aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-android/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-android/README.md')
-rw-r--r--packages/meshbay-android/README.md27
1 files changed, 26 insertions, 1 deletions
diff --git a/packages/meshbay-android/README.md b/packages/meshbay-android/README.md
index bfd82cf..69977ec 100644
--- a/packages/meshbay-android/README.md
+++ b/packages/meshbay-android/README.md
@@ -32,13 +32,38 @@ holds the same service and the same visibility, for as long as it plays
# needs JDK 17+ and an Android SDK (ANDROID_HOME, or sdk.dir in local.properties)
./gradlew assembleDebug # app/build/outputs/apk/debug/app-debug.apk
./gradlew testDebugUnitTest # JVM unit tests
+./gradlew assembleRelease # app/build/outputs/apk/release/app-release.apk
```
+A release is signed with the release key, which never enters the repository.
+`assembleRelease` reads it from `~/.gradle/gradle.properties`, and stops if
+any of these is missing rather than signing with the debug key:
+
+```properties
+meshbayReleaseStoreFile=/path/to/meshbay-release.jks
+meshbayReleaseStorePassword=...
+meshbayReleaseKeyAlias=meshbay
+meshbayReleaseKeyPassword=...
+```
+
+`apksigner verify --print-certs app-release.apk` prints the certificate's
+SHA-256 fingerprint, the one the download page publishes (§8.2). A release
+does not install over a debug build, or the reverse: the keys differ.
+
The security contract is also pinned from the Python suite by reading this
source: `packages/meshbay-hub/tests/test_android_shell.py`.
+Notifications while closed, with nothing to install: `notify/PollJob` (a
+system job, no library) fetches what is new from the hub every fifteen minutes
+with the phone's poll secret — never a session. When a UnifiedPush distributor
+is already on the phone (ntfy, …) it is used too: the hub pushes at once,
+encrypted to the phone (RFC 8291), `notify/PushReceiver` draws what the
+connector could decrypt, and the fetch slows to a four-hour net. The page turns
+it on in Settings and registers the phone with the hub; muting and "disable
+all" are decided on the hub, which then creates nothing (§11.3).
+
Not built yet: phone-specific behaviour (back button, network handover,
-keeping a download alive with the screen off), signed releases.
+keeping a download alive with the screen off), updates through a store.
## Icon