Skip to content

Commit 787f6ab

Browse files
committed
fix(android): sign local release builds by default
1 parent ea8a243 commit 787f6ab

3 files changed

Lines changed: 16 additions & 19 deletions

File tree

‎src/apps/mobile/AGENTS.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -92,9 +92,10 @@ UiState or an Intent declared there, and no module above it is visible to them.
9292
the local SDK path and is not committed.
9393
- The Android app builds from `android/`: `./gradlew :app:assembleDebug` and
9494
`:app:installDebug`; release verification is `./gradlew :app:assembleRelease`.
95-
Release signing is enabled only when all four `OPENBITFUN_ANDROID_KEYSTORE`,
95+
Release builds use the standard local Android debug keystore when formal
96+
signing credentials are absent; all four `OPENBITFUN_ANDROID_KEYSTORE`,
9697
`OPENBITFUN_ANDROID_KEYSTORE_PASSWORD`, `OPENBITFUN_ANDROID_KEY_ALIAS`, and
97-
`OPENBITFUN_ANDROID_KEY_PASSWORD` environment variables are present. Signing
98+
`OPENBITFUN_ANDROID_KEY_PASSWORD` environment variables override it. Signing
9899
files and values must never be committed. AGP 9 compiles Kotlin itself — applying
99100
`org.jetbrains.kotlin.android` is an error, not a no-op, and
100101
`kotlin { jvmToolchain(...) }` is no longer available in an app module.

‎src/apps/mobile/android/README.md‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,18 @@ Build a debug artifact with:
1313
JAVA_HOME='/Applications/Android Studio.app/Contents/jbr/Contents/Home' ./gradlew :app:assembleDebug
1414
```
1515

16-
An unsigned release is available only for local inspection and must be
17-
requested explicitly:
16+
Release builds use the standard Android debug keystore by default when formal
17+
release signing credentials are not configured. This keeps locally packaged
18+
APKs installable and upgrade-compatible with other APKs signed by the same
19+
local debug keystore.
20+
21+
For a deliberately unsigned artifact used only for local inspection, request
22+
it explicitly:
1823

1924
```bash
2025
JAVA_HOME='/Applications/Android Studio.app/Contents/jbr/Contents/Home' ./gradlew -PallowUnsignedRelease=true :app:assembleRelease
2126
```
2227

23-
For a signed release, set `OPENBITFUN_ANDROID_KEYSTORE`,
28+
For a release signed with a formal keystore, set `OPENBITFUN_ANDROID_KEYSTORE`,
2429
`OPENBITFUN_ANDROID_KEYSTORE_PASSWORD`, `OPENBITFUN_ANDROID_KEY_ALIAS`, and
2530
`OPENBITFUN_ANDROID_KEY_PASSWORD`. Release builds enable R8 and resource shrinking.

‎src/apps/mobile/android/app/build.gradle.kts‎

Lines changed: 5 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -19,19 +19,6 @@ val allowUnsignedRelease = providers.gradleProperty("allowUnsignedRelease")
1919
.map { it.equals("true", ignoreCase = true) }
2020
.orElse(false)
2121
.get()
22-
val releaseTaskRequested = gradle.startParameter.taskNames.any {
23-
it.contains("release", ignoreCase = true)
24-
}
25-
26-
if (releaseTaskRequested && !hasReleaseSigning && !allowUnsignedRelease) {
27-
throw GradleException(
28-
"Release signing credentials are missing. Set OPENBITFUN_ANDROID_KEYSTORE, " +
29-
"OPENBITFUN_ANDROID_KEYSTORE_PASSWORD, OPENBITFUN_ANDROID_KEY_ALIAS, and " +
30-
"OPENBITFUN_ANDROID_KEY_PASSWORD, or explicitly pass " +
31-
"-PallowUnsignedRelease=true for a non-distributable local artifact.",
32-
)
33-
}
34-
3522
android {
3623
sourceSets.getByName("main").assets.srcDir(file("../../../../shared/terminal/webview/generated"))
3724
namespace = "com.openbitfun.mobile.app"
@@ -76,7 +63,11 @@ android {
7663
getDefaultProguardFile("proguard-android-optimize.txt"),
7764
"proguard-rules.pro",
7865
)
79-
signingConfig = signingConfigs.findByName("release")
66+
signingConfig = when {
67+
hasReleaseSigning -> signingConfigs.getByName("release")
68+
allowUnsignedRelease -> null
69+
else -> signingConfigs.getByName("debug")
70+
}
8071
}
8172
}
8273
}

0 commit comments

Comments
 (0)