who_need_help/docs/google-play-release-candidate-2026-08-03.md

117 lines
5.7 KiB
Markdown

# Google Play release candidate — 2026-08-03
This document identifies the exact locally validated artifact intended for the
first Google Play upload. It contains no credentials or private signing-key
material.
## Upload artifact
- File: `android/dist-release-20260803-162910/who-need-help-release.aab`
- SHA-256: `03d39a9a08e9ca7569caccf1c7bd75e9349f7655935e7bbf23d1998cd37b3837`
- Package: `org.whoneedhelp.mobile`
- Version code: `1`
- Version name: `0.1.0`
- Minimum SDK: `24`
- Target SDK: `37`
- Source fingerprint:
`f2f281210d11465d8f7fda20a78d1ed2527660d2e8a10a29ed31bf031a29ce43`
The source fingerprint stored next to the artifact matched a fresh local
fingerprint after the build.
## Upload certificate
- SHA-256:
`A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB`
- SHA-1:
`8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C`
This upload certificate is not a Google Play App Signing certificate. After
the first upload, record every Play-generated signing certificate separately
and add every applicable fingerprint to production Google/Firebase
configuration and the production App Links association. Current Play signing
can expose multiple identities for quantum-ready hybrid signing, so the live
Console is authoritative; do not assume that there will be only one Play
SHA-256 fingerprint.
## Validation evidence
- `bundletool` validation passed.
- Release unit tests and Android lint passed; the lint report contains no
errors or warnings.
- R8 release build completed successfully.
- APK and AAB signing verification passed.
- The native disclosure shown immediately before Android location permission
explains collection and transmission of precise location, background use
while the app is minimized or not in use, the persistent notification, the
Stop action, raw-location deletion, and retained summary safety evidence.
- Universal APK generated from this AAB:
`android/dist-release-20260803-162910/who-need-help-release-universal.apk`
- Universal APK SHA-256:
`d079a42809155faa86da72281c985f01d4134097e4410cdfbf244869b3027d21`
- The bundletool archive SHA-256 is
`9e9d034c44e55c22bc6d6e7ac3b294e5339ee808170fe0f6c80b1307f9de5907`.
- The release APK SHA-256 is
`e40f72558aa8b0c94ad917ff885618ba56199acf5dd2beb2f331305f0748f5d2`.
- The release APK was installed over the existing production package on the
authorised physical Android 16 / API 36 device without deleting app data.
- Physical-device evidence is stored in
`output/android-physical-release/20260803-1934-policy/` and
`output/android-physical-release/20260803-1934-policy-clean/`. The production
home and Safety pages rendered without visible cropping or overlap.
- `https://whoneedhelp.com/safety` was delivered to
`org.whoneedhelp.mobile/.MainActivity` by an implicit Android App Link intent
and rendered in the installed app. Android reported the domain as verified,
delivered the intent to `org.whoneedhelp.mobile/.MainActivity`, and completed
the clean cold App Link launch in 654 ms.
- A PID-scoped log captured after the clean launch contained no application
crash, AndroidRuntime, TLS/SSL, or WebView load error. An earlier diagnostic
run crashed Android's separate `UiAutomation` process; the application
remained running and that tool crash is not counted as app evidence.
- The complete repository quality run passed 443 ExUnit tests and 14 browser
dependency tests, plus compiler, format, xref, Credo, Sobelow, Dialyzer,
dependency audit, container, Compose, Helm, migration, rollback,
observability, and image-security gates.
- The final runtime image scan reported zero detected vulnerabilities.
## Current Play Console state
The verified personal developer account contains the Who Need Help application
with Play application ID `4972430103169452589`. Play App Signing was accepted.
Google Play accepted the exact version-code `1` AAB identified above as release
`0.1.0 internal verification`, and that release is active only on the Internal
testing track. No Closed or Production rollout has been created or started.
Every Play App Signing SHA-1 and SHA-256 identity displayed for the accepted
artifact is retained in the ignored mode-`0600` provider inventory. Production
Firebase, Google OAuth, and Android App Links were reconciled with those
identities without removing the independent upload identity.
The exact release label, localized notes, pre-publication checks, and
post-publication sequence are frozen in
`android/play-store/internal-release-v1.md`.
The remaining Console sequence is:
1. Keep the accepted version-code `1` Internal release unchanged while its
verified device evidence remains the release baseline.
2. Complete the prepared store listing and App content sections using
`android/play-store/` and `android/store-assets/`, including the mandatory
location foreground-service declaration and demonstration video described
in `android/play-store/location-and-fgs-declaration.md`.
3. Start a closed test with at least 12 continuously opted-in testers for at
least 14 days before requesting production access.
The Play-delivered Internal build has already passed physical-device checks for
Google sign-in, verified App Links, production FCM, user-started foreground
location sharing while minimized, the notification Stop action, offline
recovery, and process recreation. Exact evidence and cleanup are recorded in
`docs/verification.md`.
Official references:
- https://support.google.com/googleplay/android-developer/answer/9859152
- https://support.google.com/googleplay/android-developer/answer/9842756
- https://support.google.com/googleplay/android-developer/answer/9845334
- https://support.google.com/googleplay/android-developer/answer/14151465