release(fdroid): v0.4.3 — fix self-hosted F-Droid publish (v2-only signing)
The self-hosted F-Droid repo (https://dzianisv.github.io/opencode-mobile/fdroid/repo) has been stuck at v0.4.1 because publish-fdroid crashed in androguard parsing the CI APK's v2+v3 signature block pair ('NoOverwriteDict' object has no attribute 'append'). Force v1+v2-only signing: gradle flags for local builds, plus a deterministic apksigner re-sign step in the workflow (expo prebuild regenerates build.gradle, so the workflow step is the real guarantee). Bump to v0.4.3 / versionCode 5 so a fresh tag re-runs the publish with the verified bug fixes (#10 scope fixes, send-error fix) included. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
23
.github/workflows/publish-fdroid.yml
vendored
23
.github/workflows/publish-fdroid.yml
vendored
@@ -68,6 +68,29 @@ jobs:
|
||||
working-directory: android
|
||||
run: ./gradlew assembleRelease
|
||||
|
||||
- name: Re-sign APK v1+v2 only (drop v3/v4 for fdroidserver compatibility)
|
||||
if: ${{ env.RELEASE_STORE_FILE != '' }}
|
||||
run: |
|
||||
# androguard (used by fdroidserver) crashes parsing a v2+v3 signature
|
||||
# block pair: "'NoOverwriteDict' object has no attribute 'append'".
|
||||
# expo prebuild regenerates build.gradle, so we can't rely on the
|
||||
# gradle signing flags surviving — force v1+v2-only here deterministically.
|
||||
APK=android/app/build/outputs/apk/release/app-release.apk
|
||||
APKSIGNER=$(ls "$ANDROID_HOME"/build-tools/*/apksigner | sort -V | tail -1)
|
||||
echo "Using $APKSIGNER"
|
||||
"$APKSIGNER" sign \
|
||||
--ks android/app/release.keystore \
|
||||
--ks-pass "pass:${RELEASE_STORE_PASSWORD}" \
|
||||
--ks-key-alias "${RELEASE_KEY_ALIAS}" \
|
||||
--key-pass "pass:${RELEASE_KEY_PASSWORD}" \
|
||||
--v1-signing-enabled true \
|
||||
--v2-signing-enabled true \
|
||||
--v3-signing-enabled false \
|
||||
--v4-signing-enabled false \
|
||||
"$APK"
|
||||
echo "=== signature schemes after re-sign ==="
|
||||
"$APKSIGNER" verify -v "$APK" | grep -i "Verified using" || true
|
||||
|
||||
- name: Install fdroidserver
|
||||
# androguard version matters: 4.0.x crashes parsing our APK resources
|
||||
# ("res1 must be zero!"); 4.1.0/4.1.1 crash on the signature block
|
||||
|
||||
Reference in New Issue
Block a user