Scope Android artifact fingerprints to build inputs
This commit is contained in:
parent
4d321b92f5
commit
39c07ea0ff
|
|
@ -17,6 +17,16 @@ source_files=()
|
|||
for relative_path in "${candidate_files[@]}"; do
|
||||
absolute_path="$ROOT/$relative_path"
|
||||
|
||||
# Play Console copy and artwork live beside the Android project so release
|
||||
# operators can find them, but Gradle never consumes them when producing an
|
||||
# APK or AAB. Keep the artifact fingerprint bound to binary build inputs,
|
||||
# not to reviewer instructions or store-listing edits.
|
||||
case "$relative_path" in
|
||||
android/README.md|android/play-store/*|android/store-assets/*)
|
||||
continue
|
||||
;;
|
||||
esac
|
||||
|
||||
# `git ls-files --cached` also reports tracked paths deleted in the working
|
||||
# tree. They are not inputs to the artifact being built, so exclude them
|
||||
# from the working-tree fingerprint instead of treating a valid deletion as
|
||||
|
|
@ -29,16 +39,20 @@ for relative_path in "${candidate_files[@]}"; do
|
|||
done
|
||||
|
||||
if [[ "${#source_files[@]}" -eq 0 ]]; then
|
||||
echo "No Android source files were found." >&2
|
||||
echo "No Android build input files were found." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
{
|
||||
# Version the input contract so a future deliberate scope change cannot
|
||||
# silently compare equal to a fingerprint produced by this implementation.
|
||||
printf 'who-need-help-android-build-inputs-v2\0'
|
||||
|
||||
for relative_path in "${source_files[@]}"; do
|
||||
absolute_path="$ROOT/$relative_path"
|
||||
|
||||
if [[ ! -f "$absolute_path" ]]; then
|
||||
echo "Android source input is not a regular file: $relative_path" >&2
|
||||
echo "Android build input is not a regular file: $relative_path" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
|
|
|||
|
|
@ -30,7 +30,9 @@ socket_proxy_container="wnh-socket-proxy-audit-$run_id"
|
|||
scan_dir=$(mktemp -d "${TMPDIR:-/tmp}/wnh-quality-scan.XXXXXX")
|
||||
scan_list="${scan_dir}.files"
|
||||
scan_tar="${scan_dir}.tar"
|
||||
android_fingerprint_probe="$ROOT/android/.quality-source-fingerprint-$run_id"
|
||||
android_fingerprint_probe_dir="$ROOT/android/app/src/main/assets"
|
||||
android_fingerprint_probe="$android_fingerprint_probe_dir/.quality-source-fingerprint-$run_id"
|
||||
android_metadata_probe="$ROOT/android/play-store/.quality-metadata-$run_id.md"
|
||||
|
||||
umask 077
|
||||
QUALITY_POSTGRES_USER="wnh_quality_$(openssl rand -hex 6)"
|
||||
|
|
@ -51,6 +53,8 @@ cleanup() {
|
|||
"$caddy_image" "$traefik_image" \
|
||||
>/dev/null 2>&1 || true
|
||||
rm -f "$android_fingerprint_probe"
|
||||
rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true
|
||||
rm -f "$android_metadata_probe"
|
||||
rm -rf "$scan_dir" "$scan_list" "$scan_tar"
|
||||
}
|
||||
trap cleanup EXIT HUP INT TERM
|
||||
|
|
@ -142,6 +146,17 @@ printf '%s\n' "$android_fingerprint_before" \
|
|||
"$android_artifact_probe" \
|
||||
scripts/android-development-build.sh >/dev/null
|
||||
|
||||
printf '%s\n' 'quality store metadata mutation' >"$android_metadata_probe"
|
||||
if [ "$(./scripts/android-source-fingerprint.sh)" != "$android_fingerprint_before" ]; then
|
||||
echo "Android source fingerprint changed for Play Store metadata." >&2
|
||||
exit 1
|
||||
fi
|
||||
./scripts/verify-android-artifact-source.sh \
|
||||
"$android_artifact_probe" \
|
||||
scripts/android-development-build.sh >/dev/null
|
||||
rm -f "$android_metadata_probe"
|
||||
|
||||
mkdir -p "$android_fingerprint_probe_dir"
|
||||
printf '%s\n' 'quality source mutation' >"$android_fingerprint_probe"
|
||||
android_fingerprint_after=$(./scripts/android-source-fingerprint.sh)
|
||||
if [ "$android_fingerprint_before" = "$android_fingerprint_after" ]; then
|
||||
|
|
@ -156,6 +171,7 @@ if ./scripts/verify-android-artifact-source.sh \
|
|||
fi
|
||||
|
||||
rm -f "$android_fingerprint_probe"
|
||||
rmdir "$android_fingerprint_probe_dir" >/dev/null 2>&1 || true
|
||||
test "$(./scripts/android-source-fingerprint.sh)" = "$android_fingerprint_before"
|
||||
printf '%s\n' malformed >"$android_artifact_probe/source-fingerprint.sha256"
|
||||
if ./scripts/verify-android-artifact-source.sh \
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user