Scope Android artifact fingerprints to build inputs

This commit is contained in:
SimpleTest 2026-08-03 20:10:26 +03:00
parent 4d321b92f5
commit 39c07ea0ff
2 changed files with 33 additions and 3 deletions

View File

@ -17,6 +17,16 @@ source_files=()
for relative_path in "${candidate_files[@]}"; do for relative_path in "${candidate_files[@]}"; do
absolute_path="$ROOT/$relative_path" absolute_path="$ROOT/$relative_path"
# Play Console copy and artwork live beside the Android project so release
# operators can find them, but Gradle never consumes them when producing an
# APK or AAB. Keep the artifact fingerprint bound to binary build inputs,
# not to reviewer instructions or store-listing edits.
case "$relative_path" in
android/README.md|android/play-store/*|android/store-assets/*)
continue
;;
esac
# `git ls-files --cached` also reports tracked paths deleted in the working # `git ls-files --cached` also reports tracked paths deleted in the working
# tree. They are not inputs to the artifact being built, so exclude them # tree. They are not inputs to the artifact being built, so exclude them
# from the working-tree fingerprint instead of treating a valid deletion as # from the working-tree fingerprint instead of treating a valid deletion as
@ -29,16 +39,20 @@ for relative_path in "${candidate_files[@]}"; do
done done
if [[ "${#source_files[@]}" -eq 0 ]]; then if [[ "${#source_files[@]}" -eq 0 ]]; then
echo "No Android source files were found." >&2 echo "No Android build input files were found." >&2
exit 1 exit 1
fi fi
{ {
# Version the input contract so a future deliberate scope change cannot
# silently compare equal to a fingerprint produced by this implementation.
printf 'who-need-help-android-build-inputs-v2\0'
for relative_path in "${source_files[@]}"; do for relative_path in "${source_files[@]}"; do
absolute_path="$ROOT/$relative_path" absolute_path="$ROOT/$relative_path"
if [[ ! -f "$absolute_path" ]]; then if [[ ! -f "$absolute_path" ]]; then
echo "Android source input is not a regular file: $relative_path" >&2 echo "Android build input is not a regular file: $relative_path" >&2
exit 1 exit 1
fi fi

View File

@ -30,7 +30,9 @@ socket_proxy_container="wnh-socket-proxy-audit-$run_id"
scan_dir=$(mktemp -d "${TMPDIR:-/tmp}/wnh-quality-scan.XXXXXX") scan_dir=$(mktemp -d "${TMPDIR:-/tmp}/wnh-quality-scan.XXXXXX")
scan_list="${scan_dir}.files" scan_list="${scan_dir}.files"
scan_tar="${scan_dir}.tar" scan_tar="${scan_dir}.tar"
android_fingerprint_probe="$ROOT/android/.quality-source-fingerprint-$run_id" android_fingerprint_probe_dir="$ROOT/android/app/src/main/assets"
android_fingerprint_probe="$android_fingerprint_probe_dir/.quality-source-fingerprint-$run_id"
android_metadata_probe="$ROOT/android/play-store/.quality-metadata-$run_id.md"
umask 077 umask 077
QUALITY_POSTGRES_USER="wnh_quality_$(openssl rand -hex 6)" QUALITY_POSTGRES_USER="wnh_quality_$(openssl rand -hex 6)"
@ -51,6 +53,8 @@ cleanup() {
"$caddy_image" "$traefik_image" \ "$caddy_image" "$traefik_image" \
>/dev/null 2>&1 || true >/dev/null 2>&1 || true
rm -f "$android_fingerprint_probe" rm -f "$android_fingerprint_probe"
rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true
rm -f "$android_metadata_probe"
rm -rf "$scan_dir" "$scan_list" "$scan_tar" rm -rf "$scan_dir" "$scan_list" "$scan_tar"
} }
trap cleanup EXIT HUP INT TERM trap cleanup EXIT HUP INT TERM
@ -142,6 +146,17 @@ printf '%s\n' "$android_fingerprint_before" \
"$android_artifact_probe" \ "$android_artifact_probe" \
scripts/android-development-build.sh >/dev/null scripts/android-development-build.sh >/dev/null
printf '%s\n' 'quality store metadata mutation' >"$android_metadata_probe"
if [ "$(./scripts/android-source-fingerprint.sh)" != "$android_fingerprint_before" ]; then
echo "Android source fingerprint changed for Play Store metadata." >&2
exit 1
fi
./scripts/verify-android-artifact-source.sh \
"$android_artifact_probe" \
scripts/android-development-build.sh >/dev/null
rm -f "$android_metadata_probe"
mkdir -p "$android_fingerprint_probe_dir"
printf '%s\n' 'quality source mutation' >"$android_fingerprint_probe" printf '%s\n' 'quality source mutation' >"$android_fingerprint_probe"
android_fingerprint_after=$(./scripts/android-source-fingerprint.sh) android_fingerprint_after=$(./scripts/android-source-fingerprint.sh)
if [ "$android_fingerprint_before" = "$android_fingerprint_after" ]; then if [ "$android_fingerprint_before" = "$android_fingerprint_after" ]; then
@ -156,6 +171,7 @@ if ./scripts/verify-android-artifact-source.sh \
fi fi
rm -f "$android_fingerprint_probe" rm -f "$android_fingerprint_probe"
rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true
test "$(./scripts/android-source-fingerprint.sh)" = "$android_fingerprint_before" test "$(./scripts/android-source-fingerprint.sh)" = "$android_fingerprint_before"
printf '%s\n' malformed >"$android_artifact_probe/source-fingerprint.sha256" printf '%s\n' malformed >"$android_artifact_probe/source-fingerprint.sha256"
if ./scripts/verify-android-artifact-source.sh \ if ./scripts/verify-android-artifact-source.sh \