diff --git a/android/play-store/closed-test.md b/android/play-store/closed-test.md index 43f2553..149c508 100644 --- a/android/play-store/closed-test.md +++ b/android/play-store/closed-test.md @@ -17,14 +17,16 @@ eligibility and the date on which production access can be requested. identities shown for quantum-ready hybrid signing when present. Add every applicable Play App Signing SHA-256 to production App Links and Google/Firebase configuration, then verify the production association files. -5. Upload the source-bound production AAB. The current prepared candidate is - `0.1.2 (3)` with SHA-256 +5. Use the source-bound production AAB already released only to Internal + testing. The current Internal release is `0.1.2 (3)` with SHA-256 `5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`; its exact operator record is `internal-release-v3.md`. 6. Complete the store listing, App content, privacy, Data Safety, content rating, ads, target-audience, and access declarations. -7. Start with an internal test on the owner’s device, then promote the verified - build to the closed track. +7. Finish the internal test on the owner’s device, complete the foreground- + service declaration, then promote the verified build to the closed track. + As of 2026-08-10 the Internal release is active, but Closed testing has not + been started. After installing from the internal-track opt-in link, verify the delivery boundary before testing authenticated flows: diff --git a/android/play-store/internal-release-v3.md b/android/play-store/internal-release-v3.md index 2c46e06..05a10cb 100644 --- a/android/play-store/internal-release-v3.md +++ b/android/play-store/internal-release-v3.md @@ -1,8 +1,9 @@ # Internal testing release v3 -This is the operator copy for the next Google Play Internal testing candidate. -The artifact has been built and verified locally, but it has not been uploaded, -saved, published, or delivered by Google Play yet. +This is the operator record for the current Google Play Internal testing +release. The source-bound artifact was uploaded, released only to Internal +testing, delivered by Google Play, and verified on the authorised physical +phone on 2026-08-10. ## Release identity @@ -55,28 +56,40 @@ sharing stopped without presenting a misleading technical error. Detailed evidence is recorded in `docs/google-play-release-candidate-2026-08-09-v3.md`. -## Before publishing +## Publication evidence -Verify in Play Console that: +Play Console was re-read on 2026-08-10 and showed: -1. the application is Who Need Help with package `org.whoneedhelp.mobile`; -2. the selected track is Internal testing, not Closed or Production; -3. the accepted artifact has version code `3` and version name `0.1.2`; -4. the AAB hash matches this record before upload; -5. the release notes contain no credential, private email, test URL, precise - location or medical detail; -6. no Production or Closed rollout is selected. +1. track **Internal testing** is active; +2. latest release is `0.1.2 Location consent clarity`; +3. the release is available to internal testers with one version code; +4. the release timestamp is 2026-08-10 11:02 AM in the Console UI; +5. the app is still unreviewed, so Internal testers see the temporary package + name until the application setup is reviewed; +6. no Closed or Production rollout was started by this release. -Uploading, saving or publishing is an external state change. Do not press the -final control without explicit permission for this exact candidate and track. +The App content overview was re-read on 2026-08-10 and showed exactly one item +under **Need attention**: the Foreground service permissions declaration. Its +Location form had no saved task selection and the Save control was disabled. +No incomplete declaration was saved or submitted during this inspection. -## Immediately after publication +The authorised physical phone then passed the strict installed-build verifier: +Google Play installer, Play App Signing identity, exact `0.1.2 (3)` version, +verified production App Link, and `MainActivity` resolution. -1. Install version `0.1.2 (3)` from Google Play on the authorised physical - phone; do not side-load the upload-signed APK as Play-delivered evidence. -2. Run `scripts/verify-play-installed-android.sh` and confirm the Play installer, - Play signing identity, verified App Link and expected version. -3. Re-run Google sign-in, FCM tap routing, supported and excluded App Links, - disclosure cancellation, active foreground location sharing, minimized-app - sampling and notification Stop cleanup. -4. Record Play-delivered evidence before replacing the Internal track candidate. +## Post-publication foreground-location evidence + +An exact run-scoped production fixture was used only for the location replay. +The Play-delivered app showed the prominent disclosure, Android permission +prompt, active in-app state, and persistent notification while minimized. The +notification Stop action ended the session; server verification observed 41 +samples and zero retained raw positions. Exact fixture cleanup deleted the +request, assignment, session, and synthetic requester, then both production +and frozen-test readiness endpoints returned `ready`. + +The long evidence take is not the submission video: Android's recorder reached +its time limit before the Stop action was captured even though Stop and server +cleanup were verified immediately afterward. Record a concise, complete take +from this same Play-delivered version before entering a video URL in Play +Console. Do not replace the Internal candidate until that recording and the +foreground-service declaration are complete. diff --git a/android/play-store/location-and-fgs-declaration.md b/android/play-store/location-and-fgs-declaration.md index df943fb..2ff6a83 100644 --- a/android/play-store/location-and-fgs-declaration.md +++ b/android/play-store/location-and-fgs-declaration.md @@ -179,6 +179,33 @@ Foreground-service references rechecked on 2026-08-09: - https://support.google.com/googleplay/android-developer/answer/13392821 - https://developer.android.com/develop/background-work/services/fgs/service-types +The Play Help page was rechecked again on 2026-08-10. It still requires a video +link for each declared foreground-service feature and recommends keeping the +demonstration at 30 seconds or less. The final edit must therefore retain the +user trigger, prominent disclosure, runtime prompt, minimized persistent +notification, and notification Stop action while removing only idle time. + +### Play-delivered evidence take on 2026-08-10 + +The exact Play-delivered `0.1.2 (3)` build produced a long evidence take at: + +`/g/home/Downloads/Who-Need-Help-Play-Console-location-sharing-FINAL-v4.mp4` + +Its SHA-256 is +`56608ca3e2e1aafd7a85c325109581c379d4cb714794ba4c6c414706d451ff96`. +The file is 177.864689 seconds, H.264, and 720×1600. Visual review confirms the +in-app trigger, prominent disclosure, Android runtime prompt, active in-app +state, Home/minimized operation, and persistent notification with the visible +Stop action. It contains no account email, fixture credentials, precise map, +medical information, chat, or handover code. + +This take is retained only as source evidence. The recorder reached its time +limit before the notification Stop tap and stopped in-app state were captured, +so it must not be submitted to Play Console as the final demonstration. The +Stop action was performed immediately afterward: server verification observed +41 samples and zero retained raw positions, and exact fixture cleanup passed. +A new concise take must visibly include Stop and the stopped state. + The remaining Play policy references were last checked on 2026-08-03; refresh them again immediately before submitting the declaration because the Help Center pages can change independently of the Android platform documentation: diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index 4b23cdb..c16a212 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -53,9 +53,16 @@ - [x] Build and locally validate source-bound candidate `0.1.2 (3)` from commit `cd15476`; release tests, lint, signing, bundle validation, App Links validation and API 37 instrumentation passed. The candidate is - documented in `internal-release-v3.md` and has not been uploaded. -- [ ] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it + documented in `internal-release-v3.md`; its subsequent Internal-track + upload and Play-delivered verification are recorded in the next item. +- [x] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it through Google Play and repeat the strict physical-device verification. + Play Console showed release `0.1.2 Location consent clarity` available to + internal testers on 2026-08-10 with one version code and no Closed or + Production rollout. The installed package was delivered by + `com.android.vending`; its Play signing identity, version, verified + production App Link, and `MainActivity` resolution passed the strict + verifier. ## Production capability gate @@ -103,6 +110,9 @@ service. - [ ] Complete the mandatory Play Console foreground-service declaration for the `location` service used by the exact AAB. + Read-only inspection on 2026-08-10 showed this as the only App content + item under `Need attention`. The Location declaration currently has no + saved task selection; no incomplete form was saved or submitted. - [ ] Upload the unlisted demonstration video showing the user-triggered start, prominent disclosure, Android permission, persistent notification, minimized-app operation, and Stop action. @@ -122,15 +132,21 @@ identity document, physical-device serial, and exact expected version. It must confirm the Google Play installer, Play signing identity, verified production App Link, and `MainActivity` resolution. - The 2026-08-09 physical-device replay passed that verifier, Google + The 2026-08-09 v2 physical-device replay passed that verifier, Google sign-in, production App Link routing, Android notification permission, production FCM receipt and notification-tap routing. The same Play-delivered build then passed the separate consent-driven foreground location flow: explicit disclosure, Android permission, persistent notification, minimized-app sampling, notification Stop cleanup, offline/reconnect, and stopped-process recreation without sticky - tracking. This verifies observed app behavior; it does not complete the - separate Play Console policy declarations above. + tracking. On 2026-08-10 the Play-delivered v3 install passed the strict + delivery-boundary verifier and a new production fixture replay observed + the disclosure, Android runtime prompt, active in-app state, minimized + foreground-service notification, 41 server samples, notification Stop, + and zero retained raw positions after Stop. The run-scoped fixture was + then deleted and both production and frozen-test readiness remained + healthy. This verifies observed app behavior; it does not complete the + separate Play Console policy declarations or the final video above. - [ ] Closed track created and opt-in link tested. - [ ] At least 12 testers continuously opted in for 14 days. - [ ] Tester feedback and fixes documented. diff --git a/docs/google-play-release-candidate-2026-08-09-v3.md b/docs/google-play-release-candidate-2026-08-09-v3.md index 178c252..14cad8c 100644 --- a/docs/google-play-release-candidate-2026-08-09-v3.md +++ b/docs/google-play-release-candidate-2026-08-09-v3.md @@ -1,8 +1,8 @@ # Google Play Internal candidate v3 — 2026-08-09 -This record binds the locally prepared third Internal testing candidate to the -exact committed source and observed verification evidence. It does not claim -that Google Play has accepted or delivered this build. +This record binds the third Internal testing release to the exact committed +source and observed verification evidence. Google Play accepted, released, and +delivered this exact artifact on the Internal testing track on 2026-08-10. ## Source and artifacts @@ -68,23 +68,25 @@ The current source passed API 37 instrumentation in the isolated unit ## What changed from Play-delivered v2 -The currently installed Google Play build is still `0.1.1 (2)`. Candidate v3 -changes the live-location cancellation contract: dismissing the prominent +Candidate v3 changes the live-location cancellation contract: dismissing the prominent native disclosure or denying the permission emits an explicit cancellation event instead of a generic technical-error event. The web UI can therefore remain in the stopped state without falsely telling the user that location sharing failed. -## Remaining gates +## Play delivery and remaining gates -Before this candidate can replace v2 on Internal testing: +On 2026-08-10 Play Console showed `0.1.2 Location consent clarity` available to +Internal testers with one version code. The physical phone's installed package +passed the strict Play installer, signing, exact-version, App Link, and activity +resolution verifier. A production-fixture replay also verified user-initiated +foreground location, minimized notification operation, notification Stop, 41 +samples, zero retained raw positions after Stop, and exact fixture cleanup. -1. obtain explicit permission for the exact AAB and Internal track; -2. upload and publish version code `3` only to Internal testing; -3. install it through Google Play on the physical test phone; -4. run the strict installed-build verifier and the full physical workflow; -5. create the final foreground-location declaration video from the +The remaining gates are: + +1. create a concise final foreground-location declaration video from the Play-delivered candidate; -6. complete and verify the Play Console foreground-service/location form; -7. keep Closed and Production tracks untouched until their separate gates are +2. complete and verify the Play Console foreground-service/location form; +3. keep Closed and Production tracks untouched until their separate gates are complete. diff --git a/docs/verification.md b/docs/verification.md index 7dacdc9..adce074 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -1,6 +1,6 @@ # Who Need Help — implementation verification -Observed through 2026-08-09 in the local workspace. This report separates observed +Observed through 2026-08-10 in the local workspace. This report separates observed results from product limits and unknown production properties. ## External-monitor SMTP isolation proof on 2026-08-09 @@ -2692,3 +2692,37 @@ promoted. - Exact hashes, screenshots, cleanup scope and remaining Google Play gates are recorded in `docs/google-play-release-candidate-2026-08-09-v2.md` and `android/play-store/internal-release-v2.md`. + +# 2026-08-10 authorised pilot release and Google Play internal v3 verification + +- The production application was updated app-only to local revision + `7c2b55917dcaed52f9788cbbfcc6f2ff0a3354f6`. The shared Caddy edge, frozen + hackathon-test checkout, and public Git remote were not changed. Production + readiness returned `ready` after the release. +- A temporary production E2E run exercised the authorised application release + and completed exact run-scoped cleanup. The temporary test identities and + records were verified absent afterward; production readiness remained + `ready`, and the frozen-test readiness endpoint also remained `ready`. +- Production and frozen-test SMTP credentials were separated and verified + without printing their values. The replaced credentials were deactivated. +- Off-site backup creation, restore validation, and the external monitor were + rechecked and healthy after the application release. +- Google Play released the exact `0.1.2 (3)` AAB only to Internal testing. Its + SHA-256 is + `5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`. + Play Console showed the release available to internal testers with one + version code and no Closed or Production rollout. +- The physical phone installed the artifact through Google Play. The strict + verifier observed installer `com.android.vending`, a recorded Play App + Signing identity, exact version `0.1.2 (3)`, verified production App Link, + and `MainActivity` resolution. +- A run-scoped foreground-location replay showed the prominent disclosure, + Android permission prompt, active in-app state, and persistent notification + while minimized. Notification Stop ended sharing; server verification + observed 41 samples and zero retained raw positions. The request, + assignment, tracking session, and synthetic requester were then deleted. +- The retained 177.864689-second source take is not the final Play declaration + video because Android screen recording stopped before the Stop tap and + stopped state were captured. A concise complete take of 30 seconds or less, + the Play foreground-service declaration, and Closed testing remain open + gates. No Production Play rollout has been started.