Files
jellytau/scripts/build-android.sh
T
dtourolle 1ba836928f fix(android): keep the debug applicationId out of Tauri's reach
`bun run android:dev` produced an APK whose applicationId was plain
com.dtourolle.jellytau, so installing it over a real release build failed
with INSTALL_FAILED_UPDATE_INCOMPATIBLE -- the only obvious way out being to
uninstall the release app and lose its data.

`tauri android build` rewrites the getByName("debug") block in the generated
copy of build.gradle.kts to inject its jniLibs.keepDebugSymbols entries. The
damage is visible in the generated file, where `packaging {` ends up with the
first injected line welded onto it. That rewrite drops applicationIdSuffix
and nothing else -- versionNameSuffix and the manifest placeholders beside it
survive -- and it happens after sync-android-sources.sh has copied the
canonical file into place and before Gradle configures, so no amount of
syncing beats it. The sideBySideRelease suffix in the release build type is
untouched by the same rewrite, which is why `build-and-deploy.sh release
--debug` kept working while the plain debug path did not.

The suffix moves to a top-level statement after the android {} block, which
is not inside what the rewriter looks for and survives. build-android.sh then
asserts the applicationId the APK actually carries, read from AGP's
output-metadata.json, so a future CLI that reaches further fails the build
instead of shipping a colliding APK.

Verified: a debug build now reports com.dtourolle.jellytau.debug, and the
statement is still there in gen/ after the CLI has run.
2026-08-25 23:48:24 +02:00

176 lines
7.2 KiB
Bash
Executable File

#!/bin/bash
# Build Android APK
set -e
# Source Rust environment
source "$HOME/.cargo/env.fish" 2>/dev/null || source "$HOME/.cargo/env" 2>/dev/null || true
# Set Android environment variables
export ANDROID_HOME="$HOME/Android/Sdk"
export NDK_HOME="$ANDROID_HOME/ndk/$(ls "$ANDROID_HOME/ndk" | head -1)"
echo "🤖 Building Android APK..."
echo "Android SDK: $ANDROID_HOME"
echo "NDK: $NDK_HOME"
echo ""
# Parse args: build type (debug/release) and optional --clean flag.
# By default the build is INCREMENTAL — Cargo and Vite reuse their caches.
# Pass --clean (or CLEAN=1) to wipe all caches for a from-scratch build.
#
# ABI selection: by default Tauri builds all four ABIs (arm64/arm/x86/x86_64),
# which is what a distributable universal APK needs — but for an on-device test
# it means three wasted Rust compiles. Pass --device (or ABI=aarch64) to build
# only the connected device's architecture; --abi <t> targets one explicitly.
#
# Side-by-side: the `debug` build type always installs as
# com.dtourolle.jellytau.debug ("JellyTau Debug"), so it never collides with a
# real install. `release --debug` puts a *release* build — R8-minified, exactly
# what ships — into that same slot, signed with the local debug keystore. That
# is how you validate minification (R8 stripping JNI-loaded classes has broken
# release APKs here before) without the real signing key and without
# uninstalling the app you actually use.
BUILD_TYPE="debug"
CLEAN="${CLEAN:-0}"
ABI="${ABI:-}"
SIDE_BY_SIDE="${SIDE_BY_SIDE:-0}"
next_is_abi=0
for arg in "$@"; do
if [ "$next_is_abi" = "1" ]; then
ABI="$arg"
next_is_abi=0
continue
fi
case "$arg" in
--clean) CLEAN=1 ;;
--abi) next_is_abi=1 ;;
--device) ABI="device" ;;
--debug|--side-by-side) SIDE_BY_SIDE=1 ;;
debug|release) BUILD_TYPE="$arg" ;;
esac
done
# The debug build type is side-by-side unconditionally; the flag only means
# something for a release build.
if [ "$BUILD_TYPE" = "debug" ]; then
SIDE_BY_SIDE=1
fi
# Resolve --device to the attached device's Rust target triple.
if [ "$ABI" = "device" ]; then
device_abi="$(adb shell getprop ro.product.cpu.abi 2>/dev/null | tr -d '\r\n')"
case "$device_abi" in
arm64-v8a) ABI="aarch64" ;;
armeabi-v7a) ABI="armv7" ;;
x86_64) ABI="x86_64" ;;
x86) ABI="i686" ;;
*)
echo "⚠️ Could not detect device ABI (got '${device_abi:-none}') — building all targets."
ABI=""
;;
esac
[ -n "$ABI" ] && echo "🎯 Device ABI $device_abi → building only '$ABI'"
fi
TARGET_ARGS=()
if [ -n "$ABI" ]; then
TARGET_ARGS=(--target "$ABI")
fi
# Step 0: Optionally clear build caches for a fully fresh build.
if [ "$CLEAN" = "1" ]; then
echo "🧹 Clearing build caches (clean build)..."
rm -rf node_modules/.vite dist .svelte-kit .next build target src-tauri/target 2>/dev/null || true
# `bun install`, NOT `npm install`. This is a bun project (see packageManager
# in package.json) and bun.lock is the lockfile that is committed; npm
# ignores it, re-resolves the tree from package.json alone, and writes a
# package-lock.json that .gitignore then hides.
#
# That is not cosmetic. The Tauri CLI refuses to build when a plugin's Rust
# crate and npm package differ by minor version, so the JS side is pinned
# exactly to match Cargo.lock; a re-resolve is precisely how those halves
# drift apart again. A clean build must not be able to change what gets
# installed.
bun install > /dev/null 2>&1
fi
# Step 1: Sync Android source files
echo "🔄 Syncing Android sources..."
./scripts/sync-android-sources.sh
# Step 2: Build the frontend first to avoid dev server issues
echo "🎨 Building frontend..."
bun run build
# Step 2: Build Android APK
# `--apk` is a boolean flag, NOT `--apk true`.
#
# tauri-cli took a value here until 2.10; from 2.11 it is a plain flag and the
# stray `true` is parsed as a positional argument, failing with
# "error: unexpected argument 'true' found" before the build starts. Found by
# deploying to a device after the Tauri 2.9.5 -> 2.11.5 upgrade.
if [ "$BUILD_TYPE" = "release" ] && [ "$SIDE_BY_SIDE" = "1" ]; then
# A release build in the debug slot: R8 still runs, but the applicationId is
# suffixed and the debug keystore signs it (read by build.gradle.kts from
# JT_SIDE_BY_SIDE), so the real key is not needed and it replaces any other
# .debug install cleanly. Deliberately does NOT write keystore.properties.
echo "📦 Building side-by-side release APK (com.dtourolle.jellytau.debug)..."
JT_SIDE_BY_SIDE=1 bun run tauri android build --apk "${TARGET_ARGS[@]}"
elif [ "$BUILD_TYPE" = "release" ]; then
# Configure release signing from .env (single source of truth). Must run
# after sync-android-sources.sh, since gen/android is (re)generated there.
./scripts/write-keystore-properties.sh
echo "📦 Building release APK..."
bun run tauri android build --apk "${TARGET_ARGS[@]}"
else
echo "📦 Building debug APK..."
bun run tauri android build --apk --debug "${TARGET_ARGS[@]}"
fi
# The applicationId the APK actually carries — not the one build.gradle.kts asks
# for. `tauri android build` rewrites the debug `buildTypes` block in the
# generated gradle file to inject its keepDebugSymbols entries, and that rewrite
# used to drop `applicationIdSuffix` with it, silently producing a debug APK
# under the release applicationId. Installing that over a real release build
# fails with INSTALL_FAILED_UPDATE_INCOMPATIBLE, whose only obvious remedy is
# uninstalling the release app and losing its data — so this fails the build
# instead. The suffix now lives outside the rewritten block (see
# src-tauri/android/app/build.gradle.kts); this checks that it survived.
assert_application_id() {
local variant="$1" expected="$2"
local metadata="src-tauri/gen/android/app/build/outputs/apk/universal/$variant/output-metadata.json"
[ -f "$metadata" ] || return 0
local actual
actual=$(sed -n 's/.*"applicationId"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$metadata" | head -1)
if [ -n "$actual" ] && [ "$actual" != "$expected" ]; then
echo ""
echo "❌ APK applicationId is '$actual', expected '$expected'."
echo " A build meant for the side-by-side slot came out under the"
echo " release applicationId; installing it would collide with a real"
echo " install. Check that the applicationIdSuffix at the bottom of"
echo " src-tauri/android/app/build.gradle.kts survived into"
echo " src-tauri/gen/android/app/build.gradle.kts."
exit 1
fi
}
if [ "$BUILD_TYPE" = "debug" ]; then
assert_application_id debug "com.dtourolle.jellytau.debug"
elif [ "$SIDE_BY_SIDE" = "1" ]; then
assert_application_id release "com.dtourolle.jellytau.debug"
else
assert_application_id release "com.dtourolle.jellytau"
fi
echo ""
echo "✅ APK build complete!"
echo "📱 APK location: src-tauri/gen/android/app/build/outputs/apk/"
# Containerised builds run as root against a bind-mounted tree; hand the
# artifacts back to the host user. No-op when not root. See DR-213.
"$(dirname "$0")/restore-ownership.sh"