Record production Android bundle verification

This commit is contained in:
SimpleTest 2026-07-28 04:37:33 +03:00
parent c8e95b8c77
commit 3d6f9c5004
2 changed files with 51 additions and 6 deletions

View File

@ -22,13 +22,13 @@
## Build
- [ ] Build from the exact committed candidate with the production checkout’s
single `.env`.
- [ ] Run `scripts/android-release-build.sh`.
- [ ] Verify source fingerprint, signing certificate, bundletool validation,
- [x] Build from the exact committed candidate with the validated Android
allow-list read from the production checkout’s single `.env`.
- [x] Run `scripts/android-release-build.sh`.
- [x] Verify source fingerprint, signing certificate, bundletool validation,
lint, package name, version code/name, target SDK, and production origin.
- [ ] Install the universal APK generated from the same AAB on a clean physical
phone and run the release smoke test.
- [x] Install the universal APK generated from the same AAB on the authorized
physical phone and run the release smoke test.
- [ ] Upload the source-bound AAB first to internal testing.
## Store presence

View File

@ -3,6 +3,51 @@
Observed through 2026-07-28 in the local workspace. This report separates observed
results from product limits and unknown production properties.
## Production Android bundle replay on 2026-07-28
The release tooling and application inputs below are exact local commit
`c8e95b8c77babb10a9e7578a36ba35fe6f38ff9f`. No push, hackathon-test
deployment, production deployment, Devpost edit, Play application, branch, or
tag was created or changed.
- `./scripts/quality.sh` passed the complete isolated quality/security gate,
including ShellCheck, Hadolint, actionlint, release/rollback/migration
drills, Compose/Helm validation, source and runtime-image scans, formatting,
warnings-as-errors compilation, xref, Credo, Sobelow, Dialyzer, Hex/npm
audits, and all 394 ExUnit tests. The configured scans reported zero
findings.
- The release build read only the explicit Android/OAuth/App-Links allow-list
from the production checkout's mode-`0600` `.env`. Database, SMTP, session,
and FCM service-account secrets were not copied. The temporary allow-list
file was absent after the build.
- The pipeline passed release unit tests, Android lint, R8/resource shrinking,
APK/AAB signing checks, Bundletool validation, package/origin/App-Links
validation, and generated a signed universal APK from the same AAB. The
source fingerprint in the artifact directory exactly matched the committed
tree.
- The candidate is retained at
`android/dist-release-c8e95b8-20260728T013253Z`. The Play AAB SHA-256 is
`812cf843e0f0df9cec22ac8a7e56a92ad6b07200c35548f62ea1184e8c6c419d`;
the universal APK-set SHA-256 is
`1a5794cf540a55856b465d8e20509b9835ac6604872dbaa829e3ac0689430cb7`;
and the extracted universal APK SHA-256 is
`ddd43d81b271f9dd18755f1e3fd3e62459f88206f3da293f525f43e4320b8b51`.
- The universal APK installed successfully on the authorized physical phone.
A verified `https://whoneedhelp.com/safety` App Link cold-started
`org.whoneedhelp.mobile/.MainActivity` in 571 ms. The installed package
reported version code `1`, version name `0.1.0`, minimum SDK 24, target SDK
37, and a verified `whoneedhelp.com` domain. PID-scoped logs contained no
fatal exception, AndroidRuntime, TLS, certificate, or WebView load error.
The rendered phone capture is retained at
`output/android-production-smoke/20260728-c8e95b8/safety-universal.png`.
- Read-only counts after this unauthenticated public smoke remained 14
production users and zero production push devices. The smoke did not create
an account or push-device record.
- Google Play identity review remains an external gate. The Play application
and Play App Signing certificate do not exist yet, so internal-track upload,
Play-generated signing identity, Data Safety/App Content forms, and the
required closed test cannot truthfully be marked complete.
## Physical Android and Play preflight on 2026-07-28
The application source below is exact local commit