From 39c07ea0ffdaa8cd0e9e768e7204c92bb74e88ba Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Mon, 3 Aug 2026 20:10:26 +0300 Subject: [PATCH] Scope Android artifact fingerprints to build inputs --- scripts/android-source-fingerprint.sh | 18 ++++++++++++++++-- scripts/quality.sh | 18 +++++++++++++++++- 2 files changed, 33 insertions(+), 3 deletions(-) diff --git a/scripts/android-source-fingerprint.sh b/scripts/android-source-fingerprint.sh index 1d58d90..a31370b 100755 --- a/scripts/android-source-fingerprint.sh +++ b/scripts/android-source-fingerprint.sh @@ -17,6 +17,16 @@ source_files=() for relative_path in "${candidate_files[@]}"; do absolute_path="$ROOT/$relative_path" + # Play Console copy and artwork live beside the Android project so release + # operators can find them, but Gradle never consumes them when producing an + # APK or AAB. Keep the artifact fingerprint bound to binary build inputs, + # not to reviewer instructions or store-listing edits. + case "$relative_path" in + android/README.md|android/play-store/*|android/store-assets/*) + continue + ;; + esac + # `git ls-files --cached` also reports tracked paths deleted in the working # tree. They are not inputs to the artifact being built, so exclude them # from the working-tree fingerprint instead of treating a valid deletion as @@ -29,16 +39,20 @@ for relative_path in "${candidate_files[@]}"; do done if [[ "${#source_files[@]}" -eq 0 ]]; then - echo "No Android source files were found." >&2 + echo "No Android build input files were found." >&2 exit 1 fi { + # Version the input contract so a future deliberate scope change cannot + # silently compare equal to a fingerprint produced by this implementation. + printf 'who-need-help-android-build-inputs-v2\0' + for relative_path in "${source_files[@]}"; do absolute_path="$ROOT/$relative_path" if [[ ! -f "$absolute_path" ]]; then - echo "Android source input is not a regular file: $relative_path" >&2 + echo "Android build input is not a regular file: $relative_path" >&2 exit 1 fi diff --git a/scripts/quality.sh b/scripts/quality.sh index a40c26c..7bcbe0b 100755 --- a/scripts/quality.sh +++ b/scripts/quality.sh @@ -30,7 +30,9 @@ socket_proxy_container="wnh-socket-proxy-audit-$run_id" scan_dir=$(mktemp -d "${TMPDIR:-/tmp}/wnh-quality-scan.XXXXXX") scan_list="${scan_dir}.files" scan_tar="${scan_dir}.tar" -android_fingerprint_probe="$ROOT/android/.quality-source-fingerprint-$run_id" +android_fingerprint_probe_dir="$ROOT/android/app/src/main/assets" +android_fingerprint_probe="$android_fingerprint_probe_dir/.quality-source-fingerprint-$run_id" +android_metadata_probe="$ROOT/android/play-store/.quality-metadata-$run_id.md" umask 077 QUALITY_POSTGRES_USER="wnh_quality_$(openssl rand -hex 6)" @@ -51,6 +53,8 @@ cleanup() { "$caddy_image" "$traefik_image" \ >/dev/null 2>&1 || true rm -f "$android_fingerprint_probe" + rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true + rm -f "$android_metadata_probe" rm -rf "$scan_dir" "$scan_list" "$scan_tar" } trap cleanup EXIT HUP INT TERM @@ -142,6 +146,17 @@ printf '%s\n' "$android_fingerprint_before" \ "$android_artifact_probe" \ scripts/android-development-build.sh >/dev/null +printf '%s\n' 'quality store metadata mutation' >"$android_metadata_probe" +if [ "$(./scripts/android-source-fingerprint.sh)" != "$android_fingerprint_before" ]; then + echo "Android source fingerprint changed for Play Store metadata." >&2 + exit 1 +fi +./scripts/verify-android-artifact-source.sh \ + "$android_artifact_probe" \ + scripts/android-development-build.sh >/dev/null +rm -f "$android_metadata_probe" + +mkdir -p "$android_fingerprint_probe_dir" printf '%s\n' 'quality source mutation' >"$android_fingerprint_probe" android_fingerprint_after=$(./scripts/android-source-fingerprint.sh) if [ "$android_fingerprint_before" = "$android_fingerprint_after" ]; then @@ -156,6 +171,7 @@ if ./scripts/verify-android-artifact-source.sh \ fi rm -f "$android_fingerprint_probe" +rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true test "$(./scripts/android-source-fingerprint.sh)" = "$android_fingerprint_before" printf '%s\n' malformed >"$android_artifact_probe/source-fingerprint.sha256" if ./scripts/verify-android-artifact-source.sh \