#!/usr/bin/env bash set -euo pipefail ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) mapfile -d '' -t candidate_files < <( git -C "$ROOT" ls-files \ --cached \ --others \ --exclude-standard \ -z \ -- android | LC_ALL=C sort -z ) source_files=() for relative_path in "${candidate_files[@]}"; do absolute_path="$ROOT/$relative_path" # Play Console copy and artwork live beside the Android project so release # operators can find them, but Gradle never consumes them when producing an # APK or AAB. Keep the artifact fingerprint bound to binary build inputs, # not to reviewer instructions or store-listing edits. case "$relative_path" in android/README.md|android/play-store/*|android/store-assets/*) continue ;; esac # `git ls-files --cached` also reports tracked paths deleted in the working # tree. They are not inputs to the artifact being built, so exclude them # from the working-tree fingerprint instead of treating a valid deletion as # a broken source tree. if [[ ! -e "$absolute_path" && ! -L "$absolute_path" ]]; then continue fi source_files+=("$relative_path") done if [[ "${#source_files[@]}" -eq 0 ]]; then echo "No Android build input files were found." >&2 exit 1 fi { # Version the input contract so a future deliberate scope change cannot # silently compare equal to a fingerprint produced by this implementation. printf 'who-need-help-android-build-inputs-v2\0' for relative_path in "${source_files[@]}"; do absolute_path="$ROOT/$relative_path" if [[ ! -f "$absolute_path" ]]; then echo "Android build input is not a regular file: $relative_path" >&2 exit 1 fi printf '%s\0' "$relative_path" sha256sum "$absolute_path" | awk '{print $1}' done } | sha256sum | awk '{print $1}'