Document Play internal v3 verification
This commit is contained in:
parent
7c2b55917d
commit
abbcf24984
|
|
@ -17,14 +17,16 @@ eligibility and the date on which production access can be requested.
|
||||||
identities shown for quantum-ready hybrid signing when present. Add every
|
identities shown for quantum-ready hybrid signing when present. Add every
|
||||||
applicable Play App Signing SHA-256 to production App Links and
|
applicable Play App Signing SHA-256 to production App Links and
|
||||||
Google/Firebase configuration, then verify the production association files.
|
Google/Firebase configuration, then verify the production association files.
|
||||||
5. Upload the source-bound production AAB. The current prepared candidate is
|
5. Use the source-bound production AAB already released only to Internal
|
||||||
`0.1.2 (3)` with SHA-256
|
testing. The current Internal release is `0.1.2 (3)` with SHA-256
|
||||||
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`;
|
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`;
|
||||||
its exact operator record is `internal-release-v3.md`.
|
its exact operator record is `internal-release-v3.md`.
|
||||||
6. Complete the store listing, App content, privacy, Data Safety, content rating,
|
6. Complete the store listing, App content, privacy, Data Safety, content rating,
|
||||||
ads, target-audience, and access declarations.
|
ads, target-audience, and access declarations.
|
||||||
7. Start with an internal test on the owner’s device, then promote the verified
|
7. Finish the internal test on the owner’s device, complete the foreground-
|
||||||
build to the closed track.
|
service declaration, then promote the verified build to the closed track.
|
||||||
|
As of 2026-08-10 the Internal release is active, but Closed testing has not
|
||||||
|
been started.
|
||||||
|
|
||||||
After installing from the internal-track opt-in link, verify the delivery
|
After installing from the internal-track opt-in link, verify the delivery
|
||||||
boundary before testing authenticated flows:
|
boundary before testing authenticated flows:
|
||||||
|
|
|
||||||
|
|
@ -1,8 +1,9 @@
|
||||||
# Internal testing release v3
|
# Internal testing release v3
|
||||||
|
|
||||||
This is the operator copy for the next Google Play Internal testing candidate.
|
This is the operator record for the current Google Play Internal testing
|
||||||
The artifact has been built and verified locally, but it has not been uploaded,
|
release. The source-bound artifact was uploaded, released only to Internal
|
||||||
saved, published, or delivered by Google Play yet.
|
testing, delivered by Google Play, and verified on the authorised physical
|
||||||
|
phone on 2026-08-10.
|
||||||
|
|
||||||
## Release identity
|
## Release identity
|
||||||
|
|
||||||
|
|
@ -55,28 +56,40 @@ sharing stopped without presenting a misleading technical error.
|
||||||
Detailed evidence is recorded in
|
Detailed evidence is recorded in
|
||||||
`docs/google-play-release-candidate-2026-08-09-v3.md`.
|
`docs/google-play-release-candidate-2026-08-09-v3.md`.
|
||||||
|
|
||||||
## Before publishing
|
## Publication evidence
|
||||||
|
|
||||||
Verify in Play Console that:
|
Play Console was re-read on 2026-08-10 and showed:
|
||||||
|
|
||||||
1. the application is Who Need Help with package `org.whoneedhelp.mobile`;
|
1. track **Internal testing** is active;
|
||||||
2. the selected track is Internal testing, not Closed or Production;
|
2. latest release is `0.1.2 Location consent clarity`;
|
||||||
3. the accepted artifact has version code `3` and version name `0.1.2`;
|
3. the release is available to internal testers with one version code;
|
||||||
4. the AAB hash matches this record before upload;
|
4. the release timestamp is 2026-08-10 11:02 AM in the Console UI;
|
||||||
5. the release notes contain no credential, private email, test URL, precise
|
5. the app is still unreviewed, so Internal testers see the temporary package
|
||||||
location or medical detail;
|
name until the application setup is reviewed;
|
||||||
6. no Production or Closed rollout is selected.
|
6. no Closed or Production rollout was started by this release.
|
||||||
|
|
||||||
Uploading, saving or publishing is an external state change. Do not press the
|
The App content overview was re-read on 2026-08-10 and showed exactly one item
|
||||||
final control without explicit permission for this exact candidate and track.
|
under **Need attention**: the Foreground service permissions declaration. Its
|
||||||
|
Location form had no saved task selection and the Save control was disabled.
|
||||||
|
No incomplete declaration was saved or submitted during this inspection.
|
||||||
|
|
||||||
## Immediately after publication
|
The authorised physical phone then passed the strict installed-build verifier:
|
||||||
|
Google Play installer, Play App Signing identity, exact `0.1.2 (3)` version,
|
||||||
|
verified production App Link, and `MainActivity` resolution.
|
||||||
|
|
||||||
1. Install version `0.1.2 (3)` from Google Play on the authorised physical
|
## Post-publication foreground-location evidence
|
||||||
phone; do not side-load the upload-signed APK as Play-delivered evidence.
|
|
||||||
2. Run `scripts/verify-play-installed-android.sh` and confirm the Play installer,
|
An exact run-scoped production fixture was used only for the location replay.
|
||||||
Play signing identity, verified App Link and expected version.
|
The Play-delivered app showed the prominent disclosure, Android permission
|
||||||
3. Re-run Google sign-in, FCM tap routing, supported and excluded App Links,
|
prompt, active in-app state, and persistent notification while minimized. The
|
||||||
disclosure cancellation, active foreground location sharing, minimized-app
|
notification Stop action ended the session; server verification observed 41
|
||||||
sampling and notification Stop cleanup.
|
samples and zero retained raw positions. Exact fixture cleanup deleted the
|
||||||
4. Record Play-delivered evidence before replacing the Internal track candidate.
|
request, assignment, session, and synthetic requester, then both production
|
||||||
|
and frozen-test readiness endpoints returned `ready`.
|
||||||
|
|
||||||
|
The long evidence take is not the submission video: Android's recorder reached
|
||||||
|
its time limit before the Stop action was captured even though Stop and server
|
||||||
|
cleanup were verified immediately afterward. Record a concise, complete take
|
||||||
|
from this same Play-delivered version before entering a video URL in Play
|
||||||
|
Console. Do not replace the Internal candidate until that recording and the
|
||||||
|
foreground-service declaration are complete.
|
||||||
|
|
|
||||||
|
|
@ -179,6 +179,33 @@ Foreground-service references rechecked on 2026-08-09:
|
||||||
- https://support.google.com/googleplay/android-developer/answer/13392821
|
- https://support.google.com/googleplay/android-developer/answer/13392821
|
||||||
- https://developer.android.com/develop/background-work/services/fgs/service-types
|
- https://developer.android.com/develop/background-work/services/fgs/service-types
|
||||||
|
|
||||||
|
The Play Help page was rechecked again on 2026-08-10. It still requires a video
|
||||||
|
link for each declared foreground-service feature and recommends keeping the
|
||||||
|
demonstration at 30 seconds or less. The final edit must therefore retain the
|
||||||
|
user trigger, prominent disclosure, runtime prompt, minimized persistent
|
||||||
|
notification, and notification Stop action while removing only idle time.
|
||||||
|
|
||||||
|
### Play-delivered evidence take on 2026-08-10
|
||||||
|
|
||||||
|
The exact Play-delivered `0.1.2 (3)` build produced a long evidence take at:
|
||||||
|
|
||||||
|
`/g/home/Downloads/Who-Need-Help-Play-Console-location-sharing-FINAL-v4.mp4`
|
||||||
|
|
||||||
|
Its SHA-256 is
|
||||||
|
`56608ca3e2e1aafd7a85c325109581c379d4cb714794ba4c6c414706d451ff96`.
|
||||||
|
The file is 177.864689 seconds, H.264, and 720×1600. Visual review confirms the
|
||||||
|
in-app trigger, prominent disclosure, Android runtime prompt, active in-app
|
||||||
|
state, Home/minimized operation, and persistent notification with the visible
|
||||||
|
Stop action. It contains no account email, fixture credentials, precise map,
|
||||||
|
medical information, chat, or handover code.
|
||||||
|
|
||||||
|
This take is retained only as source evidence. The recorder reached its time
|
||||||
|
limit before the notification Stop tap and stopped in-app state were captured,
|
||||||
|
so it must not be submitted to Play Console as the final demonstration. The
|
||||||
|
Stop action was performed immediately afterward: server verification observed
|
||||||
|
41 samples and zero retained raw positions, and exact fixture cleanup passed.
|
||||||
|
A new concise take must visibly include Stop and the stopped state.
|
||||||
|
|
||||||
The remaining Play policy references were last checked on 2026-08-03; refresh
|
The remaining Play policy references were last checked on 2026-08-03; refresh
|
||||||
them again immediately before submitting the declaration because the Help
|
them again immediately before submitting the declaration because the Help
|
||||||
Center pages can change independently of the Android platform documentation:
|
Center pages can change independently of the Android platform documentation:
|
||||||
|
|
|
||||||
|
|
@ -53,9 +53,16 @@
|
||||||
- [x] Build and locally validate source-bound candidate `0.1.2 (3)` from
|
- [x] Build and locally validate source-bound candidate `0.1.2 (3)` from
|
||||||
commit `cd15476`; release tests, lint, signing, bundle validation, App
|
commit `cd15476`; release tests, lint, signing, bundle validation, App
|
||||||
Links validation and API 37 instrumentation passed. The candidate is
|
Links validation and API 37 instrumentation passed. The candidate is
|
||||||
documented in `internal-release-v3.md` and has not been uploaded.
|
documented in `internal-release-v3.md`; its subsequent Internal-track
|
||||||
- [ ] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it
|
upload and Play-delivered verification are recorded in the next item.
|
||||||
|
- [x] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it
|
||||||
through Google Play and repeat the strict physical-device verification.
|
through Google Play and repeat the strict physical-device verification.
|
||||||
|
Play Console showed release `0.1.2 Location consent clarity` available to
|
||||||
|
internal testers on 2026-08-10 with one version code and no Closed or
|
||||||
|
Production rollout. The installed package was delivered by
|
||||||
|
`com.android.vending`; its Play signing identity, version, verified
|
||||||
|
production App Link, and `MainActivity` resolution passed the strict
|
||||||
|
verifier.
|
||||||
|
|
||||||
## Production capability gate
|
## Production capability gate
|
||||||
|
|
||||||
|
|
@ -103,6 +110,9 @@
|
||||||
service.
|
service.
|
||||||
- [ ] Complete the mandatory Play Console foreground-service declaration for
|
- [ ] Complete the mandatory Play Console foreground-service declaration for
|
||||||
the `location` service used by the exact AAB.
|
the `location` service used by the exact AAB.
|
||||||
|
Read-only inspection on 2026-08-10 showed this as the only App content
|
||||||
|
item under `Need attention`. The Location declaration currently has no
|
||||||
|
saved task selection; no incomplete form was saved or submitted.
|
||||||
- [ ] Upload the unlisted demonstration video showing the user-triggered start,
|
- [ ] Upload the unlisted demonstration video showing the user-triggered start,
|
||||||
prominent disclosure, Android permission, persistent notification,
|
prominent disclosure, Android permission, persistent notification,
|
||||||
minimized-app operation, and Stop action.
|
minimized-app operation, and Stop action.
|
||||||
|
|
@ -122,15 +132,21 @@
|
||||||
identity document, physical-device serial, and exact expected version.
|
identity document, physical-device serial, and exact expected version.
|
||||||
It must confirm the Google Play installer, Play signing identity,
|
It must confirm the Google Play installer, Play signing identity,
|
||||||
verified production App Link, and `MainActivity` resolution.
|
verified production App Link, and `MainActivity` resolution.
|
||||||
The 2026-08-09 physical-device replay passed that verifier, Google
|
The 2026-08-09 v2 physical-device replay passed that verifier, Google
|
||||||
sign-in, production App Link routing, Android notification permission,
|
sign-in, production App Link routing, Android notification permission,
|
||||||
production FCM receipt and notification-tap routing. The same
|
production FCM receipt and notification-tap routing. The same
|
||||||
Play-delivered build then passed the separate consent-driven foreground
|
Play-delivered build then passed the separate consent-driven foreground
|
||||||
location flow: explicit disclosure, Android permission, persistent
|
location flow: explicit disclosure, Android permission, persistent
|
||||||
notification, minimized-app sampling, notification Stop cleanup,
|
notification, minimized-app sampling, notification Stop cleanup,
|
||||||
offline/reconnect, and stopped-process recreation without sticky
|
offline/reconnect, and stopped-process recreation without sticky
|
||||||
tracking. This verifies observed app behavior; it does not complete the
|
tracking. On 2026-08-10 the Play-delivered v3 install passed the strict
|
||||||
separate Play Console policy declarations above.
|
delivery-boundary verifier and a new production fixture replay observed
|
||||||
|
the disclosure, Android runtime prompt, active in-app state, minimized
|
||||||
|
foreground-service notification, 41 server samples, notification Stop,
|
||||||
|
and zero retained raw positions after Stop. The run-scoped fixture was
|
||||||
|
then deleted and both production and frozen-test readiness remained
|
||||||
|
healthy. This verifies observed app behavior; it does not complete the
|
||||||
|
separate Play Console policy declarations or the final video above.
|
||||||
- [ ] Closed track created and opt-in link tested.
|
- [ ] Closed track created and opt-in link tested.
|
||||||
- [ ] At least 12 testers continuously opted in for 14 days.
|
- [ ] At least 12 testers continuously opted in for 14 days.
|
||||||
- [ ] Tester feedback and fixes documented.
|
- [ ] Tester feedback and fixes documented.
|
||||||
|
|
|
||||||
|
|
@ -1,8 +1,8 @@
|
||||||
# Google Play Internal candidate v3 — 2026-08-09
|
# Google Play Internal candidate v3 — 2026-08-09
|
||||||
|
|
||||||
This record binds the locally prepared third Internal testing candidate to the
|
This record binds the third Internal testing release to the exact committed
|
||||||
exact committed source and observed verification evidence. It does not claim
|
source and observed verification evidence. Google Play accepted, released, and
|
||||||
that Google Play has accepted or delivered this build.
|
delivered this exact artifact on the Internal testing track on 2026-08-10.
|
||||||
|
|
||||||
## Source and artifacts
|
## Source and artifacts
|
||||||
|
|
||||||
|
|
@ -68,23 +68,25 @@ The current source passed API 37 instrumentation in the isolated unit
|
||||||
|
|
||||||
## What changed from Play-delivered v2
|
## What changed from Play-delivered v2
|
||||||
|
|
||||||
The currently installed Google Play build is still `0.1.1 (2)`. Candidate v3
|
Candidate v3 changes the live-location cancellation contract: dismissing the prominent
|
||||||
changes the live-location cancellation contract: dismissing the prominent
|
|
||||||
native disclosure or denying the permission emits an explicit cancellation
|
native disclosure or denying the permission emits an explicit cancellation
|
||||||
event instead of a generic technical-error event. The web UI can therefore
|
event instead of a generic technical-error event. The web UI can therefore
|
||||||
remain in the stopped state without falsely telling the user that location
|
remain in the stopped state without falsely telling the user that location
|
||||||
sharing failed.
|
sharing failed.
|
||||||
|
|
||||||
## Remaining gates
|
## Play delivery and remaining gates
|
||||||
|
|
||||||
Before this candidate can replace v2 on Internal testing:
|
On 2026-08-10 Play Console showed `0.1.2 Location consent clarity` available to
|
||||||
|
Internal testers with one version code. The physical phone's installed package
|
||||||
|
passed the strict Play installer, signing, exact-version, App Link, and activity
|
||||||
|
resolution verifier. A production-fixture replay also verified user-initiated
|
||||||
|
foreground location, minimized notification operation, notification Stop, 41
|
||||||
|
samples, zero retained raw positions after Stop, and exact fixture cleanup.
|
||||||
|
|
||||||
1. obtain explicit permission for the exact AAB and Internal track;
|
The remaining gates are:
|
||||||
2. upload and publish version code `3` only to Internal testing;
|
|
||||||
3. install it through Google Play on the physical test phone;
|
1. create a concise final foreground-location declaration video from the
|
||||||
4. run the strict installed-build verifier and the full physical workflow;
|
|
||||||
5. create the final foreground-location declaration video from the
|
|
||||||
Play-delivered candidate;
|
Play-delivered candidate;
|
||||||
6. complete and verify the Play Console foreground-service/location form;
|
2. complete and verify the Play Console foreground-service/location form;
|
||||||
7. keep Closed and Production tracks untouched until their separate gates are
|
3. keep Closed and Production tracks untouched until their separate gates are
|
||||||
complete.
|
complete.
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,6 @@
|
||||||
# Who Need Help — implementation verification
|
# Who Need Help — implementation verification
|
||||||
|
|
||||||
Observed through 2026-08-09 in the local workspace. This report separates observed
|
Observed through 2026-08-10 in the local workspace. This report separates observed
|
||||||
results from product limits and unknown production properties.
|
results from product limits and unknown production properties.
|
||||||
|
|
||||||
## External-monitor SMTP isolation proof on 2026-08-09
|
## External-monitor SMTP isolation proof on 2026-08-09
|
||||||
|
|
@ -2692,3 +2692,37 @@ promoted.
|
||||||
- Exact hashes, screenshots, cleanup scope and remaining Google Play gates are
|
- Exact hashes, screenshots, cleanup scope and remaining Google Play gates are
|
||||||
recorded in `docs/google-play-release-candidate-2026-08-09-v2.md` and
|
recorded in `docs/google-play-release-candidate-2026-08-09-v2.md` and
|
||||||
`android/play-store/internal-release-v2.md`.
|
`android/play-store/internal-release-v2.md`.
|
||||||
|
|
||||||
|
# 2026-08-10 authorised pilot release and Google Play internal v3 verification
|
||||||
|
|
||||||
|
- The production application was updated app-only to local revision
|
||||||
|
`7c2b55917dcaed52f9788cbbfcc6f2ff0a3354f6`. The shared Caddy edge, frozen
|
||||||
|
hackathon-test checkout, and public Git remote were not changed. Production
|
||||||
|
readiness returned `ready` after the release.
|
||||||
|
- A temporary production E2E run exercised the authorised application release
|
||||||
|
and completed exact run-scoped cleanup. The temporary test identities and
|
||||||
|
records were verified absent afterward; production readiness remained
|
||||||
|
`ready`, and the frozen-test readiness endpoint also remained `ready`.
|
||||||
|
- Production and frozen-test SMTP credentials were separated and verified
|
||||||
|
without printing their values. The replaced credentials were deactivated.
|
||||||
|
- Off-site backup creation, restore validation, and the external monitor were
|
||||||
|
rechecked and healthy after the application release.
|
||||||
|
- Google Play released the exact `0.1.2 (3)` AAB only to Internal testing. Its
|
||||||
|
SHA-256 is
|
||||||
|
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`.
|
||||||
|
Play Console showed the release available to internal testers with one
|
||||||
|
version code and no Closed or Production rollout.
|
||||||
|
- The physical phone installed the artifact through Google Play. The strict
|
||||||
|
verifier observed installer `com.android.vending`, a recorded Play App
|
||||||
|
Signing identity, exact version `0.1.2 (3)`, verified production App Link,
|
||||||
|
and `MainActivity` resolution.
|
||||||
|
- A run-scoped foreground-location replay showed the prominent disclosure,
|
||||||
|
Android permission prompt, active in-app state, and persistent notification
|
||||||
|
while minimized. Notification Stop ended sharing; server verification
|
||||||
|
observed 41 samples and zero retained raw positions. The request,
|
||||||
|
assignment, tracking session, and synthetic requester were then deleted.
|
||||||
|
- The retained 177.864689-second source take is not the final Play declaration
|
||||||
|
video because Android screen recording stopped before the Stop tap and
|
||||||
|
stopped state were captured. A concise complete take of 30 seconds or less,
|
||||||
|
the Play foreground-service declaration, and Closed testing remain open
|
||||||
|
gates. No Production Play rollout has been started.
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user