aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-android/README.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-08 11:40:17 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-08 11:40:17 +0200
commit2860f1de75af1d44d35292ecbf79c68f02409d19 (patch)
tree01096649c0cf475403f31bff803a23a955ca3397 /packages/meshbay-android/README.md
parentc27e04c88557716bbe8e42b9174ba9b07f90facf (diff)
downloadmeshbay-2860f1de75af1d44d35292ecbf79c68f02409d19.tar.gz
feat: sign Android releases with the release keyHEADmain
assembleRelease reads the key from ~/.gradle/gradle.properties and fails without it instead of falling back to the debug key. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-android/README.md')
-rw-r--r--packages/meshbay-android/README.md18
1 files changed, 17 insertions, 1 deletions
diff --git a/packages/meshbay-android/README.md b/packages/meshbay-android/README.md
index bfd82cf..5cb474e 100644
--- a/packages/meshbay-android/README.md
+++ b/packages/meshbay-android/README.md
@@ -32,13 +32,29 @@ holds the same service and the same visibility, for as long as it plays
# needs JDK 17+ and an Android SDK (ANDROID_HOME, or sdk.dir in local.properties)
./gradlew assembleDebug # app/build/outputs/apk/debug/app-debug.apk
./gradlew testDebugUnitTest # JVM unit tests
+./gradlew assembleRelease # app/build/outputs/apk/release/app-release.apk
```
+A release is signed with the release key, which never enters the repository.
+`assembleRelease` reads it from `~/.gradle/gradle.properties`, and stops if
+any of these is missing rather than signing with the debug key:
+
+```properties
+meshbayReleaseStoreFile=/path/to/meshbay-release.jks
+meshbayReleaseStorePassword=...
+meshbayReleaseKeyAlias=meshbay
+meshbayReleaseKeyPassword=...
+```
+
+`apksigner verify --print-certs app-release.apk` prints the certificate's
+SHA-256 fingerprint, the one the download page publishes (§8.2). A release
+does not install over a debug build, or the reverse: the keys differ.
+
The security contract is also pinned from the Python suite by reading this
source: `packages/meshbay-hub/tests/test_android_shell.py`.
Not built yet: phone-specific behaviour (back button, network handover,
-keeping a download alive with the screen off), signed releases.
+keeping a download alive with the screen off), updates through a store.
## Icon