Complete WP00.03 Android source and resource provenance - #4
Conversation
deku2026
left a comment
There was a problem hiding this comment.
Completed full self-review of the 52-file change against base 69155c7 and fetched PR head 2ab7bf2. The fetched Git tree exactly matches the locally verified clean tree; the full diff (including immutable profile data) is retained with local evidence.
Reviewed source/record boundaries, all active and retired admissions, actual fixed/compiled-resource expectations, strict dependency changes, service rewriting, source and native hash checks, cookie behavior, signing/publication order and both workflows. Review findings were fixed before this head: retained-profile immutability; stale old NOTICE reference; wrapper review-summary wording via a preserved superseding record; the independently verified R8 interface merge and AGP worktree metadata. No unresolved actionable finding remains.
Local verification: 47 Python cases, nine JVM test executions, complete Windows build/lint, JVM 21 output, exact wrapper regeneration, 454 actual archive members, four real-candidate tamper cases with recomputed outer hashes, and disposable APK/AAB signature/payload checks. Naming, actionlint and full Git-history secret checks passed. Both PR/main API 26/36 and CodeQL remain mandatory. This review does not substitute for CI or protected main publication/public-byte verification.
deku2026
left a comment
There was a problem hiding this comment.
Final review updated for fetched head edb6bb1. Reviewed the complete current diff and the added public-download/signature/upgrade flow. Both build jobs now exercise that validator with actual disposable APK/AAB signatures before candidate acceptance; changed notice bytes with recomputed outer hashes and a disposable certificate cannot pass public identity checks. Local clean-source staging and that real signature fixture pass. Main-only jobs use anonymous public downloads, a hash-pinned old APK and the existing persistent certificate; they retain installation identity and actual Cloud UI evidence on both required API images. The final publication gate requires those jobs.
The previous head completed all PR CI successfully (35441752717). Its pass is not reused to authorize this head; all checks for 35442313413 must complete successfully before merge. No actionable review finding remains.
|
Post-merge verification completed for 5031d83 and public
Release: https://github.com/ArcForges/Mobile/releases/tag/android-0.1.0-ci.14.1 |
Complete Android source and packaged-resource provenance
The existing Android distributables included unclassified copied resources, including MPL Public Suffix List data under an Apache-declared OkHttp package. This implements WP00.03 and the accepted Design PR25 remediation: remove the unused data and test-runner images/source-only resources, retain explicit NO_COOKIES, and keep the native TLS/Connect transport, Android IDs, API minimum, R8 and persistent signing unchanged.
The Mobile-owned Apache checker port, closed reuse policy, ten-field template, complete inventory, immutable/superseding records, full notices and conflict process cover 110 source files, 19 reused files and 18 retained admissions. Resource gates check 122 actual inputs, all four APK/AAB variants, reviewed compiled-resource expectations and every archive member; candidate consumers repeat the checks, and signing proves unchanged payloads. Historical profiles remain immutable. Native payload checks now compare bytes as well as names.
Required lint identified the already published Contracts 1.0.0-ci.54.1 (source aa2f187a4adae8ee4f79cee192c0d382cb7fec7f). All six Maven downloads were independently verified; all 20 classes and schema bytes match the prior version. Exact pins, locks, checksums and superseding notice/resource admissions are included. No lint suppression or dependency-verification relaxation.
Local validation, including clean candidate/signature checks at edb6bb1:
The automatic local approval review rejected starting owned Android emulators with only "blocked by policy". Required real API 26/36 debug instrumentation, live Cloud calls and minified-release UI tests remain enabled in PR/main CI. Both OS builds now stage and independently verify their real archives; security and required publication gates remain enabled.
Dependencies already merged: Design PR25, Contracts PR22. PR checks are required before merge. Protected signing, actual public-byte/signature verification and the F-023 evidence update follow main CI; they are not claimed complete here.
Public-release validation now has a mandatory real-signature fixture in both PR OS builds. On main, both API images anonymously download the published assets, verify all hashes, companions and signed candidate payloads, upgrade the pinned ci.9.1 APK with the persistent identity, preserve installation UID/time and call real Cloud. The publication verifier requires both public upgrade jobs. Local real APK/AAB fixture checks passed and rejected a disposable identity as persistent and a changed notice even after recalculating the public manifest/checksums.