Compare commits

..
2 Commits
Author SHA1 Message Date
ARIA 5a69e3927b Fix CI: uv sync --extra dev; sdkmanager licenses without SIGPIPE
CI / Gateway plugin tests (push) Successful in 4m35s
CI / Kotlin tests (android host + desktop) (push) Successful in 6m37s
- pytest lives in hermes-agent's dev extra; plain uv sync left the CI venv
  without it and run_tests.sh refused to run (gateway job)
- 'yes | sdkmanager --licenses' dies with SIGPIPE (exit 141) under Gitea's
  bash -e -o pipefail; feed a finite number of y's from a file instead
  (kotlin + android jobs)
2026-08-22 03:42:15 +02:00
ARIA 1f182a7e7e Release: also build AAB; fix keystore key-password guidance
- release.yml android job: build APK + AAB (bundleRelease/bundleDebug)
- androidApp: versionCode overridable via -PappVersionCode (Play requires
  an incrementing versionCode per upload)
- make_release_keystore.sh: PKCS12 has no separate key password (keytool
  ignores -keypass) — print the store password for ANDROID_KEY_PASSWORD
2026-08-22 03:33:58 +02:00
4 changed files with 42 additions and 16 deletions

No files matched your search

+9 -3
View File
@@ -29,7 +29,9 @@ jobs:
run: | run: |
echo "$HOME/.local/bin" >> "$GITHUB_PATH" echo "$HOME/.local/bin" >> "$GITHUB_PATH"
cd hermes-agent cd hermes-agent
uv sync # pytest lives in the `dev` extra — a plain `uv sync` leaves the
# venv without it and run_tests.sh refuses to run.
uv sync --extra dev
- name: Run android gateway tests - name: Run android gateway tests
run: | run: |
@@ -62,7 +64,11 @@ jobs:
https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip
unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools" unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools"
mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest" mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest"
yes | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses > /dev/null # Finite input from a file: `yes | sdkmanager` dies with SIGPIPE
# (exit 141) under Gitea's `bash -e -o pipefail` once sdkmanager
# exits before `yes` is done writing.
for i in $(seq 100); do echo y; done > /tmp/sdk_licenses_yes.txt
"$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses < /tmp/sdk_licenses_yes.txt > /dev/null
echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV" echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV"
echo "sdk.dir=$ANDROID_HOME" > app/local.properties echo "sdk.dir=$ANDROID_HOME" > app/local.properties
@@ -70,4 +76,4 @@ jobs:
# missing SDK platforms (licenses accepted above). # missing SDK platforms (licenses accepted above).
- name: Run host tests - name: Run host tests
working-directory: app working-directory: app
run: ./gradlew :shared:testAndroidHostTest :shared:desktopTest run: ./gradlew :shared:testAndroidHostTest :shared:desktopTest
+25 -8
View File
@@ -32,7 +32,9 @@ jobs:
run: | run: |
echo "$HOME/.local/bin" >> "$GITHUB_PATH" echo "$HOME/.local/bin" >> "$GITHUB_PATH"
cd hermes-agent cd hermes-agent
uv sync # pytest lives in the `dev` extra — a plain `uv sync` leaves the
# venv without it and run_tests.sh refuses to run.
uv sync --extra dev
- name: Run android gateway tests - name: Run android gateway tests
run: | run: |
@@ -63,7 +65,11 @@ jobs:
https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip
unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools" unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools"
mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest" mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest"
yes | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses > /dev/null # Finite input from a file: `yes | sdkmanager` dies with SIGPIPE
# (exit 141) under Gitea's `bash -e -o pipefail` once sdkmanager
# exits before `yes` is done writing.
for i in $(seq 100); do echo y; done > /tmp/sdk_licenses_yes.txt
"$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses < /tmp/sdk_licenses_yes.txt > /dev/null
echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV" echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV"
echo "sdk.dir=$ANDROID_HOME" > app/local.properties echo "sdk.dir=$ANDROID_HOME" > app/local.properties
@@ -94,7 +100,11 @@ jobs:
https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip
unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools" unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools"
mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest" mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest"
yes | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses > /dev/null # Finite input from a file: `yes | sdkmanager` dies with SIGPIPE
# (exit 141) under Gitea's `bash -e -o pipefail` once sdkmanager
# exits before `yes` is done writing.
for i in $(seq 100); do echo y; done > /tmp/sdk_licenses_yes.txt
"$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses < /tmp/sdk_licenses_yes.txt > /dev/null
echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV" echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV"
echo "sdk.dir=$ANDROID_HOME" > app/local.properties echo "sdk.dir=$ANDROID_HOME" > app/local.properties
@@ -113,24 +123,31 @@ jobs:
echo "::warning::ANDROID_KEYSTORE_BASE64 secret not set — falling back to a DEBUG apk (see CI-SETUP.md §5)" echo "::warning::ANDROID_KEYSTORE_BASE64 secret not set — falling back to a DEBUG apk (see CI-SETUP.md §5)"
fi fi
- name: Build APK - name: Build APK + AAB
run: | run: |
VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH") VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH")
cd app cd app
if [ -n "$ANDROID_KEYSTORE_FILE" ]; then if [ -n "$ANDROID_KEYSTORE_FILE" ]; then
./gradlew :androidApp:assembleRelease -PappVersion="$VERSION" # APK for direct sideloading, AAB for Play Store uploads.
./gradlew :androidApp:assembleRelease :androidApp:bundleRelease -PappVersion="$VERSION"
cp androidApp/build/outputs/apk/release/androidApp-release.apk \ cp androidApp/build/outputs/apk/release/androidApp-release.apk \
"$GITHUB_WORKSPACE/iris-android-v$VERSION.apk" "$GITHUB_WORKSPACE/iris-android-v$VERSION.apk"
cp androidApp/build/outputs/bundle/release/androidApp-release.aab \
"$GITHUB_WORKSPACE/iris-android-v$VERSION.aab"
else else
./gradlew :androidApp:assembleDebug -PappVersion="$VERSION" ./gradlew :androidApp:assembleDebug :androidApp:bundleDebug -PappVersion="$VERSION"
cp androidApp/build/outputs/apk/debug/androidApp-debug.apk \ cp androidApp/build/outputs/apk/debug/androidApp-debug.apk \
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.apk" "$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.apk"
cp androidApp/build/outputs/bundle/debug/androidApp-debug.aab \
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.aab"
fi fi
- uses: actions/upload-artifact@v4 - uses: actions/upload-artifact@v4
with: with:
name: android name: android
path: iris-android-*.apk path: |
iris-android-*.apk
iris-android-*.aab
desktop: desktop:
name: Build desktop (Linux, jpackage) name: Build desktop (Linux, jpackage)
@@ -217,4 +234,4 @@ jobs:
curl -sf -X POST -H "$AUTH" -F "attachment=@$f" \ curl -sf -X POST -H "$AUTH" -F "attachment=@$f" \
"$API/releases/$RELEASE_ID/attachments" > /dev/null "$API/releases/$RELEASE_ID/attachments" > /dev/null
done done
echo "Done: $SERVER/$REPO/releases/tag/$TAG" echo "Done: $SERVER/$REPO/releases/tag/$TAG"
+4 -2
View File
@@ -13,7 +13,9 @@ android {
applicationId = "dev.iris.app" applicationId = "dev.iris.app"
minSdk = 29 minSdk = 29
targetSdk = 34 targetSdk = 34
versionCode = 1 // Play Store requires an incrementing versionCode per upload; CI can
// pass -PappVersionCode=<n>. Local builds keep the default.
versionCode = (project.findProperty("appVersionCode")?.toString()?.toIntOrNull()) ?: 1
// CI passes -PappVersion=<version> (release workflow); local builds // CI passes -PappVersion=<version> (release workflow); local builds
// keep the default. // keep the default.
versionName = (project.findProperty("appVersion") as? String) ?: "0.1.0" versionName = (project.findProperty("appVersion") as? String) ?: "0.1.0"
@@ -80,4 +82,4 @@ dependencies {
// inert and the ntfy listener is the push path. // inert and the ntfy listener is the push path.
if (file("google-services.json").exists()) { if (file("google-services.json").exists()) {
apply(plugin = "com.google.gms.google-services") apply(plugin = "com.google.gms.google-services")
} }
+4 -3
View File
@@ -16,13 +16,14 @@ if [ -e "$OUT" ]; then
exit 1 exit 1
fi fi
# PKCS12 keystores do not support a separate key password (keytool ignores
# -keypass), so one password covers both the store and the key.
STORE_PASS="$(openssl rand -base64 18 | tr -d '/+=')" STORE_PASS="$(openssl rand -base64 18 | tr -d '/+=')"
KEY_PASS="$(openssl rand -base64 18 | tr -d '/+=')"
keytool -genkeypair -v \ keytool -genkeypair -v \
-keystore "$OUT" -storetype PKCS12 \ -keystore "$OUT" -storetype PKCS12 \
-alias iris -keyalg RSA -keysize 2048 -validity 10000 \ -alias iris -keyalg RSA -keysize 2048 -validity 10000 \
-storepass "$STORE_PASS" -keypass "$KEY_PASS" \ -storepass "$STORE_PASS" \
-dname "CN=Iris Release, OU=Mobile, O=Iris, C=DE" -dname "CN=Iris Release, OU=Mobile, O=Iris, C=DE"
echo echo
@@ -35,4 +36,4 @@ echo " ANDROID_KEYSTORE_BASE64 = $(base64 -w0 "$OUT")"
echo echo
echo " ANDROID_KEYSTORE_PASSWORD = $STORE_PASS" echo " ANDROID_KEYSTORE_PASSWORD = $STORE_PASS"
echo " ANDROID_KEY_ALIAS = iris" echo " ANDROID_KEY_ALIAS = iris"
echo " ANDROID_KEY_PASSWORD = $KEY_PASS" echo " ANDROID_KEY_PASSWORD = $STORE_PASS # same: PKCS12 has no separate key password"