billing-google-play

byBachir Djoukbala

Act as an Android internal systems engineer and reverse engineer. Objective: I am diagnosing an issue where an Android app/game initiates an in-app billing flow via Google Play Store (com.android.vending), but the billing bottom sheet resolves to the wrong Google account on a multi-account device. I want to test command-line methods via Termux (both non-root, root/su, and ADB/Shizuku privileges) to understand how Google Play determines the active buyer account and whether we can manipulate that state programmatically. Please provide: 1. Exact shell commands to query the current account state and licensing bindings: - Inspecting package installer / licensing metadata via `pm dump <package_name>` or `cmd package`. - Querying the system accounts database (/data/system_de/0/accounts_de.db) and Google Auth token caches. 2. Direct CLI tests: - Can we use `cmd appops`, `cmd package`, or `am start` intents with specific extras to force a specific account context when launching the game or the billing activity? - How does Android's `DevicePolicyManager` (dpm) CLI interact with account visibility or account restriction per user/profile? 3. Android multi-user / Work Profile automation via CLI: - Provide the exact ADB/Termux commands (`pm create-user`, `am switch-user`, or `dpm` commands) to spin up an isolated profile with a single targeted Google account, clone the target APK into it, and launch it. 4. Feasibility analysis for developing a standalone manager app: - If writing an app, what specific system permissions or architecture (Device Owner API vs. Shizuku privileged service vs. LSPosed Xposed hook on com.android.vending's billing AIDL interface) would actually be capable of intercepting or dictating the account returned to the billing sheet? - Provide the specific method signatures or AIDL interfaces within com.android.vending that handle buyer account resolution. Rules: - Be strictly technical and provide actual CLI commands and code definitions. - Avoid generic user-facing advice like "clear cache" or "reinstall the app".

No preview

Comments (0)

No comments yet. Be the first!

Project Tasks

22 tasks
#1

Generate system requirement document

1m 28s0.2 cr used
Done
#2

Generate personas & user flows

0m 8s0.2 cr used
Done
#7

Create flow for Android Internal Systems Engineer / Reverse Engineer

0m 7sCredits in parent
Done
#3

Design first page

0m 17s0.2 cr used
Done
#4

Design remaining pages

Not recorded0.2 cr needed
Done
#5

Architecture

0m 57s0.2 cr used
Done
#8

Create frontend_modules diagram

0m 35sCredits in parent
Done
#9

Create sequence diagram

0m 35sCredits in parent
Done
#6

Workspace task plan

2m 8s0.2 cr used
Done
#10

Automate multi-user / Work Profile isolation and launch the cloned target APK

120 cr estimated
To Do
#11

Landing hero probe: copy command, unavailable-output recovery, and investigation context

80 cr estimated
To Do
#12

Manager architecture evaluation with reachability verdicts and snippet copy

100 cr estimated
To Do
#13

Billing Interfaces signature table with build-dependent verification

80 cr estimated
To Do
#14

CLI tests and Termux probes for account state and licensing bindings

100 cr estimated
To Do
#15

Account Inspection command copy and build-dependent claim marking

80 cr estimated
To Do
#20

Build the Policy Controls page for dpm account visibility and restriction

100 cr estimated
To Do
#21

Build the CLI Tests page for account-context selection attempts

100 cr estimated
To Do
#16

User Isolation page: isolation recipe, step commands, and recovery

100 cr estimated
To Do
#17

Billing Interfaces page: signature table, entry-point annotation, and verification

80 cr estimated
To Do
#18

Build the Landing page as the console's working instrument

120 cr estimated
To Do
#19

Build the Manager Architecture feasibility comparison page

100 cr estimated
To Do
#22

Build the Account Inspection page for account state and licensing queries

120 cr estimated
To Do

No completed page designs yet.

Completed design pages will appear here when they are ready to preview.

Landing: Read masthead and probe panel
Landing: Copy hero probe command
Landing: Copy command despite output not captured
Landing: Read buyer-account resolution diagram
Account Inspection: 1. Copy pm dump command
Account Inspection: 2. Copy cmd package command
Account Inspection: 3. Query accounts_de.db
Account Inspection: 4. Inspect Google Auth token caches
Account Inspection: 5. Escalate privilege or use alternative
Account Inspection: 6. Read account-state table
CLI Tests: 7. Copy cmd appops test
CLI Tests: 8. Read appops-value table
CLI Tests: 9. Copy cmd package test
CLI Tests: 10. Copy am start intent test
CLI Tests: 11. Note no effect on account context
Policy Controls: 12. Copy dpm subcommand
Policy Controls: 13. Read per-user scope note
Policy Controls: 14. Read effect note
Policy Controls: 15. Provision owner context or use alternative
User Isolation: 16. Copy pm create-user command
User Isolation: 17. Read expected result for new user
User Isolation: 18. Copy am switch-user command
User Isolation: 19. Add single targeted Google account
User Isolation: 20. Copy APK install command
User Isolation: 21. Copy launch command
User Isolation: 22. Observe resolved billing account
User Isolation: 23. Remove user and retry alternative
Manager Architecture: 24. Read architecture comparison table
Manager Architecture: 25. Read reachable surface and verdict
Manager Architecture: 26. Copy permission or manifest snippet
Manager Architecture: 27. Note cannot dictate account
Billing Interfaces: 28. Read signature table
Billing Interfaces: 29. Read parameter types and interface index
Billing Interfaces: 30. Copy signature
Billing Interfaces: 31. Cross-reference Landing resolution flow
Billing Interfaces: 32. Verify signature against own build

No completed page designs yet.

Completed design pages will appear here when they are ready to preview.

Landing: Read masthead and probe panel
Landing: Copy hero probe command
Landing: Copy command despite output not captured
Landing: Read buyer-account resolution diagram
Account Inspection: 1. Copy pm dump command
Account Inspection: 2. Copy cmd package command
Account Inspection: 3. Query accounts_de.db
Account Inspection: 4. Inspect Google Auth token caches
Account Inspection: 5. Escalate privilege or use alternative
Account Inspection: 6. Read account-state table
CLI Tests: 7. Copy cmd appops test
CLI Tests: 8. Read appops-value table
CLI Tests: 9. Copy cmd package test
CLI Tests: 10. Copy am start intent test
CLI Tests: 11. Note no effect on account context
Policy Controls: 12. Copy dpm subcommand
Policy Controls: 13. Read per-user scope note
Policy Controls: 14. Read effect note
Policy Controls: 15. Provision owner context or use alternative
User Isolation: 16. Copy pm create-user command
User Isolation: 17. Read expected result for new user
User Isolation: 18. Copy am switch-user command
User Isolation: 19. Add single targeted Google account
User Isolation: 20. Copy APK install command
User Isolation: 21. Copy launch command
User Isolation: 22. Observe resolved billing account
User Isolation: 23. Remove user and retry alternative
Manager Architecture: 24. Read architecture comparison table
Manager Architecture: 25. Read reachable surface and verdict
Manager Architecture: 26. Copy permission or manifest snippet
Manager Architecture: 27. Note cannot dictate account
Billing Interfaces: 28. Read signature table
Billing Interfaces: 29. Read parameter types and interface index
Billing Interfaces: 30. Copy signature
Billing Interfaces: 31. Cross-reference Landing resolution flow
Billing Interfaces: 32. Verify signature against own build