From d17637d3d36aa9c1699ff35320ef4db3307e10af Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Thu, 13 Aug 2026 05:06:21 +0300 Subject: [PATCH] Record current Play launch gates --- android/play-store/store-presence-runbook.md | 32 +++++++----- docs/verification.md | 55 +++++++++++++++----- 2 files changed, 61 insertions(+), 26 deletions(-) diff --git a/android/play-store/store-presence-runbook.md b/android/play-store/store-presence-runbook.md index ccede3c..723616a 100644 --- a/android/play-store/store-presence-runbook.md +++ b/android/play-store/store-presence-runbook.md @@ -3,18 +3,22 @@ This runbook records the exact local inputs and the observed Console gaps. It does not authorize saving fields in Play Console or publishing a release. -## Observed Console state on 2026-08-10 +## Observed Console state on 2026-08-13 - App type is **App**. - App category is not selected. - Tags are not selected. - Store-listing contact email, phone, and website are empty. -- No default store listing has been created. -- A second read-only inspection found the default English listing still empty - except for an existing unsaved app-name value `Who Need Help`. The unsaved - value was preserved; no field was entered, discarded, saved, or published. +- The default English listing has no saved short description, full + description, app icon, feature graphic, or phone screenshots. - The Dashboard showed 9 of 11 setup tasks complete. The remaining setup tasks were category/contact details and the store listing. +- Closed testing was still locked pending those setup tasks and reported zero + opted-in testers. +- The foreground-service declaration had no saved task selection. Selecting + **User-initiated location sharing** temporarily exposed a required video-link + field; the selection was then cleared and the final form had all checkboxes + unchecked, no video field, and a disabled Save action. Nothing was saved. These are direct observations from the authenticated Play Console session on that date. Recheck the Console before applying because its fields and policy @@ -51,15 +55,15 @@ send a real inbound message to it, observe arrival in the monitored mailbox, and verify that replies are handled. Google recommends keeping the public app support address distinct from the developer-account sign-in address. -A read-only public DNS check on 2026-08-10 returned no MX record for -`whoneedhelp.com`, and a connection to the domain's web-server address on SMTP -port 25 produced no server greeting within five seconds. This does not prove -that every possible mail route is absent, but it provides no evidence that -`contact@whoneedhelp.com` can receive mail. The address remains a candidate, -not a verified support inbox. Before Console entry, either configure and test a -monitored inbound mailbox/forwarder for that address or deliberately use a -different already monitored public support address. Outbound Brevo delivery -from the address is not evidence of inbound delivery to it. +A repeated read-only public DNS check on 2026-08-13 returned no MX record for +either `whoneedhelp.com` or `contact.whoneedhelp.com`. Production is configured +to send through Brevo as `contact@whoneedhelp.com`, while internal support +alerts route to the operator's monitored mailbox. These are outbound and +internal-routing facts; neither proves inbound delivery to the public address. +The address remains a candidate, not a verified support inbox. Before Console +entry, either configure and test a monitored inbound mailbox/forwarder for that +address or deliberately use a different already monitored public support +address. ## Category and child-safety gate diff --git a/docs/verification.md b/docs/verification.md index 93b7b62..75f5dd0 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -5,22 +5,19 @@ results from product limits and unknown production properties. ## Current local candidate and operations recheck on 2026-08-13 -- Application source candidate `0393cadcadf001b50901af05cf5950139b6808f0` passed the +- Application source candidate `2aa246dcfc242150b6f1bc9a20aa0ff533bab932` passed the complete isolated `scripts/quality.sh` pipeline in user-systemd unit - `codex-heavy-wnh-quality-0393cad-20260813-012423-3600824.service`. - ExUnit reported 469 passing tests with seed `346927`; the fourteen browser + `codex-heavy-wnh-quality-head-2aa246d-20260813-043521-20260813-043521-1148257.service`. + ExUnit reported 469 passing tests with seed `142388`; the fourteen browser map tests passed; every configured quality and security gate passed; and the final Debian 13.6 runtime-image scan reported zero detected - vulnerabilities. The unit exited successfully after 4 minutes 22.551 - seconds with a measured 325.8 MiB systemd-unit memory peak. One Oban - notifier process logged an Ecto Sandbox owner-exit diagnostic while the test - owner was shutting down; the suite still completed with 469 passes and a - successful unit result. -- After this evidence was recorded, documentation-only updates became the local - release candidate. A fresh read-only production release plan compared the - then-current documentation revision with + vulnerabilities. The unit exited successfully after 2 minutes 33.375 + seconds with a measured 349.8 MiB systemd-unit memory peak. Exact-name + inspection after the run found no remaining run-scoped container, network, + volume, or temporary quality/security image. +- A fresh read-only production release plan compared this candidate with production revision `dafcdb36cbe221af0c880fd05da3321e181ddd2c`. It observed - seventeen pending + twenty-one pending commits, one reviewed `application_safe` migration (`20260812120611_allow_inbox_only_nearby_subscriptions.exs`), external PostgreSQL 18.4, unchanged shared-edge routing, and all twelve environment @@ -57,6 +54,40 @@ results from product limits and unknown production properties. test deployment or shared Caddy, save Google Play Console fields, or push the public Git remote. +### Google Play Console and store-presence observation on 2026-08-13 + +- A read-only inspection of the authenticated Play Console observed app setup + at 9 of 11 tasks. The two incomplete tasks are **Select app category and + provide contact details** and **Set up store listing**. App type is `App`, + category and tags are not selected, and the public email, phone, and website + fields are empty. The default listing still has no saved short description, + full description, app icon, feature graphic, or phone screenshots. No + Console value was saved during the inspection. +- The foreground-service declaration has no saved task selection. The current + form reveals a required video-link field when **User-initiated location + sharing** is selected; that is the only observed use case matching this + application. The verified local demonstration is + `output/android/play-console/wnh-fgs-review-final-v5.mp4`, SHA-256 + `3c5f52019bf8a42ff42e1d9232afc126b62627390d74eed75084d82ecb33ac56`. + It has not been hosted and no declaration was saved. +- Closed testing remains locked until app setup is complete. The Console + reported zero opted-in closed testers. Current Google Play documentation for + a new personal developer account requires at least 12 opted-in testers for + 14 continuous days before production access can be requested; Internal + testing does not satisfy that gate. +- Public DNS returned no MX record for `whoneedhelp.com` or + `contact.whoneedhelp.com`. Production uses `contact@whoneedhelp.com` as a + Brevo outbound sender and routes internal support alerts to the monitored + operator mailbox, but neither fact establishes inbound delivery to + `contact@whoneedhelp.com`. The address must not be saved as the public Play + support contact until an inbound route is configured and tested, or the + operator deliberately selects another monitored public address. +- The connected physical phone again passed the strict Play-delivered build + check for `org.whoneedhelp.mobile` version `0.1.2 (3)`: installer Google + Play, signing identity from the protected Play App Signing set, verified + `whoneedhelp.com` App Link resolving to `MainActivity`, and no Android claim + on the browser-only OAuth callback. + ### Frozen-test memory observation on 2026-08-13 - A read-only server inspection found production healthy at about 197 MiB of