Skip to content

feat(mobile): Android companion and debug validation CI - #860

Draft
pascalandr wants to merge 1 commit into
devfrom
feat/android-companion-ci
Draft

pascalandr wants to merge 1 commit into
devfrom
feat/android-companion-ci

Conversation

@pascalandr

@pascalandr pascalandr commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Android-first prototype, not a device-qualified or store-ready mobile delivery. Thin Tauri companion: ten-locale bundled launcher and trusted HTTPS server-hosted UI; execution remains remote. No mobile Node/OpenCode/Git/backend, remote native capabilities or TLS bypass.

  • Source-owned Android transport, origin/navigation and native recovery fences; Java XML, URL/authority and hosted authentication/upload regressions.
  • Preview HTTP/WebSocket credential stripping and strict upstream TLS, with real isolated loopback browser coverage. Server remains undeployed and not approved for unrestricted public Internet exposure; residual dependency/security review is documented.
  • Separate mobile Cargo workspace with provenance-preserving Tauri 2.12.1 Int32 ABI correction. Shared iOS sources must remain in the common foundation because the vendor changes the Android graph too; iOS CI/handoff follows in a small stacked PR.
  • PR source/typecheck/browser/policy validation and real ARM64 debug APK compilation in separate jobs. Immutable action pins, read-only token, no signing secrets, no privileged PR trigger, short-lived APK/SHA256 artifacts only.

Explicit operator approval to accept Android SDK licenses on disposable GitHub runners was obtained. CODENOMAD_ANDROID_ACCEPT_SDK_LICENSES=true is enabled; missing consent otherwise skips the APK job visibly, never masquerading as build success.

Validation and limitations

GitHub Android source and ARM64 debug APK jobs passed: run 37445939638. Artifact 11404225573, retained 7 days, contains the APK, SHA256SUMS.txt and merge-commit metadata (270aeb15191937f1bc6000e87ce1e074ed71d35a). Downloaded APK SHA256 matches the manifest: 91869629265115ae70bbc9451c22fc2ed0b0115fda75eda2d0b903e791cecd95 (114,529,716 bytes).

The existing packaged-transport verifier passed on that CI APK: owned Network Security Config, system-only trust/cleartext denial, mixed-content DEX, ARM64-only inventory, signature and ZIP alignment. This is static artifact inspection only, not installation or runtime/device acceptance. Immutable pinned actions emitted a nonblocking Node20→24 deprecation notice.

Stacked iOS source/handoff PR: #861 (no native app build). Its Linux source CI passed; Android source/APK job results must be checked separately in run 37445939638.

Latest-dev integration: locked npm install with desktop scripts disabled, mobile/UI/server typechecks, 19/19 mobile source tests without JDK skip, launcher Chromium across ten locales, Rust policy 4/4, ABI integrity 142 upstream files / 13 guard inputs, preview WebSocket/browser/security regressions passed locally. GitHub runs are separate evidence; inspect the actual source and APK jobs.

Earlier hardened ARM64 debug APK SHA256: c316a46a1ee42c2106dc85384f7e9b68ae54cfe80517bc1e9bea57201ad82bdd. This retained local artifact has never been installed/runtime-tested and is not a CI artifact. Android API/device/WebView/16-KiB behavior remains unqualified; no new local emulator/adb/ETW work is authorized.

Local native iOS experiments are stopped: no linked .app, IPA, installed simulator runtime or WKWebView acceptance. ABI/lifetime execution, supported Mac/device builder and signing remain follow-up gates. No merge, release signing, store publication or Shantur assignment/notification is requested.

Generated API copies, native outputs and environment-bound Mac probe are excluded without deleting local evidence. Most diff lines are licensed upstream vendor sources preserved byte-for-byte; packages/server/src/server/http-server.ts is ~2,370 lines and upstream vendor sources exceed normal file-size guidelines, with no unrelated refactor.

Introduce an isolated Tauri HTTPS remote companion with a ten-locale launcher, strict origin/transport and launcher-only native authority. Include the shared iOS source-owned Int32 ABI fix with upstream licenses, immutable provenance and pre-link integrity guards; no linked or device-qualified iOS app is claimed.

Harden preview HTTP/WebSocket credential and upstream TLS boundaries, retain no-reuse Undici containment and document residual dependencies. Add hosted mobile auth/upload, URL/authority and real loopback WebSocket/browser regressions. Apply targeted compatible npm remediation without changing desktop native sources.

Validate PR source, Java XML, launcher browser and Rust policy separately from an explicit SDK-license-gated ARM64 debug APK job. Pin actions, use read-only tokens, preserve no secrets/release/store paths and upload only short-lived test APK/hash artifacts. Exclude generated API copies and the environment-bound historical Mac probe without deleting them.

Integrate on current dev rather than carrying unrelated historical commits. Adapt the preview fixture to the current Config/I18n providers and normalize workflow test line endings for Windows checkouts. Local source19/19, launcher browser, ABI142/13, policy4/4 and security regressions pass; GitHub build and actual device acceptance remain distinct pending evidence.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant