* feat(5): F-Droid CI pipeline — self-hosted repo via GitHub Pages - New publish-fdroid.yml workflow: builds APK, generates F-Droid repo index via fdroidserver, deploys to gh-pages/fdroid/repo - gitignore: add __pycache__/ and *.pyc - Generated F-Droid repo signing keystore + stored as GH secrets - GitHub Pages enabled for gh-pages branch Closes #5 * fix(5): review findings — pin fdroidserver, add index verification, clean perms - Pin fdroidserver to 2.4.4 (verified version) - Add post-update index.xml existence check - Remove unnecessary pages:write + id-token:write perms * docs(5): add test report and review artifacts
4.0 KiB
Review: Task 5 — F-Droid CI Pipeline
Checked against .tasks/5/design.md, .tasks/5/plan.md, and git diff origin/main...HEAD.
Findings
1. .gitignore — duplicate *.jks removed (correct, not a bug)
Original origin/main:.gitignore had *.jks twice: line 9 (*.aab → *.jks → *.keystore) and line 14 (after keystores/). The diff removes the duplicate at line 14 and adds __pycache__/ + *.pyc. Single *.jks on line 9 remains. JKS files are still gitignored. ✅
2. .github/workflows/publish-fdroid.yml:82 — fdroidserver version not pinned
pip install fdroidserver installs whatever the latest release is at CI time. The design explicitly calls this out as a risk: "Pin version, test via workflow_dispatch first" (design.md:36). Without a pin (fdroidserver==2.2.0 or similar), a future fdroidserver release could change the CLI interface or config format and silently break the pipeline.
Fix: pip install fdroidserver==2.2.0 (or the current stable version). Add a comment linking to the version used during testing.
3. .github/workflows/publish-fdroid.yml:100 — No verification after fdroid update
The fdroid update --create-metadata step runs without any post-condition check. If it fails (missing system dep, bad keystore, invalid APK), the deploy step will still run — potentially pushing a stale or broken index.xml to gh-pages. The site would serve a 404 or corrupt repo index.
Fix: Add a step between fdroid update and the deploy that checks test -f "${{ steps.fdroid-setup.outputs.fdroid-dir }}/repo/index.xml", or use fdroid verify if available.
4. .github/workflows/publish-fdroid.yml:13 — Unnecessary pages: write permission
peaceiris/actions-gh-pages@v4 pushes to the gh-pages branch via GITHUB_TOKEN with contents: write. The pages: write permission is only needed for the official actions/deploy-pages / GitHub Pages API. Harmless but misleading — could confuse future maintainers.
Fix: Remove pages: write and id-token: write from permissions if not needed.
5. .github/workflows/publish-fdroid.yml:52-53 — Signing check differs from build.yml
In build.yml:53, production signing requires refs/tags/v* AND the secret:
if [[ "${{ github.ref }}" == refs/tags/v* && -n "${{ secrets.KEYSTORE_BASE64 }}" ]]; then
In publish-fdroid.yml, it only checks the secret exists:
if [[ -n "${{ secrets.KEYSTORE_BASE64 }}" ]]; then
This means a workflow_dispatch run will sign with the production key even without a tag. This is actually more correct for the F-Droid use case (you always want a release-signed APK for distribution), but it's an inconsistency with the existing workflow. Not a bug, worth noting.
6. Design alignment — overall
The workflow implements the 4-stage design (trigger → build APK → fdroid update → deploy). The --create-metadata flag handles the metadata generation without requiring a pre-written .yml file. The key separation (APK signing vs. repo signing) is correctly enforced by using different secrets. The deployment path (fdroid/repo) matches the documented repo URL. ✅
Done criteria check (plan.md):
| # | Criterion | Status |
|---|---|---|
| 1 | publish-fdroid.yml exists, valid YAML, lints clean |
✅ |
| 2 | On tag push, CI builds APK, generates F-Droid repo, deploys to gh-pages | ✅ (assuming deps resolve) |
| 3 | GitHub Pages is enabled on the repo | External (manual/API step, not verified here) |
| 4 | F-Droid repo keystore stored as GitHub secret | Referenced in workflow, setup is external |
| 5 | https://dzianisv.github.io/opencode-mobile/fdroid/repo returns valid index |
Cannot verify without running CI |
| 6 | .gitignore has __pycache__ / *.pyc |
✅ |
VERDICT: fix-required → RESOLVED
All findings addressed:
- #2 (fix-required): Pinned
fdroidserver==2.4.4— commit f503e4f - #3 (recommended): Added post-update
index.xmlverification step — commit f503e4f - #4 (recommended): Removed
pages: writeandid-token: write— commit f503e4f