From f9e331eed28c5c0d1da6629832dab62efcbc4741 Mon Sep 17 00:00:00 2001 From: Duncan Tourolle Date: Sat, 29 Aug 2026 08:32:01 +0200 Subject: [PATCH] Let a test build be opened up, when asked MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `adb shell run-as` refuses on a release build — "package not debuggable" — and the app's private storage is then unreachable from the host. That storage is where the face shards, the thumbnail store and the catalog live, so when a device disagrees with the desktop about what it has synced there is no way to find out which of them is right. An evening was spent guessing at exactly that. `DARKROOM_DEBUGGABLE=1 ./docker/android/package.sh --install` now sets `android:debuggable` through aapt2's `--debug-mode`, and nothing else changes. Set through aapt2 rather than written into `AndroidManifest.xml` on purpose: the flag then exists only for the build that asked for it, and a release build cannot inherit it because somebody forgot to take it out again. A debuggable APK lets any process on the device read this app's files, so it belongs on a test tablet and nowhere else. Co-Authored-By: Claude Opus 5 (1M context) --- docker/android/assemble-apk.sh | 20 ++++++++++++++++++++ docker/android/package.sh | 1 + 2 files changed, 21 insertions(+) diff --git a/docker/android/assemble-apk.sh b/docker/android/assemble-apk.sh index 1fc388e..8dca2ef 100755 --- a/docker/android/assemble-apk.sh +++ b/docker/android/assemble-apk.sh @@ -139,6 +139,25 @@ fi --dir "${REPO}/apps/darkroom-android/android/res" \ -o "${OUT}/res.zip" +# `android:debuggable`, when asked for, and never otherwise. +# +# Without it `adb shell run-as` refuses — "package not debuggable" — and the +# app's own storage cannot be looked at from the host at all. That storage is +# where the face shards, the thumbnail store and the catalog live, so when a +# device disagrees with the desktop about what it has synced, there is no way +# to find out which of them is wrong. +# +# Set through aapt2 rather than in `AndroidManifest.xml` deliberately: the flag +# then exists only for the build that opted in, and a release build cannot +# inherit it by someone forgetting to take it back out again. A debuggable APK +# lets any process on the device read this app's private files, so it is a +# thing to install on a test tablet and not a thing to publish. +DEBUG_FLAG=() +if [ -n "${DARKROOM_DEBUGGABLE:-}" ]; then + echo "==> debuggable build (run-as enabled; do not publish)" + DEBUG_FLAG=(--debug-mode) +fi + "${BT}/aapt2" link \ -I "${ANDROID_JAR}" \ --manifest "${REPO}/apps/darkroom-android/android/AndroidManifest.xml" \ @@ -147,6 +166,7 @@ fi --target-sdk-version "${TARGET_API}" \ --version-name "${VERSION_NAME}" \ --version-code "${VERSION_CODE}" \ + "${DEBUG_FLAG[@]}" \ -o "${OUT}/base.apk" \ --auto-add-overlay diff --git a/docker/android/package.sh b/docker/android/package.sh index d5d14ed..61edcda 100755 --- a/docker/android/package.sh +++ b/docker/android/package.sh @@ -71,6 +71,7 @@ SO="${CACHE}/target/jniLibs/${ABI}/libdarkroom.so" echo "==> packaging APK" "${HERE}/build.sh" env \ ABI="${ABI}" RUST_TARGET="${RUST_TARGET}" \ + DARKROOM_DEBUGGABLE="${DARKROOM_DEBUGGABLE:-}" \ /work/docker/android/assemble-apk.sh # ---------------------------------------------------------------------------