diff --git a/docker/android/package.sh b/docker/android/package.sh index 7c8fa1b..f23de76 100755 --- a/docker/android/package.sh +++ b/docker/android/package.sh @@ -68,11 +68,36 @@ SO="${CACHE}/target/jniLibs/${ABI}/libdarkroom.so" # at /work and the cache's target directory at /work/target-android, so every # default in that script already points at the right place. # --------------------------------------------------------------------------- +# +# Release signing, when asked for. assemble-apk.sh selects it by the presence +# of KEYSTORE_PASS (see its header), and the keystore has to be reachable from +# inside the container, so a host path in KEYSTORE is copied under the mounted +# target directory for the duration of the build and removed after. The +# passwords travel as environment, never as arguments -- docs/android-signing.md +# has the incantation. +# --------------------------------------------------------------------------- echo "==> packaging APK" +SIGNING_ENV=() +CONTAINER_KEYSTORE="" +if [[ -n "${KEYSTORE_PASS:-}" ]]; then + [[ -f "${KEYSTORE:-}" ]] || { echo "error: KEYSTORE_PASS is set but KEYSTORE is not a file" >&2; exit 1; } + install -m 600 "${KEYSTORE}" "${CACHE}/target/release.keystore" + CONTAINER_KEYSTORE="${CACHE}/target/release.keystore" + SIGNING_ENV=( + KEYSTORE=/work/target-android/release.keystore + KEYSTORE_PASS="${KEYSTORE_PASS}" + KEY_PASS="${KEY_PASS:-${KEYSTORE_PASS}}" + KEY_ALIAS="${KEY_ALIAS:?KEY_ALIAS is required when KEYSTORE_PASS is set}" + ) +fi "${HERE}/build.sh" env \ ABI="${ABI}" RUST_TARGET="${RUST_TARGET}" \ DARKROOM_DEBUGGABLE="${DARKROOM_DEBUGGABLE:-}" \ + "${SIGNING_ENV[@]}" \ /work/docker/android/assemble-apk.sh +if [[ -n "${CONTAINER_KEYSTORE}" ]]; then + rm -f "${CONTAINER_KEYSTORE}" +fi # --------------------------------------------------------------------------- # 3. Install from the host. diff --git a/docs/android-signing.md b/docs/android-signing.md index 2bffe84..e9a61d4 100644 --- a/docs/android-signing.md +++ b/docs/android-signing.md @@ -35,6 +35,22 @@ beyond telling everybody to uninstall and reinstall. line, which keeps them out of shell history. Back the `.jks` up somewhere that is not this repository and not the machine that builds it. +**The key exists, since 2026-09-11.** It was made as above, with a random +password, and the four secrets are loaded. The local copy is at +`~/.config/darkroom/signing/` on the development desktop — `darkroom-release.jks` +beside `storepass` and `keypass`, all mode 600 in a mode 700 directory. That +copy is what `package.sh` can sign with locally: + + D=~/.config/darkroom/signing + KEYSTORE="$D/darkroom-release.jks" KEYSTORE_PASS="$(cat "$D/storepass")" \ + KEY_ALIAS=darkroom ./docker/android/package.sh --install + +Before it existed, every build — CI and local alike — was signed with a +throwaway debug key, and a debug key is exactly as durable as the cache +directory it lives in: the local one was regenerated the night the cache was +cleared, at which point no build anywhere could install over the device's copy. +Any device that received a build from before this date has to uninstall once. + ## Loading the secrets base64 -w0 darkroom-release.jks > /tmp/ks.b64