Sign the APK with a real key when one is configured
🐳 Android image / Build and push (push) Successful in 3s
Build and test / android-image (push) Successful in 3s
Build and test / Desktop (Linux) (push) Successful in 21m23s
Build and test / Layer separation (push) Successful in 29s
Traceability / Requirement traces (push) Failing after 28s
Build and test / Android (aarch64) (push) Failing after 33m28s

The APK has been debug-signed with a key generated on the spot, which is
right for putting a build on a test device and useless for anything else:
a different signature every run, so nothing can ever update in place.

Four secrets now select a real signature -- ANDROID_KEYSTORE_BASE64 and
its password, alias and key password. The names are JellyTau's, because
that repo already signs its Android build this way against this same
runner and one convention across both is one thing to remember.

Absence of the secrets is not an error. A fork or a branch build has no
access to them and should still produce an installable APK, so the debug
path stays exactly as it was. The reverse is an error: if a keystore is
supplied and cannot be read, the build fails rather than quietly falling
back to a debug key, because a release that is silently debug-signed is
worse than no release.

Passwords reach apksigner and keytool as `env:`, never `pass:`. `pass:`
puts the password in the process table for anything on the box to read.
The keystore is written to a 0700 mktemp directory and never into the
workspace, which is both what actions/cache saves and what the upload
step globs.

Also: upload-artifact drops from v4 to v3. v4 was a guess about what this
Gitea supports. v3 is what JellyTau uploads its APK with on this runner
today, which makes it the version known to work rather than the one that
ought to.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-26 10:13:50 +02:00
co-authored by Claude Opus 5
parent e9b3598841
commit 40e6334bb1
3 changed files with 141 additions and 8 deletions
+42 -4
View File
@@ -19,6 +19,19 @@
# KEYSTORE signing keystore (default: $TARGET_DIR/debug.keystore)
# ABI Android ABI (default: arm64-v8a)
# RUST_TARGET Rust target triple (default: aarch64-linux-android)
#
# Signing. With none of these set the APK is debug-signed with a generated
# throwaway key, which is what a test device wants. Set all three for a real
# signature:
#
# KEYSTORE_PASS keystore password — presence of this is what selects
# release signing
# KEY_PASS key password (default: same as KEYSTORE_PASS)
# KEY_ALIAS key alias within the store
#
# The passwords are read from the environment and handed to apksigner as
# `env:`, never `pass:`. `pass:` puts the password in the process table, where
# every other process on the machine can read it out of `ps`.
set -euo pipefail
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
@@ -30,6 +43,20 @@ TARGET_DIR="$(cd "${TARGET_DIR}" && pwd)"
JNILIBS="${JNILIBS:-${TARGET_DIR}/jniLibs}"
OUT="${OUT:-${TARGET_DIR}/apk}"
KEYSTORE="${KEYSTORE:-${TARGET_DIR}/debug.keystore}"
# Release signing is selected by supplying a password, not by a flag, so there
# is no way to ask for a release build and silently get a debug one.
if [[ -n "${KEYSTORE_PASS:-}" ]]; then
SIGNING=release
KEY_ALIAS="${KEY_ALIAS:?KEY_ALIAS is required when KEYSTORE_PASS is set}"
export DR_KS_PASS="${KEYSTORE_PASS}"
export DR_KEY_PASS="${KEY_PASS:-${KEYSTORE_PASS}}"
else
SIGNING=debug
KEY_ALIAS="androiddebugkey"
export DR_KS_PASS=android
export DR_KEY_PASS=android
fi
ABI="${ABI:-arm64-v8a}"
RUST_TARGET="${RUST_TARGET:-aarch64-linux-android}"
@@ -84,11 +111,20 @@ echo " dex: ${DEX}"
# Debug-signed only. This gets the app onto a test device; it is not a release
# signature, and the store password is the Android convention rather than a
# secret worth protecting.
if [[ ! -f "${KEYSTORE}" ]]; then
if [[ "${SIGNING}" == "release" ]]; then
# Never generated on demand. A release key is created once, by hand, and
# kept; conjuring one here would mean every build signed by a different
# identity, which is indistinguishable from having no signing story at all.
[[ -f "${KEYSTORE}" ]] || {
echo "error: KEYSTORE_PASS is set but ${KEYSTORE} does not exist" >&2
exit 1
}
echo " signing with the release key (alias ${KEY_ALIAS})"
elif [[ ! -f "${KEYSTORE}" ]]; then
echo " generating debug keystore"
mkdir -p "$(dirname "${KEYSTORE}")"
keytool -genkeypair -keystore "${KEYSTORE}" -alias androiddebugkey \
-storepass android -keypass android \
keytool -genkeypair -keystore "${KEYSTORE}" -alias "${KEY_ALIAS}" \
-storepass:env DR_KS_PASS -keypass:env DR_KEY_PASS \
-keyalg RSA -keysize 2048 -validity 10950 \
-dname "CN=Android Debug,O=Android,C=US" >/dev/null 2>&1
fi
@@ -129,10 +165,12 @@ zip -q -X "${OUT}/unaligned.apk" classes.dex
# invalidates the signature.
"${BT}/zipalign" -p -f 4 "${OUT}/unaligned.apk" "${OUT}/darkroom.apk"
"${BT}/apksigner" sign \
--ks "${KEYSTORE}" --ks-pass pass:android --key-pass pass:android \
--ks "${KEYSTORE}" --ks-key-alias "${KEY_ALIAS}" \
--ks-pass env:DR_KS_PASS --key-pass env:DR_KEY_PASS \
--min-sdk-version "${MIN_API}" \
"${OUT}/darkroom.apk"
"${BT}/apksigner" verify --print-certs "${OUT}/darkroom.apk" | head -2
echo " signing: ${SIGNING}"
# The intermediates are not the artefact, and leaving them beside it invites
# the wrong file being picked up by a glob.