19 Apr 2021 |
_hc | izzy: looking at the issuebot problem now | 10:04:56 |
izzy | Great, thanks! | 10:05:35 |
_hc | 幸猫: did you have a look at the test builds since apksigcopier was merged? https://jenkins.debian.net/job/reproducible_fdroid_build_apps/1146/consoleFull | 14:52:31 |
_hc | at the very least, some are verifying, now we have something to incrementally improve | 14:52:54 |
_hc | uniq or izzy could you toot about ga_trackingId and apps being marked with Tracking Anti-Feature? I guess link to this merge request d!7898 | 15:26:19 |
[gibot] | [data] !7898: mark apps/builds with ga_trackingId set with Trac… - https://gitlab.com/fdroid/fdroiddata/merge_requests/7898 | 15:26:21 |
_hc | something like: "we are now running automated scanners for API Key Identifiers in the binary APK files to find trackers. If your app includes these, it will be marked with Trackers . To fix that, either remove the tracking API Key entirely or move it out of the build flavor used by F-Droid" | 15:28:24 |
_hc | feel free to edit | 15:28:28 |
_hc | or maybe:
We are now automatically scanning apps for API Key Identifiers like #GoogleAnalytics' ga_trackingId that are used to enable tracking APIs. If your app includes these, it will be marked with the Trackers Anti-Feature. To fix that, either remove the tracking API Key entirely or move it out of the build flavor used by F-Droid"
| 15:30:14 |
izzy | Toot sent! | 15:33:37 |
izzy | Any findings concerning issuebot yet? | 15:34:32 |
_hc | yeah, I think I fixed the issues, I pinged you in the merge rquests | 15:35:11 |
izzy | Ah, good – thanks! Didn't get yet to that inbox. Will do soon. | 15:36:02 |
@obfusk:matrix.org | In reply to @eighthave:matrix.org 幸猫: did you have a look at the test builds since apksigcopier was merged? https://jenkins.debian.net/job/reproducible_fdroid_build_apps/1146/consoleFull I hadn't yet. Looking at that build log I see "ERROR: APK Signature Scheme v2 signer #1: Malformed additional attribute #1" on the "unsigned/binaries/" APK (for eu.bubu1.fdroidclassic_1106 and de.corona.tracing_1150100). that seems to be an issue with apksigner, not apksigcopier. | 18:12:05 |
@obfusk:matrix.org | (some other apps also fail, but those seem to be the same failures we'd already identified) | 18:12:51 |
cdesai | Is having multiple different repos with the same fingerprint a valid / supported use-case? | 23:47:50 |
cdesai | I have a few repos setup on gitlab for CalyxOS testing, and they're all using the same fingerprint | 23:48:57 |
cdesai | https://gitlab.com/CalyxOS?filter=calyx-fdroid-repo | 23:48:57 |
cdesai | Usually you'd only add the first one, and the repo for your own device, but F-Droid will detect to be a mirror | 23:48:58 |
20 Apr 2021 |
_hc | cdesai: each repo must have its own signing key. A repo is defined in fdroidclient by its signing key first and foremost | 06:48:59 |
_hc | otherwise, there is no other way to detect mirrors | 06:49:23 |
_hc | in the docs, it says to start a new repo with fdroid init , which generates a new key | 06:53:02 |
jochensp | linsui: could you have a look into https://monitor.f-droid.org/builds/log/com.mirfatif.permissionmanagerx/106 | 07:38:33 |
@rdfg77:kde.org | IIRC ndk path should be /home/vagrant/android-ndk/r22b instead of /home/vagrant/android-sdk/ndk/22.1.7171670 ? | 08:05:11 |
jochensp | ah, good point | 08:10:19 |
_hc | uniq or izzy here's a toot:
Try out our new #ReproducibleBuilds support! All signature types are supported The "fdroid build" CI job on app merge requests will run a complete test and give rapid results before sending it to the production buildserver.
| 08:35:05 |
uniq | done. | 08:37:46 |
uniq | _hc Do you think we could deploy HTTP-Headers for disabling FLoC to F-Droid web servers? | 08:38:40 |
@festplattenschnitzel:matrix.org | In reply to @eighthave:matrix.org
uniq or izzy here's a toot:
Try out our new #ReproducibleBuilds support! All signature types are supported The "fdroid build" CI job on app merge requests will run a complete test and give rapid results before sending it to the production buildserver.
I doubt the message misses a "." (dot) after "supported" before "The". | 08:42:06 |
| nug left the room. | 09:00:17 |