Scope Android artifact fingerprints to build inputs
This commit is contained in:
parent
4d321b92f5
commit
39c07ea0ff
|
|
@ -17,6 +17,16 @@ source_files=()
|
||||||
for relative_path in "${candidate_files[@]}"; do
|
for relative_path in "${candidate_files[@]}"; do
|
||||||
absolute_path="$ROOT/$relative_path"
|
absolute_path="$ROOT/$relative_path"
|
||||||
|
|
||||||
|
# Play Console copy and artwork live beside the Android project so release
|
||||||
|
# operators can find them, but Gradle never consumes them when producing an
|
||||||
|
# APK or AAB. Keep the artifact fingerprint bound to binary build inputs,
|
||||||
|
# not to reviewer instructions or store-listing edits.
|
||||||
|
case "$relative_path" in
|
||||||
|
android/README.md|android/play-store/*|android/store-assets/*)
|
||||||
|
continue
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
# `git ls-files --cached` also reports tracked paths deleted in the working
|
# `git ls-files --cached` also reports tracked paths deleted in the working
|
||||||
# tree. They are not inputs to the artifact being built, so exclude them
|
# tree. They are not inputs to the artifact being built, so exclude them
|
||||||
# from the working-tree fingerprint instead of treating a valid deletion as
|
# from the working-tree fingerprint instead of treating a valid deletion as
|
||||||
|
|
@ -29,16 +39,20 @@ for relative_path in "${candidate_files[@]}"; do
|
||||||
done
|
done
|
||||||
|
|
||||||
if [[ "${#source_files[@]}" -eq 0 ]]; then
|
if [[ "${#source_files[@]}" -eq 0 ]]; then
|
||||||
echo "No Android source files were found." >&2
|
echo "No Android build input files were found." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
{
|
{
|
||||||
|
# Version the input contract so a future deliberate scope change cannot
|
||||||
|
# silently compare equal to a fingerprint produced by this implementation.
|
||||||
|
printf 'who-need-help-android-build-inputs-v2\0'
|
||||||
|
|
||||||
for relative_path in "${source_files[@]}"; do
|
for relative_path in "${source_files[@]}"; do
|
||||||
absolute_path="$ROOT/$relative_path"
|
absolute_path="$ROOT/$relative_path"
|
||||||
|
|
||||||
if [[ ! -f "$absolute_path" ]]; then
|
if [[ ! -f "$absolute_path" ]]; then
|
||||||
echo "Android source input is not a regular file: $relative_path" >&2
|
echo "Android build input is not a regular file: $relative_path" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -30,7 +30,9 @@ socket_proxy_container="wnh-socket-proxy-audit-$run_id"
|
||||||
scan_dir=$(mktemp -d "${TMPDIR:-/tmp}/wnh-quality-scan.XXXXXX")
|
scan_dir=$(mktemp -d "${TMPDIR:-/tmp}/wnh-quality-scan.XXXXXX")
|
||||||
scan_list="${scan_dir}.files"
|
scan_list="${scan_dir}.files"
|
||||||
scan_tar="${scan_dir}.tar"
|
scan_tar="${scan_dir}.tar"
|
||||||
android_fingerprint_probe="$ROOT/android/.quality-source-fingerprint-$run_id"
|
android_fingerprint_probe_dir="$ROOT/android/app/src/main/assets"
|
||||||
|
android_fingerprint_probe="$android_fingerprint_probe_dir/.quality-source-fingerprint-$run_id"
|
||||||
|
android_metadata_probe="$ROOT/android/play-store/.quality-metadata-$run_id.md"
|
||||||
|
|
||||||
umask 077
|
umask 077
|
||||||
QUALITY_POSTGRES_USER="wnh_quality_$(openssl rand -hex 6)"
|
QUALITY_POSTGRES_USER="wnh_quality_$(openssl rand -hex 6)"
|
||||||
|
|
@ -51,6 +53,8 @@ cleanup() {
|
||||||
"$caddy_image" "$traefik_image" \
|
"$caddy_image" "$traefik_image" \
|
||||||
>/dev/null 2>&1 || true
|
>/dev/null 2>&1 || true
|
||||||
rm -f "$android_fingerprint_probe"
|
rm -f "$android_fingerprint_probe"
|
||||||
|
rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true
|
||||||
|
rm -f "$android_metadata_probe"
|
||||||
rm -rf "$scan_dir" "$scan_list" "$scan_tar"
|
rm -rf "$scan_dir" "$scan_list" "$scan_tar"
|
||||||
}
|
}
|
||||||
trap cleanup EXIT HUP INT TERM
|
trap cleanup EXIT HUP INT TERM
|
||||||
|
|
@ -142,6 +146,17 @@ printf '%s\n' "$android_fingerprint_before" \
|
||||||
"$android_artifact_probe" \
|
"$android_artifact_probe" \
|
||||||
scripts/android-development-build.sh >/dev/null
|
scripts/android-development-build.sh >/dev/null
|
||||||
|
|
||||||
|
printf '%s\n' 'quality store metadata mutation' >"$android_metadata_probe"
|
||||||
|
if [ "$(./scripts/android-source-fingerprint.sh)" != "$android_fingerprint_before" ]; then
|
||||||
|
echo "Android source fingerprint changed for Play Store metadata." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
./scripts/verify-android-artifact-source.sh \
|
||||||
|
"$android_artifact_probe" \
|
||||||
|
scripts/android-development-build.sh >/dev/null
|
||||||
|
rm -f "$android_metadata_probe"
|
||||||
|
|
||||||
|
mkdir -p "$android_fingerprint_probe_dir"
|
||||||
printf '%s\n' 'quality source mutation' >"$android_fingerprint_probe"
|
printf '%s\n' 'quality source mutation' >"$android_fingerprint_probe"
|
||||||
android_fingerprint_after=$(./scripts/android-source-fingerprint.sh)
|
android_fingerprint_after=$(./scripts/android-source-fingerprint.sh)
|
||||||
if [ "$android_fingerprint_before" = "$android_fingerprint_after" ]; then
|
if [ "$android_fingerprint_before" = "$android_fingerprint_after" ]; then
|
||||||
|
|
@ -156,6 +171,7 @@ if ./scripts/verify-android-artifact-source.sh \
|
||||||
fi
|
fi
|
||||||
|
|
||||||
rm -f "$android_fingerprint_probe"
|
rm -f "$android_fingerprint_probe"
|
||||||
|
rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true
|
||||||
test "$(./scripts/android-source-fingerprint.sh)" = "$android_fingerprint_before"
|
test "$(./scripts/android-source-fingerprint.sh)" = "$android_fingerprint_before"
|
||||||
printf '%s\n' malformed >"$android_artifact_probe/source-fingerprint.sha256"
|
printf '%s\n' malformed >"$android_artifact_probe/source-fingerprint.sha256"
|
||||||
if ./scripts/verify-android-artifact-source.sh \
|
if ./scripts/verify-android-artifact-source.sh \
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user