s AI-powered code editor.

“We are making this choice because we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk‘s companies violating contracts,” states OpenAI.

The proposed shutoff date is November 12, 2026. Developers who have invested time and effort to skill up with OpenAI via Cursor are now potentially left out in the cold due to corporate machinations beyond their control.

“We know that the people most affected by this decision are the developers who rely on OpenAI models in Cursor. We care about their experience in this transition, and we’re ready to go above and beyond to support them,” states the blog post in a conciliatory tone.

“We cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk’s companies violating contracts.”

OpenAI says it “cares deeply” about developers.

OpenAI’s moves appear to be directed at the broader SpaceX corporate mission and its behavioral traits, rather than at the no-doubt worthy software developers within the organization who work on Cursor. As such, OpenAI is maximizing the time developers can retain access to its models through Cursor by providing the “maximum notice provided” required by its contract. 

“This decision was incredibly tough, as we care deeply about our models being broadly available for developers,” said OpenAI.

SpaceX agreed to acquire Cursor maker Anysphere in June and completed the acquisition on August 14. OpenAI said it has worked with the Cursor team “for nearly four years,” which amounts to almost all of its existence. 

The organization has explained how it uses custom contracts to ensure compliance with its terms of service when working with large corporations such as SpaceX. This custom alignment is designed to ensure that, when integrations with its platform occur, it has adequately provided for safety at scale. 

Elon Musk “broke and violated” terms of contract and service

Citing a report in the New York Times, OpenAI states that, “After Musk acquired Twitter, now part of SpaceX, the company broke the terms of our contract (alongside many others). Under oath earlier this year, Musk admitted⁠ that xAI, now also part of SpaceX, had violated OpenAI’s terms of service (terms which are similar to xAI’s own).”

Detailing its displeasure openly, OpenAI further mentioned that Musk admitted that as a working organization inside of SpaceX, “xAI had violated OpenAI’s terms of service”

Legal & policy analyst and publisher of The Mitchell Report, Andrellos Mitchell tells The New Stack that so long as OpenAI is acting within the terms of its contract, he doesn’t see why it should be expected to continue a business relationship it no longer trusts.

“I think OpenAI and Musk’s companies and products need a clean and permanent break from each other – their relationship has become too adversarial. At some point, continuing to do business together stops making sense,” Mitchell says.

Lamenting the impact these moves have on programmers, Mitchell agrees that developers will “certainly be inconvenienced” and that some may have to change how they work. But he says, “Developers are talented people,” i.e., they will find new tools, new projects, and new jobs to work on. 

“The bigger lesson here is that no developer should assume any particular corporate relationship is permanent. Companies change ownership. Contracts end. Business relationships fall apart. That is part of the marketplace. Developers have to be prepared to adapt when it happens,” underlines Mitchell.

“The bigger lesson here is that no developer should assume any particular corporate relationship is permanent. Companies change ownership. Contracts end. Business relationships fall apart. That is part of the marketplace. Developers have to be prepared to adapt when it happens,” underlines Mitchell.

Underhand use of model distillation techniques

One alleged violation concerns xAI’s partial use of OpenAI technology to train its models, which OpenAI characterizes as prohibited distillation. Musk admitted that xAI had “partly” used OpenAI in this regard.

To add insult to injury, OpenAI reminds the public in its statement that its terms of service are not dissimilar to xAI’s own stipulations regarding operational mandates.

“As AI capabilities advance, we also have a new level of accountability to ensure our upcoming model, Astra, is being used in accordance with our terms. Given all of this, we’ve decided to hold the contract cancellation to the latest date we can while not providing future models to Cursor,” said OpenAI.

See also: OpenAI’s Astra can do a researcher’s week of work. That’s the problem.

Wider reactions, contractions and ramifications

Co-founder and CEO of Cursor (and now a SpaceX employee), Michael Truell, writes on X that he’s sorry to see OpenAI’s intended block now coming to light.

“OpenAI models serve about 5% of Cursor user traffic, and we’re speaking with the OpenAI team to resolve this. Cursor was one of the very first users of OpenAI; we’ve worked closely with their team for years, and we’ve trusted their platform to be neutral infrastructure for our business,” writes Truell.

Anthropic co-founder and chief compute officer Tom Brown capitalized on the opportunity and his firm’s ongoing bond with Cursor. He used X to state that, “Cursor has been a trusted partner of Anthropic since Sonnet 3.5. We’ll continue to increase compute to support Claude models in Cursor and are excited for what comes next with them at SpaceX.”

AI startup advisor at Open Machine and ex-IBM Watson and machine learning leader at AWS, Allie K. Miller, writes on X to say that, “It’s hard for me to see a world where OpenAI continues to provide model access to a Musk-led company. Maybe if the structure of SpaceX shifts to allow for it, but that’s a big shift.”

What alternatives can developers turn to next?

To continue using OpenAI models within the Cursor application, OpenAI invites developers to choose one of three options that best fit their workflow.

  • Option #1 is to bring your own OpenAI API key. This means developers could continue using OpenAI models in Cursor’s local Chat and Agent features, but appropriately billed at OpenAI API prices
  • Option #2 is to use the Codex IDE extension; this means developers would useOpenAI’ss AI coding agent, Codex, directly in Cursor with a ChatGPT subscription or an OpenAI API key. 
  • Option #3 is to use an AI gateway provider, meaning developers would connect Cursor to OpenAI models through an account they have with a compatible provider such as Amazon Bedrock, Azure, or another OpenAI-compatible gateway.

This is not the first time OpenAI has been concerned about potential or alleged misuse of its models in relation to distillation. In February of this year, Reuters reported that OpenAI had warned U.S. lawmakers that “Chinese AI startup DeepSeek is targeting the ChatGPT maker” and the nation’s leading AI companies to replicate models and use them for its own training.

The post OpenAI leaving Cursor: “Developers have to be prepared to adapt when it happens.” appeared first on The New Stack.

Read the whole story
alvinashcraft
3 hours ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories