diff --git a/src/apps/mobile/AGENTS.md b/src/apps/mobile/AGENTS.md index 3f2fdbe9b1..1622b68c9f 100644 --- a/src/apps/mobile/AGENTS.md +++ b/src/apps/mobile/AGENTS.md @@ -92,9 +92,10 @@ UiState or an Intent declared there, and no module above it is visible to them. the local SDK path and is not committed. - The Android app builds from `android/`: `./gradlew :app:assembleDebug` and `:app:installDebug`; release verification is `./gradlew :app:assembleRelease`. - Release signing is enabled only when all four `OPENBITFUN_ANDROID_KEYSTORE`, + Release builds use the standard local Android debug keystore when formal + signing credentials are absent; all four `OPENBITFUN_ANDROID_KEYSTORE`, `OPENBITFUN_ANDROID_KEYSTORE_PASSWORD`, `OPENBITFUN_ANDROID_KEY_ALIAS`, and - `OPENBITFUN_ANDROID_KEY_PASSWORD` environment variables are present. Signing + `OPENBITFUN_ANDROID_KEY_PASSWORD` environment variables override it. Signing files and values must never be committed. AGP 9 compiles Kotlin itself — applying `org.jetbrains.kotlin.android` is an error, not a no-op, and `kotlin { jvmToolchain(...) }` is no longer available in an app module. diff --git a/src/apps/mobile/android/README.md b/src/apps/mobile/android/README.md index 5ffe58d78c..6e6f7aff06 100644 --- a/src/apps/mobile/android/README.md +++ b/src/apps/mobile/android/README.md @@ -13,13 +13,18 @@ Build a debug artifact with: JAVA_HOME='/Applications/Android Studio.app/Contents/jbr/Contents/Home' ./gradlew :app:assembleDebug ``` -An unsigned release is available only for local inspection and must be -requested explicitly: +Release builds use the standard Android debug keystore by default when formal +release signing credentials are not configured. This keeps locally packaged +APKs installable and upgrade-compatible with other APKs signed by the same +local debug keystore. + +For a deliberately unsigned artifact used only for local inspection, request +it explicitly: ```bash JAVA_HOME='/Applications/Android Studio.app/Contents/jbr/Contents/Home' ./gradlew -PallowUnsignedRelease=true :app:assembleRelease ``` -For a signed release, set `OPENBITFUN_ANDROID_KEYSTORE`, +For a release signed with a formal keystore, set `OPENBITFUN_ANDROID_KEYSTORE`, `OPENBITFUN_ANDROID_KEYSTORE_PASSWORD`, `OPENBITFUN_ANDROID_KEY_ALIAS`, and `OPENBITFUN_ANDROID_KEY_PASSWORD`. Release builds enable R8 and resource shrinking. diff --git a/src/apps/mobile/android/app/build.gradle.kts b/src/apps/mobile/android/app/build.gradle.kts index 34937851c1..6965bb3dcf 100644 --- a/src/apps/mobile/android/app/build.gradle.kts +++ b/src/apps/mobile/android/app/build.gradle.kts @@ -19,19 +19,6 @@ val allowUnsignedRelease = providers.gradleProperty("allowUnsignedRelease") .map { it.equals("true", ignoreCase = true) } .orElse(false) .get() -val releaseTaskRequested = gradle.startParameter.taskNames.any { - it.contains("release", ignoreCase = true) -} - -if (releaseTaskRequested && !hasReleaseSigning && !allowUnsignedRelease) { - throw GradleException( - "Release signing credentials are missing. Set OPENBITFUN_ANDROID_KEYSTORE, " + - "OPENBITFUN_ANDROID_KEYSTORE_PASSWORD, OPENBITFUN_ANDROID_KEY_ALIAS, and " + - "OPENBITFUN_ANDROID_KEY_PASSWORD, or explicitly pass " + - "-PallowUnsignedRelease=true for a non-distributable local artifact.", - ) -} - android { sourceSets.getByName("main").assets.srcDir(file("../../../../shared/terminal/webview/generated")) namespace = "com.openbitfun.mobile.app" @@ -76,7 +63,11 @@ android { getDefaultProguardFile("proguard-android-optimize.txt"), "proguard-rules.pro", ) - signingConfig = signingConfigs.findByName("release") + signingConfig = when { + hasReleaseSigning -> signingConfigs.getByName("release") + allowUnsignedRelease -> null + else -> signingConfigs.getByName("debug") + } } } }