F-Droid Devs

114 Members
F-Droid development discussion only | Use #fdroid:f-droid.org for general, app- and repo-related matters | Meeting every Thursday at 11:30 UTC | This channel is publicly logged at https://matrix.f-droid.org/alias/%23fdroid-dev:f-droid.org 19 Servers

Load older messages


SenderMessageTime
20 Apr 2021
@freenode_jochensp:matrix.orgjochensp _hc: there are a number of traceback in the issuebot run, are you aware of that? 17:55:42
@eighthave:matrix.org_hc jochensp: as far as I can tell, they were there before, but now they are exposed, since it shows the whole trackback 18:03:12
@eighthave:matrix.org_hc izzy: seems like issuebot didn't find an APK 18:04:25
@eighthave:matrix.org_hc also, that the fdroid build failure is from the fdroid build --scan-binary. issuebot doesn't have that (yet?) 18:05:59
@freenode_jochensp:matrix.orgjochensp _hc: but: โœ“ Built build/app/outputs/flutter-apk/app-release.apk (35.3MB). 18:07:53
@eighthave:matrix.org_hc I have some sketches for issuebot modules that do what fdroid build --scan-binary does, but more reliably. they use gradle to run the build, and output which libs are used. I can send them to anyone who'd like to work on them 18:10:19
@freenode_smichel17:matrix.org@freenode_smichel17:matrix.org joined the room.18:56:43
@freenode_izzy:matrix.orgizzy _hc <seems like _issuebot_ didn't find an APK> then my bot would have produced an empty report. But it explicitly wreote it found no libs, so it must have had an APK to scan. 18:58:15
@freenode_izzy:matrix.orgizzy Let me quote: "<h3>APK library scanner</h3> <details>\n <summary>unsigned/com.hanntech.free2pass_8.apk</summary>\n No offending libs found.\n</details>\n" โ€“ so it had some "unsigned/com.hanntech.free2pass_8.apk" which then didn't make it to the artifacts. 18:59:57
@freenode_izzy:matrix.orgizzyAnd that confuses me.19:01:05
@obfusk:matrix.org@obfusk:matrix.org
In reply to @eighthave:matrix.org
a v4 sig is functionally the same as v2/v3 an a PGP detached sig, so if we can get APKs to pass v2/v3, then the associated v4 sig file will also work
yes. I hadn't looked at all the details yet so wasn't sure if there was more to it, but v4 seems to be an optional detached .apk.idsig signature file (and still requires a v1/v2/v3 signature as well). so it should work, as you said :) I don't think the version of apksigner in Debian supports v4 yet though, so I'd have to get a newer version to test. though unless those signature files are also being distributed, being "supported" doesn't really mean anything in practice *yet* (even if it's true). it does look like (newer versions of) adb will also validate them, so it's not just used for Play it seems.
19:57:30
@freenode_cdesai:matrix.orgcdesaiapksigner has been generating those files here when signing chromium19:58:17
@obfusk:matrix.org@obfusk:matrix.org _hc: I finally managed to get one of my python-for-android apps to build identically on stretch and buster, so I'll probably have another RB test case soonish. 20:00:03
@obfusk:matrix.org@obfusk:matrix.org
In reply to @freenode_cdesai:matrix.org
apksigner has been generating those files here when signing chromium
I think the CI run for my MR to add signatures to one of my apps also generated one.
20:01:34
@obfusk:matrix.org@obfusk:matrix.orgaccording to https://source.android.com/security/apksigning/v4 v4 verification failures are more or less ignored though ๐Ÿ˜•20:04:25
21 Apr 2021
@freenode_izzy:matrix.orgizzy _hc: again on the library scanner with above MR. I wonder what APK it eats there. When running it locally on the very same APK from artifacts, it reports "2 offenders". Running via the pipeline, it states "no offenders". I'm confused. Once you've merged my update, reportData will hopefully give more details. 07:53:32
@eighthave:matrix.org_hc izzy: yeah, seems like there is a bug there. I'm currently deep in Tor work, so I be able to look at this for a while. please file issues against issuebot when you find things like that and ping me if you want me to respond sooner rather than later 08:01:49
@eighthave:matrix.org_hc ๅนธ็Œซ: cdesai I mostly mentioned v4 signatures because I thought people would ask, and it is easier to say "all signature types" rather than listing out the types 08:02:35
@eighthave:matrix.org_hcv4 signatures are not relevant in F-Droid only Google Play AFAIK08:02:48
@eighthave:matrix.org_hcF-Droid alreay provides two signatures that are equivalent to the v4: gpg and the sha256 in the signed index08:03:21
@freenode_izzy:matrix.orgizzyThanks _hc[m]! Maybe you could merge my latest MR? I cleaned up a little bit and now include full scan results with reportData, that might help me tracking things down.08:04:21
@eighthave:matrix.org_hci'll look now08:04:32
@freenode_izzy:matrix.orgizzyThanks!08:04:38
@eighthave:matrix.org_hcalso, FYI, I'm ok with you self merging on the php stuff, and others with Developer access can merge08:05:25
@freenode_jochensp:matrix.orgjochensp _hc: I can't merge MRs in the issuebot repo 08:06:15
@freenode_jochensp:matrix.orgjochensp(otherwise I would have don it)08:06:24
@freenode_jochensp:matrix.orgjochensp*done08:06:27
@eighthave:matrix.org_hcoh? I though you had Developer access in the group?08:06:40
@freenode_jochensp:matrix.orgjochenspyes08:06:46
@freenode_izzy:matrix.orgizzy I don't have merge privileges at issuebot โ€“ but yeah, I'd be fine with self-merging things I feel confident with (which matches "the php stuff" here and not much more). I'd of course keep fingers off stuff I cannot confidently confirm ;) 08:06:50

Show newer messages


Back to Room ListRoom Version: 1