Document Play internal v3 verification

This commit is contained in:
SimpleTest 2026-08-10 12:21:04 +03:00
parent 7c2b55917d
commit abbcf24984
6 changed files with 141 additions and 47 deletions

View File

@ -17,14 +17,16 @@ eligibility and the date on which production access can be requested.
identities shown for quantum-ready hybrid signing when present. Add every
applicable Play App Signing SHA-256 to production App Links and
Google/Firebase configuration, then verify the production association files.
5. Upload the source-bound production AAB. The current prepared candidate is
`0.1.2 (3)` with SHA-256
5. Use the source-bound production AAB already released only to Internal
testing. The current Internal release is `0.1.2 (3)` with SHA-256
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`;
its exact operator record is `internal-release-v3.md`.
6. Complete the store listing, App content, privacy, Data Safety, content rating,
ads, target-audience, and access declarations.
7. Start with an internal test on the owner’s device, then promote the verified
build to the closed track.
7. Finish the internal test on the owner’s device, complete the foreground-
service declaration, then promote the verified build to the closed track.
As of 2026-08-10 the Internal release is active, but Closed testing has not
been started.
After installing from the internal-track opt-in link, verify the delivery
boundary before testing authenticated flows:

View File

@ -1,8 +1,9 @@
# Internal testing release v3
This is the operator copy for the next Google Play Internal testing candidate.
The artifact has been built and verified locally, but it has not been uploaded,
saved, published, or delivered by Google Play yet.
This is the operator record for the current Google Play Internal testing
release. The source-bound artifact was uploaded, released only to Internal
testing, delivered by Google Play, and verified on the authorised physical
phone on 2026-08-10.
## Release identity
@ -55,28 +56,40 @@ sharing stopped without presenting a misleading technical error.
Detailed evidence is recorded in
`docs/google-play-release-candidate-2026-08-09-v3.md`.
## Before publishing
## Publication evidence
Verify in Play Console that:
Play Console was re-read on 2026-08-10 and showed:
1. the application is Who Need Help with package `org.whoneedhelp.mobile`;
2. the selected track is Internal testing, not Closed or Production;
3. the accepted artifact has version code `3` and version name `0.1.2`;
4. the AAB hash matches this record before upload;
5. the release notes contain no credential, private email, test URL, precise
location or medical detail;
6. no Production or Closed rollout is selected.
1. track **Internal testing** is active;
2. latest release is `0.1.2 Location consent clarity`;
3. the release is available to internal testers with one version code;
4. the release timestamp is 2026-08-10 11:02 AM in the Console UI;
5. the app is still unreviewed, so Internal testers see the temporary package
name until the application setup is reviewed;
6. no Closed or Production rollout was started by this release.
Uploading, saving or publishing is an external state change. Do not press the
final control without explicit permission for this exact candidate and track.
The App content overview was re-read on 2026-08-10 and showed exactly one item
under **Need attention**: the Foreground service permissions declaration. Its
Location form had no saved task selection and the Save control was disabled.
No incomplete declaration was saved or submitted during this inspection.
## Immediately after publication
The authorised physical phone then passed the strict installed-build verifier:
Google Play installer, Play App Signing identity, exact `0.1.2 (3)` version,
verified production App Link, and `MainActivity` resolution.
1. Install version `0.1.2 (3)` from Google Play on the authorised physical
phone; do not side-load the upload-signed APK as Play-delivered evidence.
2. Run `scripts/verify-play-installed-android.sh` and confirm the Play installer,
Play signing identity, verified App Link and expected version.
3. Re-run Google sign-in, FCM tap routing, supported and excluded App Links,
disclosure cancellation, active foreground location sharing, minimized-app
sampling and notification Stop cleanup.
4. Record Play-delivered evidence before replacing the Internal track candidate.
## Post-publication foreground-location evidence
An exact run-scoped production fixture was used only for the location replay.
The Play-delivered app showed the prominent disclosure, Android permission
prompt, active in-app state, and persistent notification while minimized. The
notification Stop action ended the session; server verification observed 41
samples and zero retained raw positions. Exact fixture cleanup deleted the
request, assignment, session, and synthetic requester, then both production
and frozen-test readiness endpoints returned `ready`.
The long evidence take is not the submission video: Android's recorder reached
its time limit before the Stop action was captured even though Stop and server
cleanup were verified immediately afterward. Record a concise, complete take
from this same Play-delivered version before entering a video URL in Play
Console. Do not replace the Internal candidate until that recording and the
foreground-service declaration are complete.

View File

@ -179,6 +179,33 @@ Foreground-service references rechecked on 2026-08-09:
- https://support.google.com/googleplay/android-developer/answer/13392821
- https://developer.android.com/develop/background-work/services/fgs/service-types
The Play Help page was rechecked again on 2026-08-10. It still requires a video
link for each declared foreground-service feature and recommends keeping the
demonstration at 30 seconds or less. The final edit must therefore retain the
user trigger, prominent disclosure, runtime prompt, minimized persistent
notification, and notification Stop action while removing only idle time.
### Play-delivered evidence take on 2026-08-10
The exact Play-delivered `0.1.2 (3)` build produced a long evidence take at:
`/g/home/Downloads/Who-Need-Help-Play-Console-location-sharing-FINAL-v4.mp4`
Its SHA-256 is
`56608ca3e2e1aafd7a85c325109581c379d4cb714794ba4c6c414706d451ff96`.
The file is 177.864689 seconds, H.264, and 720×1600. Visual review confirms the
in-app trigger, prominent disclosure, Android runtime prompt, active in-app
state, Home/minimized operation, and persistent notification with the visible
Stop action. It contains no account email, fixture credentials, precise map,
medical information, chat, or handover code.
This take is retained only as source evidence. The recorder reached its time
limit before the notification Stop tap and stopped in-app state were captured,
so it must not be submitted to Play Console as the final demonstration. The
Stop action was performed immediately afterward: server verification observed
41 samples and zero retained raw positions, and exact fixture cleanup passed.
A new concise take must visibly include Stop and the stopped state.
The remaining Play policy references were last checked on 2026-08-03; refresh
them again immediately before submitting the declaration because the Help
Center pages can change independently of the Android platform documentation:

View File

@ -53,9 +53,16 @@
- [x] Build and locally validate source-bound candidate `0.1.2 (3)` from
commit `cd15476`; release tests, lint, signing, bundle validation, App
Links validation and API 37 instrumentation passed. The candidate is
documented in `internal-release-v3.md` and has not been uploaded.
- [ ] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it
documented in `internal-release-v3.md`; its subsequent Internal-track
upload and Play-delivered verification are recorded in the next item.
- [x] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it
through Google Play and repeat the strict physical-device verification.
Play Console showed release `0.1.2 Location consent clarity` available to
internal testers on 2026-08-10 with one version code and no Closed or
Production rollout. The installed package was delivered by
`com.android.vending`; its Play signing identity, version, verified
production App Link, and `MainActivity` resolution passed the strict
verifier.
## Production capability gate
@ -103,6 +110,9 @@
service.
- [ ] Complete the mandatory Play Console foreground-service declaration for
the `location` service used by the exact AAB.
Read-only inspection on 2026-08-10 showed this as the only App content
item under `Need attention`. The Location declaration currently has no
saved task selection; no incomplete form was saved or submitted.
- [ ] Upload the unlisted demonstration video showing the user-triggered start,
prominent disclosure, Android permission, persistent notification,
minimized-app operation, and Stop action.
@ -122,15 +132,21 @@
identity document, physical-device serial, and exact expected version.
It must confirm the Google Play installer, Play signing identity,
verified production App Link, and `MainActivity` resolution.
The 2026-08-09 physical-device replay passed that verifier, Google
The 2026-08-09 v2 physical-device replay passed that verifier, Google
sign-in, production App Link routing, Android notification permission,
production FCM receipt and notification-tap routing. The same
Play-delivered build then passed the separate consent-driven foreground
location flow: explicit disclosure, Android permission, persistent
notification, minimized-app sampling, notification Stop cleanup,
offline/reconnect, and stopped-process recreation without sticky
tracking. This verifies observed app behavior; it does not complete the
separate Play Console policy declarations above.
tracking. On 2026-08-10 the Play-delivered v3 install passed the strict
delivery-boundary verifier and a new production fixture replay observed
the disclosure, Android runtime prompt, active in-app state, minimized
foreground-service notification, 41 server samples, notification Stop,
and zero retained raw positions after Stop. The run-scoped fixture was
then deleted and both production and frozen-test readiness remained
healthy. This verifies observed app behavior; it does not complete the
separate Play Console policy declarations or the final video above.
- [ ] Closed track created and opt-in link tested.
- [ ] At least 12 testers continuously opted in for 14 days.
- [ ] Tester feedback and fixes documented.

View File

@ -1,8 +1,8 @@
# Google Play Internal candidate v3 — 2026-08-09
This record binds the locally prepared third Internal testing candidate to the
exact committed source and observed verification evidence. It does not claim
that Google Play has accepted or delivered this build.
This record binds the third Internal testing release to the exact committed
source and observed verification evidence. Google Play accepted, released, and
delivered this exact artifact on the Internal testing track on 2026-08-10.
## Source and artifacts
@ -68,23 +68,25 @@ The current source passed API 37 instrumentation in the isolated unit
## What changed from Play-delivered v2
The currently installed Google Play build is still `0.1.1 (2)`. Candidate v3
changes the live-location cancellation contract: dismissing the prominent
Candidate v3 changes the live-location cancellation contract: dismissing the prominent
native disclosure or denying the permission emits an explicit cancellation
event instead of a generic technical-error event. The web UI can therefore
remain in the stopped state without falsely telling the user that location
sharing failed.
## Remaining gates
## Play delivery and remaining gates
Before this candidate can replace v2 on Internal testing:
On 2026-08-10 Play Console showed `0.1.2 Location consent clarity` available to
Internal testers with one version code. The physical phone's installed package
passed the strict Play installer, signing, exact-version, App Link, and activity
resolution verifier. A production-fixture replay also verified user-initiated
foreground location, minimized notification operation, notification Stop, 41
samples, zero retained raw positions after Stop, and exact fixture cleanup.
1. obtain explicit permission for the exact AAB and Internal track;
2. upload and publish version code `3` only to Internal testing;
3. install it through Google Play on the physical test phone;
4. run the strict installed-build verifier and the full physical workflow;
5. create the final foreground-location declaration video from the
The remaining gates are:
1. create a concise final foreground-location declaration video from the
Play-delivered candidate;
6. complete and verify the Play Console foreground-service/location form;
7. keep Closed and Production tracks untouched until their separate gates are
2. complete and verify the Play Console foreground-service/location form;
3. keep Closed and Production tracks untouched until their separate gates are
complete.

View File

@ -1,6 +1,6 @@
# Who Need Help — implementation verification
Observed through 2026-08-09 in the local workspace. This report separates observed
Observed through 2026-08-10 in the local workspace. This report separates observed
results from product limits and unknown production properties.
## External-monitor SMTP isolation proof on 2026-08-09
@ -2692,3 +2692,37 @@ promoted.
- Exact hashes, screenshots, cleanup scope and remaining Google Play gates are
recorded in `docs/google-play-release-candidate-2026-08-09-v2.md` and
`android/play-store/internal-release-v2.md`.
# 2026-08-10 authorised pilot release and Google Play internal v3 verification
- The production application was updated app-only to local revision
`7c2b55917dcaed52f9788cbbfcc6f2ff0a3354f6`. The shared Caddy edge, frozen
hackathon-test checkout, and public Git remote were not changed. Production
readiness returned `ready` after the release.
- A temporary production E2E run exercised the authorised application release
and completed exact run-scoped cleanup. The temporary test identities and
records were verified absent afterward; production readiness remained
`ready`, and the frozen-test readiness endpoint also remained `ready`.
- Production and frozen-test SMTP credentials were separated and verified
without printing their values. The replaced credentials were deactivated.
- Off-site backup creation, restore validation, and the external monitor were
rechecked and healthy after the application release.
- Google Play released the exact `0.1.2 (3)` AAB only to Internal testing. Its
SHA-256 is
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`.
Play Console showed the release available to internal testers with one
version code and no Closed or Production rollout.
- The physical phone installed the artifact through Google Play. The strict
verifier observed installer `com.android.vending`, a recorded Play App
Signing identity, exact version `0.1.2 (3)`, verified production App Link,
and `MainActivity` resolution.
- A run-scoped foreground-location replay showed the prominent disclosure,
Android permission prompt, active in-app state, and persistent notification
while minimized. Notification Stop ended sharing; server verification
observed 41 samples and zero retained raw positions. The request,
assignment, tracking session, and synthetic requester were then deleted.
- The retained 177.864689-second source take is not the final Play declaration
video because Android screen recording stopped before the Stop tap and
stopped state were captured. A concise complete take of 30 seconds or less,
the Play foreground-service declaration, and Closed testing remain open
gates. No Production Play rollout has been started.