diff --git a/docker/android/assemble-apk.sh b/docker/android/assemble-apk.sh index 1fc388e..8dca2ef 100755 --- a/docker/android/assemble-apk.sh +++ b/docker/android/assemble-apk.sh @@ -139,6 +139,25 @@ fi --dir "${REPO}/apps/darkroom-android/android/res" \ -o "${OUT}/res.zip" +# `android:debuggable`, when asked for, and never otherwise. +# +# Without it `adb shell run-as` refuses — "package not debuggable" — and the +# app's own storage cannot be looked at from the host at all. That storage is +# where the face shards, the thumbnail store and the catalog live, so when a +# device disagrees with the desktop about what it has synced, there is no way +# to find out which of them is wrong. +# +# Set through aapt2 rather than in `AndroidManifest.xml` deliberately: the flag +# then exists only for the build that opted in, and a release build cannot +# inherit it by someone forgetting to take it back out again. A debuggable APK +# lets any process on the device read this app's private files, so it is a +# thing to install on a test tablet and not a thing to publish. +DEBUG_FLAG=() +if [ -n "${DARKROOM_DEBUGGABLE:-}" ]; then + echo "==> debuggable build (run-as enabled; do not publish)" + DEBUG_FLAG=(--debug-mode) +fi + "${BT}/aapt2" link \ -I "${ANDROID_JAR}" \ --manifest "${REPO}/apps/darkroom-android/android/AndroidManifest.xml" \ @@ -147,6 +166,7 @@ fi --target-sdk-version "${TARGET_API}" \ --version-name "${VERSION_NAME}" \ --version-code "${VERSION_CODE}" \ + "${DEBUG_FLAG[@]}" \ -o "${OUT}/base.apk" \ --auto-add-overlay diff --git a/docker/android/package.sh b/docker/android/package.sh index d5d14ed..61edcda 100755 --- a/docker/android/package.sh +++ b/docker/android/package.sh @@ -71,6 +71,7 @@ SO="${CACHE}/target/jniLibs/${ABI}/libdarkroom.so" echo "==> packaging APK" "${HERE}/build.sh" env \ ABI="${ABI}" RUST_TARGET="${RUST_TARGET}" \ + DARKROOM_DEBUGGABLE="${DARKROOM_DEBUGGABLE:-}" \ /work/docker/android/assemble-apk.sh # ---------------------------------------------------------------------------