Repository navigation
feat/migration data receive #35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish F-Droid | |
| on: | |
| push: | |
| branches: | |
| - main | |
| tags: | |
| - "android@*" | |
| paths: | |
| - "apps/mobile/**" | |
| - "packages/**" | |
| - "package.json" | |
| - "pnpm-lock.yaml" | |
| - "pnpm-workspace.yaml" | |
| - "fastlane/**" | |
| - "metadata/**" | |
| - "scripts/fdroid-*.sh" | |
| - ".github/workflows/app-zum-doc-mobile-android-publish-fdroid.yaml" | |
| pull_request: | |
| paths: | |
| - "apps/mobile/**" | |
| - "packages/**" | |
| - "package.json" | |
| - "pnpm-lock.yaml" | |
| - "pnpm-workspace.yaml" | |
| - "fastlane/**" | |
| - "metadata/**" | |
| - "scripts/fdroid-*.sh" | |
| - ".github/workflows/app-zum-doc-mobile-android-publish-fdroid.yaml" | |
| workflow_dispatch: | |
| concurrency: | |
| group: fdroid-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| permissions: | |
| contents: read | |
| env: | |
| FDROID_APPID: de.helpwave.appzumdoc | |
| FDROID_IMAGE: registry.gitlab.com/fdroid/fdroidserver:buildserver-trixie | |
| jobs: | |
| verify: | |
| runs-on: "ubuntu-24.04" # @sync android.runner | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - run: | | |
| set -euo pipefail | |
| scripts/mobile-sync.sh check | |
| scripts/fdroid-metadata.sh check | |
| if [[ "${GITHUB_REF_TYPE}" == "tag" ]]; then | |
| scripts/mobile-sync.sh check-tag "${GITHUB_REF_NAME}" | |
| fi | |
| build: | |
| needs: verify | |
| name: Build with the F-Droid buildserver (${{ matrix.name }}) | |
| runs-on: "ubuntu-24.04" # @sync android.runner | |
| timeout-minutes: 90 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: a | |
| subnet: 172.30.0.0/24 | |
| hostname: buildserver-a | |
| tz: UTC | |
| cpus: "0-3" | |
| - name: b | |
| subnet: 10.77.0.0/24 | |
| hostname: buildserver-b | |
| tz: Pacific/Auckland | |
| cpus: "0-1" | |
| steps: | |
| - name: Free disk space | |
| run: sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc /usr/local/.ghcup | |
| - uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 0 | |
| - name: Build | |
| env: | |
| SUBNET: ${{ matrix.subnet }} | |
| BUILD_HOSTNAME: ${{ matrix.hostname }} | |
| BUILD_TZ: ${{ matrix.tz }} | |
| BUILD_CPUS: ${{ matrix.cpus }} | |
| run: | | |
| set -euo pipefail | |
| mkdir -p "${RUNNER_TEMP}/fdroid" | |
| docker network create --subnet "${SUBNET}" fdroid | |
| docker run --rm --network fdroid --hostname "${BUILD_HOSTNAME}" --cpuset-cpus "${BUILD_CPUS}" -e TZ="${BUILD_TZ}" \ | |
| -v "${GITHUB_WORKSPACE}:/repo" -v "${RUNNER_TEMP}/fdroid:/out" \ | |
| "${FDROID_IMAGE}" /repo/scripts/fdroid-build.sh "${GITHUB_SHA}" /out | |
| - uses: actions/upload-artifact@v6 | |
| with: | |
| name: fdroid-unsigned-${{ matrix.name }} | |
| path: ${{ runner.temp }}/fdroid/*.apk | |
| if-no-files-found: error | |
| reproducible: | |
| needs: build | |
| name: Builds from different environments are identical | |
| runs-on: "ubuntu-24.04" # @sync android.runner | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/download-artifact@v7 | |
| with: | |
| pattern: fdroid-unsigned-* | |
| path: ${{ runner.temp }}/apk | |
| - run: | | |
| set -euo pipefail | |
| cd "${RUNNER_TEMP}/apk" | |
| a="$(ls fdroid-unsigned-a/*.apk)" | |
| b="$(ls fdroid-unsigned-b/*.apk)" | |
| sha256sum "${a}" "${b}" | |
| cmp -s "${a}" "${b}" && exit 0 | |
| unzip -q "${a}" -d a | |
| unzip -q "${b}" -d b | |
| diff -rq a b || true | |
| diff -rq a b | awk '/ differ$/ {print $2}' | while read -r f; do | |
| echo "::group::${f#a/}" | |
| diff <(strings -n 4 "${f}") <(strings -n 4 "b/${f#a/}") | head -n 40 || true | |
| echo "::endgroup::" | |
| done | |
| echo "::error::The F-Droid build depends on the build environment, so F-Droid cannot reproduce our APK." | |
| exit 1 | |
| release: | |
| if: github.ref_type == 'tag' | |
| needs: reproducible | |
| name: Sign and publish GitHub release | |
| runs-on: "ubuntu-24.04" # @sync android.runner | |
| timeout-minutes: 15 | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/download-artifact@v7 | |
| with: | |
| name: fdroid-unsigned-a | |
| path: ${{ runner.temp }}/unsigned | |
| - uses: android-actions/setup-android@v4 | |
| with: | |
| packages: "platform-tools platforms;android-36 build-tools;36.0.0" # @sync android.sdkPackages | |
| - name: Sign and verify against the F-Droid build | |
| env: | |
| ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }} | |
| ANDROID_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }} | |
| ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }} | |
| ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }} | |
| run: | | |
| set -euo pipefail | |
| version="$(scripts/mobile-sync.sh store-version "${GITHUB_REF_NAME}")" | |
| unsigned="$(ls "${RUNNER_TEMP}"/unsigned/*.apk)" | |
| signed="${RUNNER_TEMP}/app-zum-doc-${version}.apk" | |
| keystore="${RUNNER_TEMP}/release.p12" | |
| export PATH="${ANDROID_HOME}/build-tools/36.0.0:${PATH}" | |
| base64 --decode <<< "${ANDROID_KEYSTORE_BASE64}" > "${keystore}" | |
| apksigner sign --alignment-preserved --ks "${keystore}" --ks-type PKCS12 --ks-key-alias "${ANDROID_KEY_ALIAS}" \ | |
| --ks-pass env:ANDROID_KEYSTORE_PASSWORD --key-pass env:ANDROID_KEY_PASSWORD \ | |
| --out "${signed}" "${unsigned}" | |
| rm -f "${keystore}" | |
| expected="$(sed -n 's/^AllowedAPKSigningKeys: //p' "metadata/${FDROID_APPID}.yml")" | |
| grep -q "SHA-256 digest: ${expected}$" <<< "$(apksigner verify --print-certs "${signed}")" | |
| pipx install apksigcopier | |
| apksigcopier compare "${signed}" --unsigned "${unsigned}" | |
| scripts/fdroid-metadata.sh render "${GITHUB_SHA}" "${RUNNER_TEMP}/${FDROID_APPID}.yml" | |
| echo "VERSION=${version}" >> "${GITHUB_ENV}" | |
| echo "SIGNED=${signed}" >> "${GITHUB_ENV}" | |
| - name: Publish GitHub release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| set -euo pipefail | |
| gh release view "${GITHUB_REF_NAME}" >/dev/null 2>&1 \ | |
| || gh release create "${GITHUB_REF_NAME}" --verify-tag \ | |
| --title "Android ${VERSION}" --notes "App zum Doc Android ${VERSION}." | |
| gh release upload "${GITHUB_REF_NAME}" --clobber \ | |
| "${SIGNED}" "${RUNNER_TEMP}/${FDROID_APPID}.yml" |