Enforce Android Apache boundary and distributable licence closure - #3
Conversation
Signed-off-by: sammiller <dekueon@gmail.com>
Signed-off-by: sammiller <dekueon@gmail.com>
|
Full review of final head d1bf5bd completed. The complete remote diff matches the reviewed local patch (894598ac0f44ea24c4071755bf159e5b41cbbe77). Review covered independent Apache tooling, all three effective Gradle declarations, the complete resolved graph and strict checksum updates, upstream retained notices and native source/compiler evidence, generated assets, immutable stage/sign/publish boundaries, both API device gates, identity continuity and documentation. All nine repositories passed the read-only 75-project boundary audit and naming scan. Fourteen local Python fixtures, full strict warm/cold builds, actual effective-property rejection and real API26/API36 debug/release checks passed. The final clean-commit candidate was rebuilt, staged and verified after the last review fix. The first secret-scan failure was an identified false positive on the public SLF4J 2.0.18 JAR SHA-256, independently re-downloaded from Maven Central. The correction retains the default scanner and excludes only the exact file-and-line checksum match. Actual scanner regressions confirm a changed checksum or another path still fails, and full-history scanning now passes locally and in latest-head CI. No unresolved review finding. Latest-head build/device/security CI must all pass before merge. Main signing/publication, public artifact contents and certificate-preserving upgrade remain pending post-merge checks; no store/full-product acceptance is inferred. |
|
All twelve applicable latest-head checks are now successful in CI run 35406342747, including both OS builds, API26 and API36 device jobs, all three CodeQL languages, dependency/secret scans and the aggregate Verify gate. The two main-only publication checks are correctly inapplicable to this PR. Final reviewed head remains d1bf5bd with no unresolved findings. Proceeding to merge and the required main publication and public upgrade checks. |
|
Post-merge closure passed for 69155c7. Main CI 35407161182 is successful, including both OS builds, all security gates, API26/API36 device tests, persistent Publish Android and Verify publication. The release android-0.1.0-ci.9.1 has eight publicly downloaded and digest-verified assets. The signed APK and AAB preserve every candidate payload entry; only the three expected signature metadata entries were added. Actual APK/AAB signature verification confirms the existing public certificate 7a8b3b1402e77c3ec78e7a0b9f99d5358adc321d0e8d2a319c838d1cda181e9c. Source-bound closure/notices and all candidate hashes match the clean merged build. Main device evidence records five instrumentation tests and eight real SDK calls per API, plus minified release Cloud calls; the observed Cloud source is 2cf5a58633a7e09db05ebc1741f1cab83547a832. Independent local installs downloaded the old public 601 APK and upgraded directly to public 901 on both owned API26/API36 emulators. The UID and first-install timestamp were preserved, each upgraded app completed one real Cloud button call, and screenshots were inspected. No test signature or developer build was used for this final upgrade proof. The primary checkout is synchronized and clean; branch/worktree are retained. Current Android licence and distribution gates are satisfied for this exact closure: 195 components, 122 artifacts, four native binaries and twelve retained texts. No Play submission, physical-device or full ArcChat-product acceptance is claimed. Design's candidate-specific gate record is being updated with these actual results. |
Implement WP00.02 for all three Apache-2.0 Mobile Gradle scopes and block Android packaging unless its actual resolved dependency, native binary and retained notice closure matches reviewed policy. Every release/debug/test APK and AAB embeds the same source-bound receipt and complete notices, and protected signing re-verifies and publishes those companions with the immutable candidate.
The Design-approved GPL conflict remediation removes optional desugar_jdk_libs without changing JVM 21, minimum API 26, package IDs or signing identity. Required lint also selected the verified stable AGP 9.4.1 patch and published Contracts 1.0.0-ci.44.1; exact locks/checksums are updated. The current closure contains 195 components, 122 unique artifacts, four reviewed native binaries and twelve retained notice texts. Both API 26 and API 36 now gate the same Linux candidate, and main publication has an explicit successful dependency condition and a required publication result.
Dependencies: accepted ArcForges-Design#18/#19 and Contracts#17 are already merged; Contracts 1.0.0-ci.44.1 is verified public on all three registries. Original Mobile licence tooling is independently Apache-2.0 and imports no AGPL implementation.
Local validation completed: fourteen Python fixtures; actual Gradle override rejection; complete strict build including formatting, shared/app tests, lint and all four archives; a second complete strict build from an empty Gradle cache (177 tasks executed); JVM 21 bytecode checks; API 26 and API 36 instrumentation (five tests each), real SDK success/Unicode/failure/deadline calls and actual minified release button calls against Cloud commit 2cf5a58633a7e09db05ebc1741f1cab83547a832; screenshots reviewed. A clean source-commit candidate at 98da7ec was staged and all embedded assets and inventory checks passed. Actionlint and git diff checks passed. Full local source, dependency origin, notice and generated metadata review completed.
Latest-head Windows/Linux CI, both device jobs and security remain prerequisite PR gates. Persistent main signing/publication, public-download identity and certificate continuity, and published-APK installation/upgrade are explicitly pending post-merge gates. This scope does not establish Play approval, physical-device support or full ArcChat product readiness. Keep the branch and worktree after merge.