diff --git a/android/play-store/internal-release-v3.md b/android/play-store/internal-release-v3.md new file mode 100644 index 0000000..2c46e06 --- /dev/null +++ b/android/play-store/internal-release-v3.md @@ -0,0 +1,82 @@ +# Internal testing release v3 + +This is the operator copy for the next Google Play Internal testing candidate. +The artifact has been built and verified locally, but it has not been uploaded, +saved, published, or delivered by Google Play yet. + +## Release identity + +- Track: Internal testing only +- Release label: `0.1.2 Location consent clarity` +- Package: `org.whoneedhelp.mobile` +- Version code: `3` +- Version name: `0.1.2` +- Source commit: `cd154766a06bb1febb0598fb3f53db78628bd7f6` +- Source fingerprint: + `70529d3befcb0818f0b79f7869389b4fad432eb2911be08d52342529b7f22614` +- AAB: `android/dist-release-20260809-v3/who-need-help-release.aab` +- AAB SHA-256: + `5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922` + +Do not upload an artifact with a different hash under this release record. A +code change requires a new version code, a fresh source-bound build, and a new +record. + +## Release notes + +### English (United States) + +Improves live-location consent feedback. Cancelling the disclosure now leaves +sharing stopped without presenting a misleading technical error. + +### Ukrainian + +Покращено повідомлення про згоду на передавання геолокації. Скасування діалогу +тепер залишає передавання вимкненим і не показує помилкову технічну помилку. + +### Russian + +Улучшена обратная связь при согласии на передачу геолокации. Отмена диалога +теперь оставляет передачу выключенной и не показывает ложную техническую ошибку. + +## Local verification + +- Release unit tests, release lint, R8/resource shrinking, APK/AAB signing, + bundletool validation and the production App Links gate passed. +- The exported source fingerprint matches the current committed source. +- API 37 instrumentation passed 10/10 tests, including explicit native + disclosure cancellation and notification-based Stop behavior. +- The independent process-death probe observed the expected killed process and + verified that the non-sticky foreground service and notification did not + remain. +- The one-off emulator container, image and volume were removed by the test + harness. + +Detailed evidence is recorded in +`docs/google-play-release-candidate-2026-08-09-v3.md`. + +## Before publishing + +Verify in Play Console that: + +1. the application is Who Need Help with package `org.whoneedhelp.mobile`; +2. the selected track is Internal testing, not Closed or Production; +3. the accepted artifact has version code `3` and version name `0.1.2`; +4. the AAB hash matches this record before upload; +5. the release notes contain no credential, private email, test URL, precise + location or medical detail; +6. no Production or Closed rollout is selected. + +Uploading, saving or publishing is an external state change. Do not press the +final control without explicit permission for this exact candidate and track. + +## Immediately after publication + +1. Install version `0.1.2 (3)` from Google Play on the authorised physical + phone; do not side-load the upload-signed APK as Play-delivered evidence. +2. Run `scripts/verify-play-installed-android.sh` and confirm the Play installer, + Play signing identity, verified App Link and expected version. +3. Re-run Google sign-in, FCM tap routing, supported and excluded App Links, + disclosure cancellation, active foreground location sharing, minimized-app + sampling and notification Stop cleanup. +4. Record Play-delivered evidence before replacing the Internal track candidate. diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index f2f9f40..4b23cdb 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -50,6 +50,12 @@ accepted artifact and the internal release is available to testers. The exact `0.1.0 (1)` release is active only on the Internal testing track; no Closed or Production rollout was started. +- [x] Build and locally validate source-bound candidate `0.1.2 (3)` from + commit `cd15476`; release tests, lint, signing, bundle validation, App + Links validation and API 37 instrumentation passed. The candidate is + documented in `internal-release-v3.md` and has not been uploaded. +- [ ] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it + through Google Play and repeat the strict physical-device verification. ## Production capability gate diff --git a/docs/google-play-release-candidate-2026-08-09-v3.md b/docs/google-play-release-candidate-2026-08-09-v3.md new file mode 100644 index 0000000..178c252 --- /dev/null +++ b/docs/google-play-release-candidate-2026-08-09-v3.md @@ -0,0 +1,90 @@ +# Google Play Internal candidate v3 — 2026-08-09 + +This record binds the locally prepared third Internal testing candidate to the +exact committed source and observed verification evidence. It does not claim +that Google Play has accepted or delivered this build. + +## Source and artifacts + +- Source commit: `cd154766a06bb1febb0598fb3f53db78628bd7f6` +- Source fingerprint: + `70529d3befcb0818f0b79f7869389b4fad432eb2911be08d52342529b7f22614` +- Package: `org.whoneedhelp.mobile` +- Version: `0.1.2 (3)` +- Intended Internal release label: `0.1.2 Location consent clarity` +- Artifact directory: `android/dist-release-20260809-v3/` +- Release APK SHA-256: + `32132ee85b58e2f719b11d004dd7f5896bfde3b01372ad0b3293bf7bcbe79193` +- Play AAB SHA-256: + `5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922` +- Universal APK SHA-256: + `b2bcb19d96c42621a5001a6b682edcb6d27aa3932ec334f0e93b0b7f20817393` +- Universal APKS SHA-256: + `b7024006c27c5d4878cad95b8c9dc2eb2e1038aa713c9dbf719a51eccfa1a497` + +The build used a temporary mode-0600 copy of the production Android +configuration with only the candidate version changed to `0.1.2 (3)`. The +temporary file was removed by the isolated build unit. The development `.env`, +production server and frozen hackathon test deployment were not changed. + +## Release pipeline evidence + +The source-bound release pipeline completed successfully: + +- production Android environment and App Links identity validation; +- release unit tests; +- release lint; +- R8 code shrinking and resource shrinking; +- release APK and AAB assembly; +- APK signing-certificate verification; +- AAB JAR-signature verification; +- bundletool AAB validation and universal APK generation; +- package-name and production-origin verification; +- exported source fingerprint comparison with the current committed source. + +The isolated build unit was +`codex-heavy-wnh-android-release-v3-20260809-20260809-211532-3613142.service`. +It completed successfully in 37.450 seconds with a 154 MiB unit memory peak; +Docker build workers are accounted for by the Docker service rather than this +client unit. + +## Instrumentation evidence + +The current source passed API 37 instrumentation in the isolated unit +`codex-heavy-wnh-android-instrumentation-api37-v3-20260809-211723-3671839.service`. + +- Main instrumentation: `OK (10 tests)` in 71.145 seconds. +- The suite covered loading state, denied permission, web geolocation, + disclosure cancellation, App Link recreation/update, foreground location + posting and notification Stop, network retry, Home/activity destruction and + main-page retry. +- The process-death probe intentionally killed the instrumented app after the + foreground service appeared. The harness verified that the non-sticky + service and persistent notification did not remain. +- Evidence directory: + `output/android-instrumentation/api37-0/20260809181723-3672268/`. +- The generated emulator container, image and named AVD volume were absent + after cleanup. + +## What changed from Play-delivered v2 + +The currently installed Google Play build is still `0.1.1 (2)`. Candidate v3 +changes the live-location cancellation contract: dismissing the prominent +native disclosure or denying the permission emits an explicit cancellation +event instead of a generic technical-error event. The web UI can therefore +remain in the stopped state without falsely telling the user that location +sharing failed. + +## Remaining gates + +Before this candidate can replace v2 on Internal testing: + +1. obtain explicit permission for the exact AAB and Internal track; +2. upload and publish version code `3` only to Internal testing; +3. install it through Google Play on the physical test phone; +4. run the strict installed-build verifier and the full physical workflow; +5. create the final foreground-location declaration video from the + Play-delivered candidate; +6. complete and verify the Play Console foreground-service/location form; +7. keep Closed and Production tracks untouched until their separate gates are + complete.