diff options
Diffstat (limited to 'packages/meshbay-android/README.md')
| -rw-r--r-- | packages/meshbay-android/README.md | 27 |
1 files changed, 26 insertions, 1 deletions
diff --git a/packages/meshbay-android/README.md b/packages/meshbay-android/README.md index bfd82cf..69977ec 100644 --- a/packages/meshbay-android/README.md +++ b/packages/meshbay-android/README.md @@ -32,13 +32,38 @@ holds the same service and the same visibility, for as long as it plays # needs JDK 17+ and an Android SDK (ANDROID_HOME, or sdk.dir in local.properties) ./gradlew assembleDebug # app/build/outputs/apk/debug/app-debug.apk ./gradlew testDebugUnitTest # JVM unit tests +./gradlew assembleRelease # app/build/outputs/apk/release/app-release.apk ``` +A release is signed with the release key, which never enters the repository. +`assembleRelease` reads it from `~/.gradle/gradle.properties`, and stops if +any of these is missing rather than signing with the debug key: + +```properties +meshbayReleaseStoreFile=/path/to/meshbay-release.jks +meshbayReleaseStorePassword=... +meshbayReleaseKeyAlias=meshbay +meshbayReleaseKeyPassword=... +``` + +`apksigner verify --print-certs app-release.apk` prints the certificate's +SHA-256 fingerprint, the one the download page publishes (§8.2). A release +does not install over a debug build, or the reverse: the keys differ. + The security contract is also pinned from the Python suite by reading this source: `packages/meshbay-hub/tests/test_android_shell.py`. +Notifications while closed, with nothing to install: `notify/PollJob` (a +system job, no library) fetches what is new from the hub every fifteen minutes +with the phone's poll secret — never a session. When a UnifiedPush distributor +is already on the phone (ntfy, …) it is used too: the hub pushes at once, +encrypted to the phone (RFC 8291), `notify/PushReceiver` draws what the +connector could decrypt, and the fetch slows to a four-hour net. The page turns +it on in Settings and registers the phone with the hub; muting and "disable +all" are decided on the hub, which then creates nothing (§11.3). + Not built yet: phone-specific behaviour (back button, network handover, -keeping a download alive with the screen off), signed releases. +keeping a download alive with the screen off), updates through a store. ## Icon |