Prepare Android internal release candidate v3

This commit is contained in:
SimpleTest 2026-08-09 21:23:17 +03:00
parent cd154766a0
commit d97adefac1
3 changed files with 178 additions and 0 deletions

View File

@ -0,0 +1,82 @@
# Internal testing release v3
This is the operator copy for the next Google Play Internal testing candidate.
The artifact has been built and verified locally, but it has not been uploaded,
saved, published, or delivered by Google Play yet.
## Release identity
- Track: Internal testing only
- Release label: `0.1.2 Location consent clarity`
- Package: `org.whoneedhelp.mobile`
- Version code: `3`
- Version name: `0.1.2`
- Source commit: `cd154766a06bb1febb0598fb3f53db78628bd7f6`
- Source fingerprint:
`70529d3befcb0818f0b79f7869389b4fad432eb2911be08d52342529b7f22614`
- AAB: `android/dist-release-20260809-v3/who-need-help-release.aab`
- AAB SHA-256:
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`
Do not upload an artifact with a different hash under this release record. A
code change requires a new version code, a fresh source-bound build, and a new
record.
## Release notes
### English (United States)
Improves live-location consent feedback. Cancelling the disclosure now leaves
sharing stopped without presenting a misleading technical error.
### Ukrainian
Покращено повідомлення про згоду на передавання геолокації. Скасування діалогу
тепер залишає передавання вимкненим і не показує помилкову технічну помилку.
### Russian
Улучшена обратная связь при согласии на передачу геолокации. Отмена диалога
теперь оставляет передачу выключенной и не показывает ложную техническую ошибку.
## Local verification
- Release unit tests, release lint, R8/resource shrinking, APK/AAB signing,
bundletool validation and the production App Links gate passed.
- The exported source fingerprint matches the current committed source.
- API 37 instrumentation passed 10/10 tests, including explicit native
disclosure cancellation and notification-based Stop behavior.
- The independent process-death probe observed the expected killed process and
verified that the non-sticky foreground service and notification did not
remain.
- The one-off emulator container, image and volume were removed by the test
harness.
Detailed evidence is recorded in
`docs/google-play-release-candidate-2026-08-09-v3.md`.
## Before publishing
Verify in Play Console that:
1. the application is Who Need Help with package `org.whoneedhelp.mobile`;
2. the selected track is Internal testing, not Closed or Production;
3. the accepted artifact has version code `3` and version name `0.1.2`;
4. the AAB hash matches this record before upload;
5. the release notes contain no credential, private email, test URL, precise
location or medical detail;
6. no Production or Closed rollout is selected.
Uploading, saving or publishing is an external state change. Do not press the
final control without explicit permission for this exact candidate and track.
## Immediately after publication
1. Install version `0.1.2 (3)` from Google Play on the authorised physical
phone; do not side-load the upload-signed APK as Play-delivered evidence.
2. Run `scripts/verify-play-installed-android.sh` and confirm the Play installer,
Play signing identity, verified App Link and expected version.
3. Re-run Google sign-in, FCM tap routing, supported and excluded App Links,
disclosure cancellation, active foreground location sharing, minimized-app
sampling and notification Stop cleanup.
4. Record Play-delivered evidence before replacing the Internal track candidate.

View File

@ -50,6 +50,12 @@
accepted artifact and the internal release is available to testers. The accepted artifact and the internal release is available to testers. The
exact `0.1.0 (1)` release is active only on the Internal testing track; exact `0.1.0 (1)` release is active only on the Internal testing track;
no Closed or Production rollout was started. no Closed or Production rollout was started.
- [x] Build and locally validate source-bound candidate `0.1.2 (3)` from
commit `cd15476`; release tests, lint, signing, bundle validation, App
Links validation and API 37 instrumentation passed. The candidate is
documented in `internal-release-v3.md` and has not been uploaded.
- [ ] Upload the exact recorded `0.1.2 (3)` AAB to Internal testing, install it
through Google Play and repeat the strict physical-device verification.
## Production capability gate ## Production capability gate

View File

@ -0,0 +1,90 @@
# Google Play Internal candidate v3 — 2026-08-09
This record binds the locally prepared third Internal testing candidate to the
exact committed source and observed verification evidence. It does not claim
that Google Play has accepted or delivered this build.
## Source and artifacts
- Source commit: `cd154766a06bb1febb0598fb3f53db78628bd7f6`
- Source fingerprint:
`70529d3befcb0818f0b79f7869389b4fad432eb2911be08d52342529b7f22614`
- Package: `org.whoneedhelp.mobile`
- Version: `0.1.2 (3)`
- Intended Internal release label: `0.1.2 Location consent clarity`
- Artifact directory: `android/dist-release-20260809-v3/`
- Release APK SHA-256:
`32132ee85b58e2f719b11d004dd7f5896bfde3b01372ad0b3293bf7bcbe79193`
- Play AAB SHA-256:
`5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922`
- Universal APK SHA-256:
`b2bcb19d96c42621a5001a6b682edcb6d27aa3932ec334f0e93b0b7f20817393`
- Universal APKS SHA-256:
`b7024006c27c5d4878cad95b8c9dc2eb2e1038aa713c9dbf719a51eccfa1a497`
The build used a temporary mode-0600 copy of the production Android
configuration with only the candidate version changed to `0.1.2 (3)`. The
temporary file was removed by the isolated build unit. The development `.env`,
production server and frozen hackathon test deployment were not changed.
## Release pipeline evidence
The source-bound release pipeline completed successfully:
- production Android environment and App Links identity validation;
- release unit tests;
- release lint;
- R8 code shrinking and resource shrinking;
- release APK and AAB assembly;
- APK signing-certificate verification;
- AAB JAR-signature verification;
- bundletool AAB validation and universal APK generation;
- package-name and production-origin verification;
- exported source fingerprint comparison with the current committed source.
The isolated build unit was
`codex-heavy-wnh-android-release-v3-20260809-20260809-211532-3613142.service`.
It completed successfully in 37.450 seconds with a 154 MiB unit memory peak;
Docker build workers are accounted for by the Docker service rather than this
client unit.
## Instrumentation evidence
The current source passed API 37 instrumentation in the isolated unit
`codex-heavy-wnh-android-instrumentation-api37-v3-20260809-211723-3671839.service`.
- Main instrumentation: `OK (10 tests)` in 71.145 seconds.
- The suite covered loading state, denied permission, web geolocation,
disclosure cancellation, App Link recreation/update, foreground location
posting and notification Stop, network retry, Home/activity destruction and
main-page retry.
- The process-death probe intentionally killed the instrumented app after the
foreground service appeared. The harness verified that the non-sticky
service and persistent notification did not remain.
- Evidence directory:
`output/android-instrumentation/api37-0/20260809181723-3672268/`.
- The generated emulator container, image and named AVD volume were absent
after cleanup.
## What changed from Play-delivered v2
The currently installed Google Play build is still `0.1.1 (2)`. Candidate v3
changes the live-location cancellation contract: dismissing the prominent
native disclosure or denying the permission emits an explicit cancellation
event instead of a generic technical-error event. The web UI can therefore
remain in the stopped state without falsely telling the user that location
sharing failed.
## Remaining gates
Before this candidate can replace v2 on Internal testing:
1. obtain explicit permission for the exact AAB and Internal track;
2. upload and publish version code `3` only to Internal testing;
3. install it through Google Play on the physical test phone;
4. run the strict installed-build verifier and the full physical workflow;
5. create the final foreground-location declaration video from the
Play-delivered candidate;
6. complete and verify the Play Console foreground-service/location form;
7. keep Closed and Production tracks untouched until their separate gates are
complete.