who_need_help/docs/google-play-release-candidate-2026-08-09-v3.md

3.9 KiB

Google Play Internal candidate v3 — 2026-08-09

This record binds the locally prepared third Internal testing candidate to the exact committed source and observed verification evidence. It does not claim that Google Play has accepted or delivered this build.

Source and artifacts

  • Source commit: cd154766a06bb1febb0598fb3f53db78628bd7f6
  • Source fingerprint: 70529d3befcb0818f0b79f7869389b4fad432eb2911be08d52342529b7f22614
  • Package: org.whoneedhelp.mobile
  • Version: 0.1.2 (3)
  • Intended Internal release label: 0.1.2 Location consent clarity
  • Artifact directory: android/dist-release-20260809-v3/
  • Release APK SHA-256: 32132ee85b58e2f719b11d004dd7f5896bfde3b01372ad0b3293bf7bcbe79193
  • Play AAB SHA-256: 5f1b63d02467ce63af795d16459a75693e415426478e0788b83f0f6d35dff922
  • Universal APK SHA-256: b2bcb19d96c42621a5001a6b682edcb6d27aa3932ec334f0e93b0b7f20817393
  • Universal APKS SHA-256: b7024006c27c5d4878cad95b8c9dc2eb2e1038aa713c9dbf719a51eccfa1a497

The build used a temporary mode-0600 copy of the production Android configuration with only the candidate version changed to 0.1.2 (3). The temporary file was removed by the isolated build unit. The development .env, production server and frozen hackathon test deployment were not changed.

Release pipeline evidence

The source-bound release pipeline completed successfully:

  • production Android environment and App Links identity validation;
  • release unit tests;
  • release lint;
  • R8 code shrinking and resource shrinking;
  • release APK and AAB assembly;
  • APK signing-certificate verification;
  • AAB JAR-signature verification;
  • bundletool AAB validation and universal APK generation;
  • package-name and production-origin verification;
  • exported source fingerprint comparison with the current committed source.

The isolated build unit was codex-heavy-wnh-android-release-v3-20260809-20260809-211532-3613142.service. It completed successfully in 37.450 seconds with a 154 MiB unit memory peak; Docker build workers are accounted for by the Docker service rather than this client unit.

Instrumentation evidence

The current source passed API 37 instrumentation in the isolated unit codex-heavy-wnh-android-instrumentation-api37-v3-20260809-211723-3671839.service.

  • Main instrumentation: OK (10 tests) in 71.145 seconds.
  • The suite covered loading state, denied permission, web geolocation, disclosure cancellation, App Link recreation/update, foreground location posting and notification Stop, network retry, Home/activity destruction and main-page retry.
  • The process-death probe intentionally killed the instrumented app after the foreground service appeared. The harness verified that the non-sticky service and persistent notification did not remain.
  • Evidence directory: output/android-instrumentation/api37-0/20260809181723-3672268/.
  • The generated emulator container, image and named AVD volume were absent after cleanup.

What changed from Play-delivered v2

The currently installed Google Play build is still 0.1.1 (2). Candidate v3 changes the live-location cancellation contract: dismissing the prominent native disclosure or denying the permission emits an explicit cancellation event instead of a generic technical-error event. The web UI can therefore remain in the stopped state without falsely telling the user that location sharing failed.

Remaining gates

Before this candidate can replace v2 on Internal testing:

  1. obtain explicit permission for the exact AAB and Internal track;
  2. upload and publish version code 3 only to Internal testing;
  3. install it through Google Play on the physical test phone;
  4. run the strict installed-build verifier and the full physical workflow;
  5. create the final foreground-location declaration video from the Play-delivered candidate;
  6. complete and verify the Play Console foreground-service/location form;
  7. keep Closed and Production tracks untouched until their separate gates are complete.