Skip to content

Complete WP00.03 Android source and resource provenance - #4

Merged
deku2026 merged 5 commits into
mainfrom
codex/wp00-03-provenance
Sep 19, 2026
Merged

deku2026 merged 5 commits into
mainfrom
codex/wp00-03-provenance

Conversation

@deku2026

@deku2026 deku2026 commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Complete Android source and packaged-resource provenance

The existing Android distributables included unclassified copied resources, including MPL Public Suffix List data under an Apache-declared OkHttp package. This implements WP00.03 and the accepted Design PR25 remediation: remove the unused data and test-runner images/source-only resources, retain explicit NO_COOKIES, and keep the native TLS/Connect transport, Android IDs, API minimum, R8 and persistent signing unchanged.

The Mobile-owned Apache checker port, closed reuse policy, ten-field template, complete inventory, immutable/superseding records, full notices and conflict process cover 110 source files, 19 reused files and 18 retained admissions. Resource gates check 122 actual inputs, all four APK/AAB variants, reviewed compiled-resource expectations and every archive member; candidate consumers repeat the checks, and signing proves unchanged payloads. Historical profiles remain immutable. Native payload checks now compare bytes as well as names.

Required lint identified the already published Contracts 1.0.0-ci.54.1 (source aa2f187a4adae8ee4f79cee192c0d382cb7fec7f). All six Maven downloads were independently verified; all 20 classes and schema bytes match the prior version. Exact pins, locks, checksums and superseding notice/resource admissions are included. No lint suppression or dependency-verification relaxation.

Local validation, including clean candidate/signature checks at edb6bb1:

  • Windows formatting, JVM tests (5 transport + 2 desktop + 2 Android-host), lint and all four actual archives passed; application class files target JVM 21.
  • 47 Python provenance/dependency/resource/release checks passed, including historical profile, wrong-source, notice, policy, path and native-byte failures.
  • Clean-source candidate verification covered 454 archive members. Four independently modified real candidates were rejected despite recomputed outer checksums: replaced fixed bytes, renamed excluded data, unknown resource and removed notice.
  • Disposable local APK/AAB signing and actual signature/payload verification passed. Persistent release identity remains exclusively with protected main publication.
  • Verified Gradle 9.7.1 wrapper regeneration reproduced both launch scripts and the JAR; workflow/naming/history secret checks passed.

The automatic local approval review rejected starting owned Android emulators with only "blocked by policy". Required real API 26/36 debug instrumentation, live Cloud calls and minified-release UI tests remain enabled in PR/main CI. Both OS builds now stage and independently verify their real archives; security and required publication gates remain enabled.

Dependencies already merged: Design PR25, Contracts PR22. PR checks are required before merge. Protected signing, actual public-byte/signature verification and the F-023 evidence update follow main CI; they are not claimed complete here.

Public-release validation now has a mandatory real-signature fixture in both PR OS builds. On main, both API images anonymously download the published assets, verify all hashes, companions and signed candidate payloads, upgrade the pinned ci.9.1 APK with the persistent identity, preserve installation UID/time and call real Cloud. The publication verifier requires both public upgrade jobs. Local real APK/AAB fixture checks passed and rejected a disposable identity as persistent and a changed notice even after recalculating the public manifest/checksums.

@deku2026 deku2026 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Completed full self-review of the 52-file change against base 69155c7 and fetched PR head 2ab7bf2. The fetched Git tree exactly matches the locally verified clean tree; the full diff (including immutable profile data) is retained with local evidence.

Reviewed source/record boundaries, all active and retired admissions, actual fixed/compiled-resource expectations, strict dependency changes, service rewriting, source and native hash checks, cookie behavior, signing/publication order and both workflows. Review findings were fixed before this head: retained-profile immutability; stale old NOTICE reference; wrapper review-summary wording via a preserved superseding record; the independently verified R8 interface merge and AGP worktree metadata. No unresolved actionable finding remains.

Local verification: 47 Python cases, nine JVM test executions, complete Windows build/lint, JVM 21 output, exact wrapper regeneration, 454 actual archive members, four real-candidate tamper cases with recomputed outer hashes, and disposable APK/AAB signature/payload checks. Naming, actionlint and full Git-history secret checks passed. Both PR/main API 26/36 and CodeQL remain mandatory. This review does not substitute for CI or protected main publication/public-byte verification.

@deku2026 deku2026 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final review updated for fetched head edb6bb1. Reviewed the complete current diff and the added public-download/signature/upgrade flow. Both build jobs now exercise that validator with actual disposable APK/AAB signatures before candidate acceptance; changed notice bytes with recomputed outer hashes and a disposable certificate cannot pass public identity checks. Local clean-source staging and that real signature fixture pass. Main-only jobs use anonymous public downloads, a hash-pinned old APK and the existing persistent certificate; they retain installation identity and actual Cloud UI evidence on both required API images. The final publication gate requires those jobs.

The previous head completed all PR CI successfully (35441752717). Its pass is not reused to authorize this head; all checks for 35442313413 must complete successfully before merge. No actionable review finding remains.

@deku2026
deku2026 merged commit 8015127 into main Sep 19, 2026
14 checks passed
@deku2026

Copy link
Copy Markdown
Contributor Author

Post-merge verification completed for 5031d83 and public android-0.1.0-ci.14.1.

  • All main CI gates passed: https://github.com/ArcForges/Mobile/actions/runs/35444269638
  • Independently downloaded all eleven public assets anonymously; GitHub asset digests, release/SHA256SUMS, source/notice/resource companions and every original candidate payload match. All 454 members of the four Android archives remain source/profile-bound.
  • Actual APK and AAB certificates both match the retained persistent SHA256 7a8b3b1402e77c3ec78e7a0b9f99d5358adc321d0e8d2a319c838d1cda181e9c. Public APK SHA256 is 418c406dd4b1cd12b5cd9b489a863340e3c6ccb172d8aa8809ad0c14de4d4de9.
  • API 26 and 36 each passed five instrumentation tests, eight actual SDK calls with expected success/error/deadline results, native UI recreation and the minified-release Cloud button call. The observed Native AOT Cloud source is 3165c97cccd3ea1e0b230d66e22ab9c775ca19d8.
  • Both independent public upgrade jobs installed ci.9.1 and upgraded version code 901 to 1401, preserving UID and first-install time. The actual public APK completed one real Cloud button call on each API. Raw package dumps, upgrade receipts and both screenshots were independently reviewed.
  • The exact merged source passes provenance (110 inventoried files, 19 reused, 18 retained records); primary main was pulled and is clean. Branches, both correction worktrees and all earlier evidence/releases remain retained.

Release: https://github.com/ArcForges/Mobile/releases/tag/android-0.1.0-ci.14.1
The ci.12.1 API 36 verification failure remains recorded; this reviewed correction and final passing release supersede its incomplete upgrade proof. WP00.03 has no unavailable external prerequisite. Local emulator startup was rejected by automatic approval review with blocked by policy; required emulator evidence was obtained in CI. No physical-device, store or full companion-product readiness is claimed.

@deku2026
deku2026 deleted the codex/wp00-03-provenance branch September 19, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant