Files
opencode-mobile/.tasks/5/review.md
Den 416ab446c4 feat(5): F-Droid CI pipeline — self-hosted repo via GitHub Pages (#7)
* feat(5): F-Droid CI pipeline — self-hosted repo via GitHub Pages

- New publish-fdroid.yml workflow: builds APK, generates F-Droid repo
  index via fdroidserver, deploys to gh-pages/fdroid/repo
- gitignore: add __pycache__/ and *.pyc
- Generated F-Droid repo signing keystore + stored as GH secrets
- GitHub Pages enabled for gh-pages branch

Closes #5

* fix(5): review findings — pin fdroidserver, add index verification, clean perms

- Pin fdroidserver to 2.4.4 (verified version)
- Add post-update index.xml existence check
- Remove unnecessary pages:write + id-token:write perms

* docs(5): add test report and review artifacts
2026-05-26 01:06:22 -07:00

4.0 KiB

Review: Task 5 — F-Droid CI Pipeline

Checked against .tasks/5/design.md, .tasks/5/plan.md, and git diff origin/main...HEAD.


Findings

1. .gitignore — duplicate *.jks removed (correct, not a bug)

Original origin/main:.gitignore had *.jks twice: line 9 (*.aab → *.jks → *.keystore) and line 14 (after keystores/). The diff removes the duplicate at line 14 and adds __pycache__/ + *.pyc. Single *.jks on line 9 remains. JKS files are still gitignored. ✅

2. .github/workflows/publish-fdroid.yml:82 — fdroidserver version not pinned

pip install fdroidserver installs whatever the latest release is at CI time. The design explicitly calls this out as a risk: "Pin version, test via workflow_dispatch first" (design.md:36). Without a pin (fdroidserver==2.2.0 or similar), a future fdroidserver release could change the CLI interface or config format and silently break the pipeline.

Fix: pip install fdroidserver==2.2.0 (or the current stable version). Add a comment linking to the version used during testing.

3. .github/workflows/publish-fdroid.yml:100 — No verification after fdroid update

The fdroid update --create-metadata step runs without any post-condition check. If it fails (missing system dep, bad keystore, invalid APK), the deploy step will still run — potentially pushing a stale or broken index.xml to gh-pages. The site would serve a 404 or corrupt repo index.

Fix: Add a step between fdroid update and the deploy that checks test -f "${{ steps.fdroid-setup.outputs.fdroid-dir }}/repo/index.xml", or use fdroid verify if available.

4. .github/workflows/publish-fdroid.yml:13 — Unnecessary pages: write permission

peaceiris/actions-gh-pages@v4 pushes to the gh-pages branch via GITHUB_TOKEN with contents: write. The pages: write permission is only needed for the official actions/deploy-pages / GitHub Pages API. Harmless but misleading — could confuse future maintainers.

Fix: Remove pages: write and id-token: write from permissions if not needed.

5. .github/workflows/publish-fdroid.yml:52-53 — Signing check differs from build.yml

In build.yml:53, production signing requires refs/tags/v* AND the secret:

if [[ "${{ github.ref }}" == refs/tags/v* && -n "${{ secrets.KEYSTORE_BASE64 }}" ]]; then

In publish-fdroid.yml, it only checks the secret exists:

if [[ -n "${{ secrets.KEYSTORE_BASE64 }}" ]]; then

This means a workflow_dispatch run will sign with the production key even without a tag. This is actually more correct for the F-Droid use case (you always want a release-signed APK for distribution), but it's an inconsistency with the existing workflow. Not a bug, worth noting.

6. Design alignment — overall

The workflow implements the 4-stage design (trigger → build APK → fdroid update → deploy). The --create-metadata flag handles the metadata generation without requiring a pre-written .yml file. The key separation (APK signing vs. repo signing) is correctly enforced by using different secrets. The deployment path (fdroid/repo) matches the documented repo URL. ✅

Done criteria check (plan.md):

# Criterion Status
1 publish-fdroid.yml exists, valid YAML, lints clean ✅
2 On tag push, CI builds APK, generates F-Droid repo, deploys to gh-pages ✅ (assuming deps resolve)
3 GitHub Pages is enabled on the repo External (manual/API step, not verified here)
4 F-Droid repo keystore stored as GitHub secret Referenced in workflow, setup is external
5 https://dzianisv.github.io/opencode-mobile/fdroid/repo returns valid index Cannot verify without running CI
6 .gitignore has __pycache__ / *.pyc ✅

VERDICT: fix-required → RESOLVED

All findings addressed:

  • #2 (fix-required): Pinned fdroidserver==2.4.4 — commit f503e4f
  • #3 (recommended): Added post-update index.xml verification step — commit f503e4f
  • #4 (recommended): Removed pages: write and id-token: write — commit f503e4f