mirror of
https://github.com/sune-org/sune.git
synced 2026-10-08 20:15:19 +00:00
Add Android APK release workflow
Bubblewrap TWA config for chat.sune, plus a manually dispatched workflow that builds, signs, verifies against assetlinks.json, attests provenance and publishes the release for the tag given as input. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,139 @@
|
||||
name: Release APK
|
||||
run-name: Release APK ${{ inputs.version }}
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
version:
|
||||
description: 'Release tag to create, e.g. v1.0.0'
|
||||
required: true
|
||||
type: string
|
||||
|
||||
concurrency: release-apk
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
apk:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
permissions:
|
||||
contents: write # create the tag + release
|
||||
id-token: write # sign the build attestation
|
||||
attestations: write
|
||||
env:
|
||||
TAG: ${{ inputs.version }}
|
||||
steps:
|
||||
- name: Validate version
|
||||
run: |
|
||||
[[ "$TAG" =~ ^v([0-9]+)\.([0-9]+)\.([0-9]+)$ ]] || { echo "::error::version must look like v1.0.0"; exit 1; }
|
||||
MA=${BASH_REMATCH[1]} MI=${BASH_REMATCH[2]} PA=${BASH_REMATCH[3]}
|
||||
(( MI < 100 && PA < 100 )) || { echo "::error::minor and patch must be < 100"; exit 1; }
|
||||
echo "VERSION=${TAG#v}" >> $GITHUB_ENV
|
||||
echo "CODE=$((MA*10000 + MI*100 + PA))" >> $GITHUB_ENV
|
||||
echo "APK=sune-$TAG.apk" >> $GITHUB_ENV
|
||||
echo "BT=$RUNNER_TEMP/sdk/build-tools/36.1.0" >> $GITHUB_ENV
|
||||
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Fail if the release already exists
|
||||
if: github.ref == 'refs/heads/master'
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
|
||||
echo "::error::$TAG already exists"; exit 1
|
||||
fi
|
||||
|
||||
- uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
|
||||
with:
|
||||
distribution: temurin
|
||||
java-version: 17
|
||||
|
||||
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 22
|
||||
|
||||
- name: Install Android SDK + Bubblewrap
|
||||
run: |
|
||||
SDK=$RUNNER_TEMP/sdk
|
||||
mkdir -p "$SDK/bin" # bubblewrap only checks that this exists
|
||||
SM=$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager
|
||||
yes | "$SM" --sdk_root="$SDK" --licenses >/dev/null || true # yes exits on SIGPIPE
|
||||
"$SM" --sdk_root="$SDK" "build-tools;36.1.0" "platforms;android-36" >/dev/null
|
||||
npm install --global --ignore-scripts @bubblewrap/cli@1.25.0
|
||||
mkdir -p ~/.bubblewrap
|
||||
jq -n --arg jdk "$JAVA_HOME" --arg sdk "$SDK" '{jdkPath:$jdk,androidSdkPath:$sdk}' > ~/.bubblewrap/config.json
|
||||
|
||||
- name: Build + sign
|
||||
env:
|
||||
ANDROID_KEYSTORE_B64: ${{ secrets.ANDROID_KEYSTORE_B64 }}
|
||||
ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
|
||||
BUBBLEWRAP_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASS }}
|
||||
BUBBLEWRAP_KEY_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASS }}
|
||||
run: |
|
||||
B=$RUNNER_TEMP/build OUT=$RUNNER_TEMP/out
|
||||
mkdir -p "$B" "$OUT"
|
||||
echo "$ANDROID_KEYSTORE_B64" | base64 -d > "$B/sune.jks"
|
||||
# pin the icon to this exact commit instead of whatever the site serves today
|
||||
ICON="https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/public/appstore_content/%E2%9C%BA.png"
|
||||
jq --arg v "$VERSION" --argjson c "$CODE" --arg a "$ANDROID_KEY_ALIAS" --arg i "$ICON" \
|
||||
'.appVersion=$v | .appVersionCode=$c | .signingKey.alias=$a | .iconUrl=$i | .maskableIconUrl=$i' \
|
||||
android/twa-manifest.json > "$B/twa-manifest.json"
|
||||
cd "$B"
|
||||
bubblewrap update --manifest ./twa-manifest.json --skipVersionUpgrade
|
||||
bubblewrap build --manifest ./twa-manifest.json --skipPwaValidation
|
||||
mv app-release-signed.apk "$OUT/$APK"
|
||||
rm -f sune.jks
|
||||
echo "OUT=$OUT" >> $GITHUB_ENV
|
||||
|
||||
- name: Verify the APK
|
||||
run: |
|
||||
cd "$OUT"
|
||||
"$BT/apksigner" verify --verbose --print-certs "$APK" | tee verify.txt
|
||||
grep -q "Number of signers: 1" verify.txt
|
||||
GOT=$(sed -n 's/.*certificate SHA-256 digest: //p' verify.txt | sed -n 1p)
|
||||
WANT=$(jq -r '.[].target | select(.package_name=="chat.sune") | .sha256_cert_fingerprints[]' "$GITHUB_WORKSPACE/public/.well-known/assetlinks.json" | tr -d ':' | tr A-F a-f)
|
||||
[ "$GOT" = "$WANT" ] || { echo "::error::signing cert $GOT does not match assetlinks.json ($WANT)"; exit 1; }
|
||||
"$BT/aapt2" dump badging "$APK" > full-badging.txt
|
||||
grep -m1 '^package:' full-badging.txt | tee badging.txt
|
||||
grep -q "name='chat.sune' versionCode='$CODE' versionName='$VERSION'" badging.txt
|
||||
sha256sum "$APK" | tee "$APK.sha256"
|
||||
echo "SIGNER=$GOT" >> $GITHUB_ENV
|
||||
|
||||
- name: Attest build provenance
|
||||
if: github.ref == 'refs/heads/master'
|
||||
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
|
||||
with:
|
||||
subject-path: ${{ runner.temp }}/out/sune-${{ inputs.version }}.apk
|
||||
|
||||
- name: Publish release
|
||||
if: github.ref == 'refs/heads/master'
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
cd "$OUT"
|
||||
SHA=$(cut -d' ' -f1 "$APK.sha256")
|
||||
cat > notes.md <<EOF
|
||||
Built and signed by GitHub Actions from commit \`$GITHUB_SHA\` ([workflow run]($GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID)). Nobody handled the file in between.
|
||||
|
||||
Verify a download:
|
||||
\`\`\`
|
||||
gh attestation verify $APK --repo $GITHUB_REPOSITORY
|
||||
\`\`\`
|
||||
|
||||
- Package: \`chat.sune\`
|
||||
- SHA-256: \`$SHA\`
|
||||
- Signing certificate SHA-256: \`$SIGNER\`
|
||||
EOF
|
||||
gh release create "$TAG" "$APK" "$APK.sha256" --repo "$GITHUB_REPOSITORY" --target "$GITHUB_SHA" --title "Sune $TAG" --notes-file notes.md
|
||||
|
||||
- name: Keep the APK as a workflow artifact (non-release runs)
|
||||
if: github.ref != 'refs/heads/master'
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: ${{ env.APK }}
|
||||
path: ${{ runner.temp }}/out/*.apk
|
||||
retention-days: 3
|
||||
@@ -0,0 +1,37 @@
|
||||
# Android app
|
||||
|
||||
Sune for Android is a [Trusted Web Activity](https://developer.chrome.com/docs/android/trusted-web-activity) wrapper around https://sune.chat, built with [Bubblewrap](https://github.com/GoogleChromeLabs/bubblewrap). It contains no app code, only the config in `twa-manifest.json`.
|
||||
|
||||
| | New app | Legacy app (v0.x) |
|
||||
|---|---|---|
|
||||
| Package | `chat.sune` | `com.planetrenox.sune` |
|
||||
| Host | `sune.chat` (also trusts `sune.planetrenox.com`) | `sune.planetrenox.com` |
|
||||
| Signing cert SHA-256 | `09:85:1F:7B:BB:40:67:9C:F8:70:1C:7D:9F:65:72:77:78:0E:C0:58:CF:34:09:9A:97:D2:8A:74:FB:CE:87:2A` | `E8:7D:70:60:C2:7D:EF:CB:4D:4D:2B:E2:2E:5E:37:ED:F7:0B:1E:F5:77:D7:04:1F:6B:07:EC:B8:1D:78:6D:43` (**leaked**) |
|
||||
|
||||
Both are listed for both domains in [`public/.well-known/assetlinks.json`](../public/.well-known/assetlinks.json); that file is what makes Chrome hide the address bar. Remove the legacy entry once nobody uses the old app (a leaked key can sign a fake `com.planetrenox.sune` that Chrome would trust).
|
||||
|
||||
## Releasing
|
||||
|
||||
Actions → **Release APK** → Run workflow on `master` → enter the tag, e.g. `v1.0.0`.
|
||||
|
||||
It builds `sune-v1.0.0.apk`, signs it, checks the signing cert against `assetlinks.json`, attests build provenance, then creates the tag and release. `versionCode` is `major*10000 + minor*100 + patch`. Run it from any other branch to do a dry run: it builds and verifies but publishes nothing.
|
||||
|
||||
## Verifying a download
|
||||
|
||||
```bash
|
||||
gh attestation verify sune-v1.0.0.apk --repo sune-org/sune
|
||||
```
|
||||
|
||||
This proves the file was built by this repo's workflow at the commit named in the release, and not modified since. The APK is only a wrapper; the app itself is served live from sune.chat and is not covered by it.
|
||||
|
||||
## Signing key
|
||||
|
||||
Never in the repo (`*.jks` is gitignored). Repo secrets, read only by `.github/workflows/apk.yml`:
|
||||
|
||||
| Secret | What |
|
||||
|---|---|
|
||||
| `ANDROID_KEYSTORE_B64` | base64 of the PKCS12 keystore (RSA 4096, alias `sune`, valid to 2054) |
|
||||
| `ANDROID_KEYSTORE_PASS` | keystore password (also used as the key password) |
|
||||
| `ANDROID_KEY_ALIAS` | `sune` |
|
||||
|
||||
Losing this key means users can't update `chat.sune` and would have to uninstall and reinstall. Keep an offline copy.
|
||||
@@ -0,0 +1,30 @@
|
||||
{
|
||||
"packageId": "chat.sune",
|
||||
"host": "sune.chat",
|
||||
"name": "Sune",
|
||||
"launcherName": "Sune",
|
||||
"display": "standalone",
|
||||
"orientation": "portrait",
|
||||
"themeColor": "#FFFFFF",
|
||||
"themeColorDark": "#FFFFFF",
|
||||
"navigationColor": "#FFFFFF",
|
||||
"navigationColorDark": "#FFFFFF",
|
||||
"navigationDividerColor": "#00000000",
|
||||
"navigationDividerColorDark": "#00000000",
|
||||
"backgroundColor": "#000000",
|
||||
"startUrl": "/",
|
||||
"iconUrl": "https://sune.chat/appstore_content/%E2%9C%BA.png",
|
||||
"maskableIconUrl": "https://sune.chat/appstore_content/%E2%9C%BA.png",
|
||||
"webManifestUrl": "https://sune.chat/manifest.webmanifest",
|
||||
"fullScopeUrl": "https://sune.chat/",
|
||||
"additionalTrustedOrigins": ["https://sune.planetrenox.com"],
|
||||
"enableNotifications": false,
|
||||
"enableSiteSettingsShortcut": false,
|
||||
"splashScreenFadeOutDuration": 300,
|
||||
"fallbackType": "customtabs",
|
||||
"minSdkVersion": 21,
|
||||
"appVersion": "1.0.0",
|
||||
"appVersionCode": 10000,
|
||||
"signingKey": { "path": "./sune.jks", "alias": "sune" },
|
||||
"generatorApp": "bubblewrap-cli"
|
||||
}
|
||||
Reference in New Issue
Block a user