Skip to content

fix(core): Clear the persisted replay id when resetting the scope cache - #6033

Merged
runningcode merged 3 commits into
mainfrom
no/clear-persisted-replay-id-on-init
Sep 29, 2026
Merged

runningcode merged 3 commits into
mainfrom
no/clear-persisted-replay-id-on-init

Conversation

@runningcode

@runningcode runningcode commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

📜 Description

PersistingScopeObserver.resetCache() runs on SDK init and clears the persisted scope so values from the previous process don't leak into the new one. It deletes user, level, request, fingerprint, contexts, extras, tags, trace and transaction, and clears the breadcrumb queue — but it has never touched replay.json.

This adds delete(REPLAY_FILENAME) alongside the others, plus a test in PersistingScopeObserverBatchingTest.

💡 Motivation and Context

A replay id points at a replay recorded by the process that wrote it. Leaving it on disk across an init means ApplicationExitInfoEventProcessor can read a stale id and attach it to an ANR event from the current process. The impact is bounded — the processor falls back to scanning for the newest replay_* folder when the id's folder is gone, and the replay integration overwrites the file once it starts recording — but the id should not survive the reset in the first place.

The intent was there from the start: the comment at the resetCache() call site in Sentry.notifyOptionsObservers already gives replayId as its example of a value that must not reach new events. The implementation just never included it.

💚 How did you test it?

New test resetCache clears the replay id left behind by the previous process in PersistingScopeObserverBatchingTest. Verified it fails without the one-line change (expected: null / but was: <afcb46b1140ade5187c4bbb5daa804df>) and passes with it.

Ran :sentry:test, :sentry-android-core:testReleaseUnitTest and :sentry-android-replay:testReleaseUnitTest — all pass.

📝 Checklist

  • I added GH Issue ID & Linear ID
  • I added tests to verify the changes.
  • No new PII added or SDK only sends newly added PII if sendDefaultPII is enabled.
  • I updated the docs if needed.
  • I updated the wizard if needed.
  • Review from the native team if needed.
  • No breaking change or entry added to the changelog.
  • No breaking change for hybrid SDKs or communicated to hybrid SDKs.
  • Public API changes reviewed by another Mobile SDK team member or implemented according to the develop docs spec.

🔮 Next steps

None.

runningcode and others added 2 commits September 1, 2026 08:58
resetCache() clears every other persisted scope value on init but leaves
replay.json in place, so a replay id written by a previous process can
still be attached to events from the current one. The reset already runs
after the integrations that consume those values, so deleting it here is
safe.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@sentry

sentry Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

📲 Install Builds

Android

🔗 App Name App ID Version Configuration
SDK Size io.sentry.tests.size 8.58.0 (1) release

⚙️ sentry-android Build Distribution Settings

Comment thread sentry/src/main/java/io/sentry/cache/PersistingScopeObserver.java Outdated
@runningcode
runningcode marked this pull request as ready for review September 28, 2026 15:14
@runningcode runningcode added the sanity-check PR needs a lightweight review for obvious issues label Sep 28, 2026

@romtsn romtsn left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>
@runningcode
runningcode merged commit 0f0be1c into main Sep 29, 2026
71 checks passed
@runningcode
runningcode deleted the no/clear-persisted-replay-id-on-init branch September 29, 2026 07:03
runningcode added a commit that referenced this pull request Sep 29, 2026
* docs: Warn about sendDefaultPii removal (#6156)

Make the upcoming removal visible in the data collection changelog entry
so customers know to migrate before the next major SDK version.

Co-authored-by: Claude <noreply@anthropic.com>

* release: 8.58.0

* docs(changelog): Remove warning indentation (#6157)

Co-authored-by: sentry-junior[bot] <264270552+sentry-junior[bot]@users.noreply.github.com>
Co-authored-by: Alexander Dinauer <alexander.dinauer@sentry.io>

* feat(core): Deprecate sendDefaultPii (#6158)

* feat(core): Deprecate sendDefaultPii

Mark the SentryOptions accessors as deprecated and scheduled for removal in 9.0. Direct users to dataCollection while retaining legacy fallback behavior throughout 8.x.

Co-Authored-By: Claude <noreply@anthropic.com>

* changelog

---------

Co-authored-by: Claude <noreply@anthropic.com>

* feat(android): Make tombstone merge time threshold configurable (#6154)

* feat(android): Make tombstone merge time threshold configurable

* changelog

* ref(android): Drop duplicate no-match log and document the merge threshold default

* docs(android): Expand tombstone merge threshold javadoc

* chore(deps): bump the github-actions group across 1 directory with 6 updates (#6169)

Bumps the github-actions group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.2` |
| [getsentry/github-workflows/danger](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/craft](https://github.com/getsentry/craft) | `2.31.0` | `2.31.2` |
| [getsentry/github-workflows/updater](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |



Updates `github/codeql-action/init` from 4.38.0 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...2892aa5)

Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b96794f...2892aa5)

Updates `getsentry/github-workflows/danger` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/craft` from 2.31.0 to 2.31.2
- [Release notes](https://github.com/getsentry/craft/releases)
- [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md)
- [Commits](getsentry/craft@55694f8...25028d0)

Updates `getsentry/github-workflows/updater` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/github-workflows/validate-pr` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/danger
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/craft
  dependency-version: 2.31.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/updater
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/validate-pr
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(detekt): Ignore FunctionNaming for Composable functions (#6176)

Compose functions that emit UI are PascalCase by convention, which
detekt's default FunctionNaming pattern flags. Follow detekt's Compose
guide and skip the rule for @composable functions.

Fixes JAVA-748
Fixes #6175

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(android): Compile Android modules against Android SDK 37.2 (#6172)

Updates our compile SDK version from 37.0 to 37.2 for all Sentry Android modules, which lays the groundwork for accommodating new MemoryLimiter flags introduced in 37.2.

Introduces a mechanism that lets us support compilation against minor SDK versions for any future release.

* ref(android): Match MemoryLimiter app exit reason introduced in Android 37.2 (JAVA-687) (#6174)

Android 37.2 introduced a new ApplicationExitInfo.REASON_MEMORY_LIMITER flag. This commit updates our MemoryLimiterIntegration code to match against it (while preserving ouro previous matching logic).

No new Android API guard is needed for the new flag because:

 - we already check MemoryLimiterIntegration registration against API 37; and
 - REASON_MEMORY_LIMITER is a static integer constant and will be inlined as an integer by the Java compiler (meaning we don't need extra protection for devices on 37.0 or 37.1).

* build(detekt): Apply remaining Compose guide settings (#6179)

Add the rest of detekt's Compose guide on top of the FunctionNaming
change from #6176. Keep accepting SCREAMING_CASE top-level constants,
because the guide's PascalCase-only pattern would flag every existing
TRACE_ORIGIN-style constant.

Refs JAVA-748

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: Link Data Collection changelog to guides (#6180)

Replace duplicated configuration details in the 8.58.0 changelog with links to the Android, Java, and Spring Boot documentation while retaining the sendDefaultPii removal warning.

Co-authored-by: Claude <noreply@anthropic.com>

* fix(core): Clear the persisted replay id when resetting the scope cache (#6033)

* fix(core): Clear the persisted replay id when resetting the scope cache

resetCache() clears every other persisted scope value on init but leaves
replay.json in place, so a replay id written by a previous process can
still be attached to events from the current one. The reset already runs
after the integrations that consume those values, so deleting it here is
safe.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* changelog

* Remove comment

Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>

* build(detekt): Lint all Kotlin modules (#6178)

* build(detekt): Apply Compose guide and lint all Kotlin modules

Add the remaining settings from detekt's Compose guide. Keep accepting
SCREAMING_CASE top-level constants, because the guide's PascalCase-only
pattern would flag every existing TRACE_ORIGIN-style constant.

sentry-compose had the detekt plugin applied but the task was always
NO-SOURCE, because the default source set is src/main and a
multiplatform module keeps its code in src/androidMain. Point it at the
Android source sets. Also enable detekt in sentry-android-replay, where
it was commented out, and in the Kotlin modules that never applied it.

The newly linted modules have 298 existing findings. Record them in
per-module baselines so check passes and only new issues fail. They can
be fixed in follow-ups.

Refs JAVA-748

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* build(detekt): Move Compose guide settings to a separate PR

Regenerate the baselines against main's config so this PR doesn't depend
on the config change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Alexander Dinauer <adinauer@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: adinauer <2542832+adinauer@users.noreply.github.com>
Co-authored-by: sentry-release-bot[bot] <180476844+sentry-release-bot[bot]@users.noreply.github.com>
Co-authored-by: sentry-junior[bot] <264270552+sentry-junior[bot]@users.noreply.github.com>
Co-authored-by: Alexander Dinauer <alexander.dinauer@sentry.io>
Co-authored-by: Markus Hintersteiner <markus.hintersteiner@sentry.io>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Brown <adam.brown@sentry.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

sanity-check PR needs a lightweight review for obvious issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants