Record current Google Play internal release

This commit is contained in:
SimpleTest 2026-08-25 19:00:10 +03:00
parent 7094f21394
commit 9cdd31c72e
6 changed files with 169 additions and 47 deletions

View File

@ -5,7 +5,7 @@ least 12 testers to remain opted in to the closed test for 14 continuous days
before production access can be requested. before production access can be requested.
This requirement was rechecked against the official Play Console Help article This requirement was rechecked against the official Play Console Help article
on 2026-08-09. The Console remains the source of truth for the account's actual on 2026-08-25. The Console remains the source of truth for the account's actual
eligibility and the date on which production access can be requested. eligibility and the date on which production access can be requested.
## Before inviting testers ## Before inviting testers
@ -17,20 +17,19 @@ eligibility and the date on which production access can be requested.
identities shown for quantum-ready hybrid signing when present. Add every identities shown for quantum-ready hybrid signing when present. Add every
applicable Play App Signing SHA-256 to production App Links and applicable Play App Signing SHA-256 to production App Links and
Google/Firebase configuration, then verify the production association files. Google/Firebase configuration, then verify the production association files.
5. Use the source-bound production AAB already released only to Internal 5. Use the recorded production AAB already released only to Internal testing.
testing. The current Internal release is `0.1.2 (3)` with SHA-256 The current Internal release is `0.1.3 (4)` with SHA-256
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`; `5147404e91aee6ef87014e19db93403fdb18a15e91b749737c494c372ea87371`;
its exact operator record is `internal-release-v3.md`. its exact operator record is `internal-release-v4.md`.
6. Complete the store listing, App content, privacy, Data Safety, content rating, 6. Complete the store listing, App content, privacy, Data Safety, content rating,
ads, target-audience, and access declarations. Read-only Play Console ads, target-audience, and access declarations. Read-only Store settings
inspection on 2026-08-10 showed app setup at 9 of 11 tasks: the two inspection on 2026-08-25 showed category **Social** and public contact email
incomplete tasks were **Select an app category and provide contact details** `contact@whoneedhelp.com`; phone and website were empty.
and **Set up your store listing**.
7. Finish the internal test on the owner’s device, complete the foreground- 7. Finish the internal test on the owner’s device, complete the foreground-
service declaration, then promote the verified build to the closed track. service declaration, then promote the verified build to the closed track.
As of 2026-08-10 the Internal release is active, but Closed testing has not As of 2026-08-25 the Internal release is active. The existing **Closed
been started. The Dashboard showed Closed testing locked until app setup is testing - Alpha** track is inactive with zero of four setup tasks complete:
finished and `0 testers currently opted-in`. countries and testers are not selected, and the track has no release.
After installing from the internal-track opt-in link, verify the delivery After installing from the internal-track opt-in link, verify the delivery
boundary before testing authenticated flows: boundary before testing authenticated flows:
@ -39,8 +38,8 @@ boundary before testing authenticated flows:
./scripts/verify-play-installed-android.sh \ ./scripts/verify-play-installed-android.sh \
/secure/downloads/play-identities.json \ /secure/downloads/play-identities.json \
DEVICE_SERIAL \ DEVICE_SERIAL \
3 \ 4 \
0.1.2 0.1.3
``` ```
The verifier is read-only. It requires the Google Play installer, one of the The verifier is read-only. It requires the Google Play installer, one of the

View File

@ -0,0 +1,67 @@
# Internal testing release v4
This operator record identifies the Android build currently available through
Google Play Internal testing. It records observed artifact, Console, and
physical-device evidence without authorizing a Closed or Production rollout.
## Release identity
- Track: Internal testing only
- Release label: `0.1.3 Reliable notifications`
- Package: `org.whoneedhelp.mobile`
- Version code: `4`
- Version name: `0.1.3`
- Source fingerprint:
`42b485964a8c3fdaeff94ca80dcd8f33533e1723c6c2d625a9483458c0ff0068`
- AAB: `android/dist-release-20260821-v4-precommit/who-need-help-release.aab`
- AAB SHA-256:
`5147404e91aee6ef87014e19db93403fdb18a15e91b749737c494c372ea87371`
- Companion APK SHA-256:
`58136ea5ddead7ee683f28f3ae12aa65334207c40ebfe2fdb34064b8d2710c3d`
- Upload-certificate SHA-256:
`a5742bae70c6d034e37544b62e37a375c0e005647450f40f29b2a984f9fdb8fb`
The artifact directory name is accurate: the build was produced before its
matching Android source state was committed. Historical checkout comparison
found `f15f5578e010df80a430f2dbfa4aca54face65f3` to be the first committed
revision whose Android build-input fingerprint exactly matches the retained
artifact. This is reproducibility evidence; it is not a claim that the
artifact was originally built by checking out that commit.
Do not upload a different artifact under this release record. Any Android
source or build-input change requires a new version code, a fresh source-bound
build, and a new operator record.
## Publication evidence
A read-only authenticated Play Console inspection on 2026-08-25 showed:
1. **Internal testing** is active;
2. the latest release is `0.1.3 Reliable notifications` with one version code;
3. the release is available to internal testers;
4. the Console displayed a release time of 2026-08-25 3:46 PM;
5. the app remains unreviewed, so Internal testers see the temporary package
name;
6. the existing **Closed testing - Alpha** track is inactive, has zero of four
setup tasks complete, has no countries or testers selected, and contains no
release;
7. no Production rollout was observed or started during the inspection.
## Play-delivered physical-device evidence
The authorised physical phone passed the strict delivery-boundary verifier:
```bash
./scripts/verify-play-installed-android.sh \
output/runtime/production-provider-setup/play-identities.json \
72551e60 \
4 \
0.1.3
```
The verifier observed package `org.whoneedhelp.mobile`, version `0.1.3 (4)`,
Google Play as installer, a signing identity in the protected Play App Signing
set, and a verified `whoneedhelp.com` App Link resolving to `MainActivity`. The
browser-only Google OAuth callback was not claimed by the Android application.
The verification was read-only and did not install, update, clear, or
reconfigure the app.

View File

@ -63,6 +63,12 @@
`com.android.vending`; its Play signing identity, version, verified `com.android.vending`; its Play signing identity, version, verified
production App Link, and `MainActivity` resolution passed the strict production App Link, and `MainActivity` resolution passed the strict
verifier. verifier.
- [x] Record and verify Internal release `0.1.3 (4)`. Play Console showed
`0.1.3 Reliable notifications` available to internal testers on
2026-08-25. The retained AAB SHA-256, Android source fingerprint,
provenance limitation, and strict Play-delivered phone verification are
recorded in `internal-release-v4.md`. No Closed or Production release was
created by this verification.
## Production capability gate ## Production capability gate
@ -98,14 +104,13 @@ block publishing changes, including Store Listing, Pricing, and Distribution.
listing task is complete. listing task is complete.
- [x] Choose category in the current Console options. **Social** was saved; - [x] Choose category in the current Console options. **Social** was saved;
tags were deliberately left empty rather than adding an inaccurate tag. tags were deliberately left empty rather than adding an inaccurate tag.
- [ ] Complete **Select an app category and provide contact details** in Play - [x] Complete **Select an app category and provide contact details** in Play
Console. Read-only Dashboard inspection on 2026-08-10 showed this task Console. Read-only Store settings inspection on 2026-08-25 showed
incomplete; no values were selected or saved during that inspection. category **Social** and public contact email `contact@whoneedhelp.com`;
`contact@whoneedhelp.com` must not be entered yet: a same-day public DNS phone and website were empty. A controlled inbound routing message sent
check found no MX record and no observed SMTP greeting on the web-server to that address was observed once in the operator Gmail Inbox with the
address, so inbound delivery has not been demonstrated. Configure and `Projects/WhoNeedHelp` label. This proves the tested inbound forwarding
test that mailbox/forwarder, or deliberately choose another monitored route; it does not prove a standalone mailbox or reply-from identity.
public support address, before saving the field.
- [x] Complete **Set up your store listing** in Play Console using the prepared - [x] Complete **Set up your store listing** in Play Console using the prepared
copy and assets. A read-only Dashboard inspection on 2026-08-14 showed copy and assets. A read-only Dashboard inspection on 2026-08-14 showed
overall app setup at 10 of 11 tasks and marked this task complete. overall app setup at 10 of 11 tasks and marked this task complete.
@ -195,16 +200,22 @@ block publishing changes, including Store Listing, Pricing, and Distribution.
was reconnected: Google Play installer, version `0.1.2 (3)`, Play signing was reconnected: Google Play installer, version `0.1.2 (3)`, Play signing
identity, verified production App Link, and `MainActivity` resolution all identity, verified production App Link, and `MainActivity` resolution all
matched the protected production identity record. matched the protected production identity record.
On 2026-08-25 the strict verifier also passed for the current
Play-delivered `0.1.3 (4)` install: Google Play installer, a protected
Play signing identity, verified production App Link, and `MainActivity`
resolution all matched. The exact artifact record is
`internal-release-v4.md`.
- [ ] Closed track created and opt-in link tested. - [ ] Closed track created and opt-in link tested.
- [ ] At least 12 testers continuously opted in for 14 days. - [ ] At least 12 testers continuously opted in for 14 days.
- [ ] Tester feedback and fixes documented. - [ ] Tester feedback and fixes documented.
- [ ] Production-access questionnaire completed from actual evidence. - [ ] Production-access questionnaire completed from actual evidence.
On 2026-08-20 Play Console still showed Closed testing locked until the one On 2026-08-25 the existing **Closed testing - Alpha** track was inactive with
remaining app-setup task, public contact details, is complete and reported `0 zero of four setup tasks complete. Countries and testers were not selected, and
testers currently opted-in`. The Console still required at least 12 opted-in the track had no release. The current official requirement for this personal
testers for at least 14 days. No Closed or Production release was created developer account was rechecked as at least 12 testers continuously opted in
during this inspection. for at least 14 days before applying for Production access. No Closed or
Production release was created during this inspection.
## Publishing ## Publishing

View File

@ -36,10 +36,11 @@ access field:
password manager. password manager.
- Stable synthetic request URL: create at release time. - Stable synthetic request URL: create at release time.
- Stable synthetic activity URL: create at release time. - Stable synthetic activity URL: create at release time.
- Public support contact: choose at submission time only after the address has - Public support contact: `contact@whoneedhelp.com`. On 2026-08-25 a controlled
passed a real inbound-delivery test. `contact@whoneedhelp.com` is currently message addressed to it was observed once in the operator Gmail Inbox with
verified only as an outbound Brevo sender; DNS inspection found no MX record the `Projects/WhoNeedHelp` label. This verifies the tested inbound forwarding
proving that replies or new inbound messages reach an operator. route, not a standalone mailbox or the ability to send replies from that
identity.
## Copy for Play Console App access ## Copy for Play Console App access
@ -72,7 +73,7 @@ payment, medicine, travel or real-world meeting is required. The credentials
are reusable, do not require a one-time code or developer mailbox, and work are reusable, do not require a one-time code or developer mailbox, and work
independently of reviewer location. independently of reviewer location.
Support: [ENTER A TESTED, MONITORED INBOUND ADDRESS IN PLAY CONSOLE ONLY] Support: contact@whoneedhelp.com
``` ```
After `scripts/prepare-play-review.sh ... --confirm` succeeds, append the exact After `scripts/prepare-play-review.sh ... --confirm` succeeds, append the exact

View File

@ -51,6 +51,23 @@ deployment, frozen test deployment, or public Git remote was changed.
This recheck was read-only. No Console field, release, track, deployment, This recheck was read-only. No Console field, release, track, deployment,
frozen test environment, or public Git remote was changed. frozen test environment, or public Git remote was changed.
## Read-only recheck on 2026-08-25
- Store settings showed app category **Social** and public contact email
`contact@whoneedhelp.com`; phone and website were empty.
- Internal testing was active with release `0.1.3 Reliable notifications`, one
version code, and status available to internal testers.
- The existing **Closed testing - Alpha** track was inactive with zero of four
setup tasks complete. Countries and testers were not selected, and the track
contained no release.
- A controlled message addressed to `contact@whoneedhelp.com` was observed once
in the operator Gmail Inbox with the `Projects/WhoNeedHelp` label. The
message was not opened or marked read. This verifies the tested inbound
forwarding route, not a standalone mailbox or reply-from identity.
This recheck was read-only. No Console field, release, track, deployment,
frozen test environment, or public Git remote was changed.
These are direct observations from the authenticated Play Console session on These are direct observations from the authenticated Play Console session on
that date. Recheck the Console before applying because its fields and policy that date. Recheck the Console before applying because its fields and policy
requirements can change. requirements can change.
@ -76,25 +93,17 @@ location.
## Contact fields ## Contact fields
- Public support email candidate: `contact@whoneedhelp.com` - Public support email saved in Play Store settings: `contact@whoneedhelp.com`
- Website: `https://whoneedhelp.com/` - Website: `https://whoneedhelp.com/`
- Public phone: leave empty unless the operator deliberately chooses a number - Public phone: leave empty unless the operator deliberately chooses a number
that can be published and monitored. that can be published and monitored.
Do not save the email merely because it is used as an outbound sender. First Production sends through Brevo as `contact@whoneedhelp.com`. A controlled
send a real inbound message to it, observe arrival in the monitored mailbox, inbound routing message sent to that address was observed once in the monitored
and verify that replies are handled. Google recommends keeping the public app operator Gmail Inbox on 2026-08-25. This proves the tested forwarding path. It
support address distinct from the developer-account sign-in address. does not prove a standalone mailbox, reply handling, or the ability to send
from that address through Gmail. Recheck inbound routing and operator access
A repeated read-only public DNS check on 2026-08-13 returned no MX record for before a public release, and separately test the chosen reply workflow.
either `whoneedhelp.com` or `contact.whoneedhelp.com`. Production is configured
to send through Brevo as `contact@whoneedhelp.com`, while internal support
alerts route to the operator's monitored mailbox. These are outbound and
internal-routing facts; neither proves inbound delivery to the public address.
The address remains a candidate, not a verified support inbox. Before Console
entry, either configure and test a monitored inbound mailbox/forwarder for that
address or deliberately use a different already monitored public support
address.
## Category and child-safety gate ## Category and child-safety gate

View File

@ -3460,3 +3460,38 @@ promoted.
- This was local verification only. Production, the frozen hackathon test - This was local verification only. Production, the frozen hackathon test
deployment, shared Caddy, and the public Git remote were not changed or deployment, shared Caddy, and the public Git remote were not changed or
pushed. pushed.
# 2026-08-25 Google Play Internal v4 and contact recheck
- Read-only authenticated Play Console inspection showed **Internal testing**
active with release `0.1.3 Reliable notifications`, one version code, and
status available to internal testers. The Console displayed a release time
of 2026-08-25 3:46 PM and still identified the app as unreviewed.
- The existing **Closed testing - Alpha** track was inactive with zero of four
setup tasks complete. Countries and testers were not selected, and the track
contained no release. No Closed or Production rollout was started.
- Store settings showed category **Social** and public contact email
`contact@whoneedhelp.com`; phone and website were empty.
- A Gmail search in the existing authenticated operator session showed exactly
one unread controlled routing message addressed through
`contact@whoneedhelp.com`. It was in Inbox with the
`Projects/WhoNeedHelp` label. The message was not opened or marked read. This
verifies the observed inbound forwarding path, not a standalone mailbox or
reply-from identity.
- The retained v4 AAB has SHA-256
`5147404e91aee6ef87014e19db93403fdb18a15e91b749737c494c372ea87371`
and Android source fingerprint
`42b485964a8c3fdaeff94ca80dcd8f33533e1723c6c2d625a9483458c0ff0068`.
Historical checkout comparison found
`f15f5578e010df80a430f2dbfa4aca54face65f3` to be the first committed
revision whose Android build-input fingerprint matches the precommit
artifact. This is reproducibility evidence and does not claim that the
artifact was originally built from that checkout.
- The connected physical phone passed the strict Play delivery verifier for
package `org.whoneedhelp.mobile` at `0.1.3 (4)`: Google Play installer, a
signing identity from the protected Play set, verified production App Link,
and `MainActivity` resolution all matched. The browser-only Google OAuth
callback was not claimed by the Android app.
- These checks were read-only. They did not install or update the phone app,
change Play Console, deploy production, modify the frozen hackathon test,
change shared Caddy, or push the public Git remote.