Add Android APK release workflow

Bubblewrap TWA config for chat.sune, plus a manually dispatched workflow
that builds, signs, verifies against assetlinks.json, attests provenance
and publishes the release for the tag given as input.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-01 12:25:57 -07:00
co-authored by Claude Sonnet 5.5
parent c321396ac4
commit ae05a6fd37
3 changed files with 206 additions and 0 deletions
+139
View File
@@ -0,0 +1,139 @@
name: Release APK
run-name: Release APK ${{ inputs.version }}
on:
workflow_dispatch:
inputs:
version:
description: 'Release tag to create, e.g. v1.0.0'
required: true
type: string
concurrency: release-apk
permissions: {}
jobs:
apk:
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: write # create the tag + release
id-token: write # sign the build attestation
attestations: write
env:
TAG: ${{ inputs.version }}
steps:
- name: Validate version
run: |
[[ "$TAG" =~ ^v([0-9]+)\.([0-9]+)\.([0-9]+)$ ]] || { echo "::error::version must look like v1.0.0"; exit 1; }
MA=${BASH_REMATCH[1]} MI=${BASH_REMATCH[2]} PA=${BASH_REMATCH[3]}
(( MI < 100 && PA < 100 )) || { echo "::error::minor and patch must be < 100"; exit 1; }
echo "VERSION=${TAG#v}" >> $GITHUB_ENV
echo "CODE=$((MA*10000 + MI*100 + PA))" >> $GITHUB_ENV
echo "APK=sune-$TAG.apk" >> $GITHUB_ENV
echo "BT=$RUNNER_TEMP/sdk/build-tools/36.1.0" >> $GITHUB_ENV
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Fail if the release already exists
if: github.ref == 'refs/heads/master'
env:
GH_TOKEN: ${{ github.token }}
run: |
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
echo "::error::$TAG already exists"; exit 1
fi
- uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
distribution: temurin
java-version: 17
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
- name: Install Android SDK + Bubblewrap
run: |
SDK=$RUNNER_TEMP/sdk
mkdir -p "$SDK/bin" # bubblewrap only checks that this exists
SM=$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager
yes | "$SM" --sdk_root="$SDK" --licenses >/dev/null || true # yes exits on SIGPIPE
"$SM" --sdk_root="$SDK" "build-tools;36.1.0" "platforms;android-36" >/dev/null
npm install --global --ignore-scripts @bubblewrap/cli@1.25.0
mkdir -p ~/.bubblewrap
jq -n --arg jdk "$JAVA_HOME" --arg sdk "$SDK" '{jdkPath:$jdk,androidSdkPath:$sdk}' > ~/.bubblewrap/config.json
- name: Build + sign
env:
ANDROID_KEYSTORE_B64: ${{ secrets.ANDROID_KEYSTORE_B64 }}
ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
BUBBLEWRAP_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASS }}
BUBBLEWRAP_KEY_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASS }}
run: |
B=$RUNNER_TEMP/build OUT=$RUNNER_TEMP/out
mkdir -p "$B" "$OUT"
echo "$ANDROID_KEYSTORE_B64" | base64 -d > "$B/sune.jks"
# pin the icon to this exact commit instead of whatever the site serves today
ICON="https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$GITHUB_SHA/public/appstore_content/%E2%9C%BA.png"
jq --arg v "$VERSION" --argjson c "$CODE" --arg a "$ANDROID_KEY_ALIAS" --arg i "$ICON" \
'.appVersion=$v | .appVersionCode=$c | .signingKey.alias=$a | .iconUrl=$i | .maskableIconUrl=$i' \
android/twa-manifest.json > "$B/twa-manifest.json"
cd "$B"
bubblewrap update --manifest ./twa-manifest.json --skipVersionUpgrade
bubblewrap build --manifest ./twa-manifest.json --skipPwaValidation
mv app-release-signed.apk "$OUT/$APK"
rm -f sune.jks
echo "OUT=$OUT" >> $GITHUB_ENV
- name: Verify the APK
run: |
cd "$OUT"
"$BT/apksigner" verify --verbose --print-certs "$APK" | tee verify.txt
grep -q "Number of signers: 1" verify.txt
GOT=$(sed -n 's/.*certificate SHA-256 digest: //p' verify.txt | sed -n 1p)
WANT=$(jq -r '.[].target | select(.package_name=="chat.sune") | .sha256_cert_fingerprints[]' "$GITHUB_WORKSPACE/public/.well-known/assetlinks.json" | tr -d ':' | tr A-F a-f)
[ "$GOT" = "$WANT" ] || { echo "::error::signing cert $GOT does not match assetlinks.json ($WANT)"; exit 1; }
"$BT/aapt2" dump badging "$APK" > full-badging.txt
grep -m1 '^package:' full-badging.txt | tee badging.txt
grep -q "name='chat.sune' versionCode='$CODE' versionName='$VERSION'" badging.txt
sha256sum "$APK" | tee "$APK.sha256"
echo "SIGNER=$GOT" >> $GITHUB_ENV
- name: Attest build provenance
if: github.ref == 'refs/heads/master'
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: ${{ runner.temp }}/out/sune-${{ inputs.version }}.apk
- name: Publish release
if: github.ref == 'refs/heads/master'
env:
GH_TOKEN: ${{ github.token }}
run: |
cd "$OUT"
SHA=$(cut -d' ' -f1 "$APK.sha256")
cat > notes.md <<EOF
Built and signed by GitHub Actions from commit \`$GITHUB_SHA\` ([workflow run]($GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID)). Nobody handled the file in between.
Verify a download:
\`\`\`
gh attestation verify $APK --repo $GITHUB_REPOSITORY
\`\`\`
- Package: \`chat.sune\`
- SHA-256: \`$SHA\`
- Signing certificate SHA-256: \`$SIGNER\`
EOF
gh release create "$TAG" "$APK" "$APK.sha256" --repo "$GITHUB_REPOSITORY" --target "$GITHUB_SHA" --title "Sune $TAG" --notes-file notes.md
- name: Keep the APK as a workflow artifact (non-release runs)
if: github.ref != 'refs/heads/master'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ env.APK }}
path: ${{ runner.temp }}/out/*.apk
retention-days: 3
+37
View File
@@ -0,0 +1,37 @@
# Android app
Sune for Android is a [Trusted Web Activity](https://developer.chrome.com/docs/android/trusted-web-activity) wrapper around https://sune.chat, built with [Bubblewrap](https://github.com/GoogleChromeLabs/bubblewrap). It contains no app code, only the config in `twa-manifest.json`.
| | New app | Legacy app (v0.x) |
|---|---|---|
| Package | `chat.sune` | `com.planetrenox.sune` |
| Host | `sune.chat` (also trusts `sune.planetrenox.com`) | `sune.planetrenox.com` |
| Signing cert SHA-256 | `09:85:1F:7B:BB:40:67:9C:F8:70:1C:7D:9F:65:72:77:78:0E:C0:58:CF:34:09:9A:97:D2:8A:74:FB:CE:87:2A` | `E8:7D:70:60:C2:7D:EF:CB:4D:4D:2B:E2:2E:5E:37:ED:F7:0B:1E:F5:77:D7:04:1F:6B:07:EC:B8:1D:78:6D:43` (**leaked**) |
Both are listed for both domains in [`public/.well-known/assetlinks.json`](../public/.well-known/assetlinks.json); that file is what makes Chrome hide the address bar. Remove the legacy entry once nobody uses the old app (a leaked key can sign a fake `com.planetrenox.sune` that Chrome would trust).
## Releasing
Actions → **Release APK** → Run workflow on `master` → enter the tag, e.g. `v1.0.0`.
It builds `sune-v1.0.0.apk`, signs it, checks the signing cert against `assetlinks.json`, attests build provenance, then creates the tag and release. `versionCode` is `major*10000 + minor*100 + patch`. Run it from any other branch to do a dry run: it builds and verifies but publishes nothing.
## Verifying a download
```bash
gh attestation verify sune-v1.0.0.apk --repo sune-org/sune
```
This proves the file was built by this repo's workflow at the commit named in the release, and not modified since. The APK is only a wrapper; the app itself is served live from sune.chat and is not covered by it.
## Signing key
Never in the repo (`*.jks` is gitignored). Repo secrets, read only by `.github/workflows/apk.yml`:
| Secret | What |
|---|---|
| `ANDROID_KEYSTORE_B64` | base64 of the PKCS12 keystore (RSA 4096, alias `sune`, valid to 2054) |
| `ANDROID_KEYSTORE_PASS` | keystore password (also used as the key password) |
| `ANDROID_KEY_ALIAS` | `sune` |
Losing this key means users can't update `chat.sune` and would have to uninstall and reinstall. Keep an offline copy.
+30
View File
@@ -0,0 +1,30 @@
{
"packageId": "chat.sune",
"host": "sune.chat",
"name": "Sune",
"launcherName": "Sune",
"display": "standalone",
"orientation": "portrait",
"themeColor": "#FFFFFF",
"themeColorDark": "#FFFFFF",
"navigationColor": "#FFFFFF",
"navigationColorDark": "#FFFFFF",
"navigationDividerColor": "#00000000",
"navigationDividerColorDark": "#00000000",
"backgroundColor": "#000000",
"startUrl": "/",
"iconUrl": "https://sune.chat/appstore_content/%E2%9C%BA.png",
"maskableIconUrl": "https://sune.chat/appstore_content/%E2%9C%BA.png",
"webManifestUrl": "https://sune.chat/manifest.webmanifest",
"fullScopeUrl": "https://sune.chat/",
"additionalTrustedOrigins": ["https://sune.planetrenox.com"],
"enableNotifications": false,
"enableSiteSettingsShortcut": false,
"splashScreenFadeOutDuration": 300,
"fallbackType": "customtabs",
"minSdkVersion": 21,
"appVersion": "1.0.0",
"appVersionCode": 10000,
"signingKey": { "path": "./sune.jks", "alias": "sune" },
"generatorApp": "bubblewrap-cli"
}