Let a test build be opened up, when asked
`adb shell run-as` refuses on a release build — "package not debuggable" — and the app's private storage is then unreachable from the host. That storage is where the face shards, the thumbnail store and the catalog live, so when a device disagrees with the desktop about what it has synced there is no way to find out which of them is right. An evening was spent guessing at exactly that. `DARKROOM_DEBUGGABLE=1 ./docker/android/package.sh --install` now sets `android:debuggable` through aapt2's `--debug-mode`, and nothing else changes. Set through aapt2 rather than written into `AndroidManifest.xml` on purpose: the flag then exists only for the build that asked for it, and a release build cannot inherit it because somebody forgot to take it out again. A debuggable APK lets any process on the device read this app's files, so it belongs on a test tablet and nowhere else. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -139,6 +139,25 @@ fi
|
||||
--dir "${REPO}/apps/darkroom-android/android/res" \
|
||||
-o "${OUT}/res.zip"
|
||||
|
||||
# `android:debuggable`, when asked for, and never otherwise.
|
||||
#
|
||||
# Without it `adb shell run-as` refuses — "package not debuggable" — and the
|
||||
# app's own storage cannot be looked at from the host at all. That storage is
|
||||
# where the face shards, the thumbnail store and the catalog live, so when a
|
||||
# device disagrees with the desktop about what it has synced, there is no way
|
||||
# to find out which of them is wrong.
|
||||
#
|
||||
# Set through aapt2 rather than in `AndroidManifest.xml` deliberately: the flag
|
||||
# then exists only for the build that opted in, and a release build cannot
|
||||
# inherit it by someone forgetting to take it back out again. A debuggable APK
|
||||
# lets any process on the device read this app's private files, so it is a
|
||||
# thing to install on a test tablet and not a thing to publish.
|
||||
DEBUG_FLAG=()
|
||||
if [ -n "${DARKROOM_DEBUGGABLE:-}" ]; then
|
||||
echo "==> debuggable build (run-as enabled; do not publish)"
|
||||
DEBUG_FLAG=(--debug-mode)
|
||||
fi
|
||||
|
||||
"${BT}/aapt2" link \
|
||||
-I "${ANDROID_JAR}" \
|
||||
--manifest "${REPO}/apps/darkroom-android/android/AndroidManifest.xml" \
|
||||
@@ -147,6 +166,7 @@ fi
|
||||
--target-sdk-version "${TARGET_API}" \
|
||||
--version-name "${VERSION_NAME}" \
|
||||
--version-code "${VERSION_CODE}" \
|
||||
"${DEBUG_FLAG[@]}" \
|
||||
-o "${OUT}/base.apk" \
|
||||
--auto-add-overlay
|
||||
|
||||
|
||||
@@ -71,6 +71,7 @@ SO="${CACHE}/target/jniLibs/${ABI}/libdarkroom.so"
|
||||
echo "==> packaging APK"
|
||||
"${HERE}/build.sh" env \
|
||||
ABI="${ABI}" RUST_TARGET="${RUST_TARGET}" \
|
||||
DARKROOM_DEBUGGABLE="${DARKROOM_DEBUGGABLE:-}" \
|
||||
/work/docker/android/assemble-apk.sh
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user