This commit is contained in:
franzap
2026-01-20 11:06:35 -03:00
parent 628f965c66
commit 4feff660e0
5 changed files with 14 additions and 120 deletions
-96
View File
@@ -1,96 +0,0 @@
name: Reproducible APK Proof
on:
# push:
# branches:
# - reproducible-build
workflow_dispatch:
jobs:
repro:
runs-on: ubuntu-22.04
timeout-minutes: 90
permissions:
contents: read
steps:
- name: Free disk space (Docker/Android toolchain is large)
run: |
df -h
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android /usr/local/share/boost || true
sudo apt-get clean || true
docker system prune -af || true
df -h
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Show runner info
run: |
uname -a
lscpu | sed -n '1,30p'
docker version
docker info | sed -n '1,80p'
- name: Make scripts executable
run: |
chmod +x repro/prove_repro.sh || true
chmod +x repro/build_in_container.sh || true
- name: Set cache dirs (host paths)
run: |
echo "GRADLE_USER_HOME=${{ runner.temp }}/gradle" >> $GITHUB_ENV
echo "PUB_CACHE=${{ runner.temp }}/pub-cache" >> $GITHUB_ENV
mkdir -p "${{ runner.temp }}/gradle" "${{ runner.temp }}/pub-cache"
# The Docker image runs as a non-root "builder" user (uid != runner uid).
# Make the bind-mounted caches writable inside the container.
chmod -R a+rwx "${{ runner.temp }}/gradle" "${{ runner.temp }}/pub-cache" || true
- name: Cache Gradle
uses: actions/cache@v4
with:
path: ${{ runner.temp }}/gradle
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
- name: Cache Pub
uses: actions/cache@v4
with:
path: ${{ runner.temp }}/pub-cache
key: pub-${{ runner.os }}-${{ hashFiles('pubspec.lock') }}
- name: Run reproducibility proof (Docker)
run: |
bash repro/prove_repro.sh
- name: Install diff tools
if: failure()
run: |
sudo apt-get update
sudo apt-get install -y diffoscope unzip
- name: Diff APKs (if present)
if: failure()
run: |
ls -la .repro_out || true
A="$(ls -1 .repro_out/*-A-release.apk 2>/dev/null | head -n1 || true)"
B="$(ls -1 .repro_out/*-B-release.apk 2>/dev/null | head -n1 || true)"
echo "A=$A"
echo "B=$B"
if [ -n "$A" ] && [ -n "$B" ]; then
diffoscope "$A" "$B" --text .repro_out/diffoscope.txt || true
mkdir -p /tmp/apkA /tmp/apkB
unzip -q "$A" -d /tmp/apkA
unzip -q "$B" -d /tmp/apkB
diff -qr /tmp/apkA /tmp/apkB | head -n 200 > .repro_out/unzip-diff.txt || true
fi
- name: Upload artifacts (.repro_out)
if: always()
uses: actions/upload-artifact@v4
with:
name: repro-out-${{ github.sha }}
path: .repro_out
if-no-files-found: warn
include-hidden-files: true
-2
View File
@@ -46,8 +46,6 @@ app.*.map.json
/android/app/release
/tmp
/flutter_data
.repro_out/
# FVM (commit only the version pin/config; never the SDK itself)
!.fvmrc
+1 -9
View File
@@ -15,17 +15,9 @@ APK will be available at `build/app/outputs/flutter-apk`.
<a href="https://zapstore.dev/apps/naddr1qvzqqqr7pvpzq7xwd748yfjrsu5yuerm56fcn9tntmyv04w95etn0e23xrczvvraqqgxgetk9eaxzurnw3hhyefwv9c8qakg5jt">
<img src="./assets/images/badge.png"
alt="Get it on ZapStore" width="200">
alt="Get it on Zapstore" width="200">
</a>
> **Note on releases and reproducibility**
>
> Zapstore Android release APKs are expected to be **bit-for-bit reproducible** from
> the same git commit.
>
> Builds intended for verification (e.g. F-Droid or release auditing) must follow
> the pinned toolchain and deterministic build invariants described in `INVARIANTS.md`.
## Contributing
Unless it's a minor fix, please reach out to us first before working on any contribution!
+12 -12
View File
@@ -581,26 +581,26 @@ packages:
dependency: transitive
description:
name: leak_tracker
sha256: "33e2e26bdd85a0112ec15400c8cbffea70d0f9c3407491f672a2fad47915e2de"
sha256: "6bb818ecbdffe216e81182c2f0714a2e62b593f4a4f13098713ff1685dfb6ab0"
url: "https://pub.dev"
source: hosted
version: "11.0.2"
version: "10.0.9"
leak_tracker_flutter_testing:
dependency: transitive
description:
name: leak_tracker_flutter_testing
sha256: "1dbc140bb5a23c75ea9c4811222756104fbcd1a27173f0c34ca01e16bea473c1"
sha256: f8b613e7e6a13ec79cfdc0e97638fddb3ab848452eff057653abd3edba760573
url: "https://pub.dev"
source: hosted
version: "3.0.10"
version: "3.0.9"
leak_tracker_testing:
dependency: transitive
description:
name: leak_tracker_testing
sha256: "8d5a2d49f4a66b49744b23b018848400d23e54caf9463f4eb20df3eb8acb2eb1"
sha256: "6ba465d5d76e67ddf503e1161d1f4a6bc42306f9d66ca1e8f079a47290fb06d3"
url: "https://pub.dev"
source: hosted
version: "3.0.2"
version: "3.0.1"
lints:
dependency: transitive
description:
@@ -653,10 +653,10 @@ packages:
dependency: transitive
description:
name: meta
sha256: "23f08335362185a5ea2ad3a4e597f1375e78bce8a040df5c600c8d3552ef2394"
sha256: e3641ec5d63ebf0d9b41bd43201a66e3fc79a65db5f61fc181f04cd27aab950c
url: "https://pub.dev"
source: hosted
version: "1.17.0"
version: "1.16.0"
mime:
dependency: transitive
description:
@@ -1141,10 +1141,10 @@ packages:
dependency: transitive
description:
name: test_api
sha256: ab2726c1a94d3176a45960b6234466ec367179b87dd74f1611adb1f3b5fb9d55
sha256: fb31f383e2ee25fbbfe06b40fe21e1e458d14080e3c67e7ba0acfde4df4e0bbd
url: "https://pub.dev"
source: hosted
version: "0.7.7"
version: "0.7.4"
timezone:
dependency: transitive
description:
@@ -1261,10 +1261,10 @@ packages:
dependency: transitive
description:
name: vector_math
sha256: d530bd74fea330e6e364cda7a85019c434070188383e1cd8d9777ee586914c5b
sha256: "80b3257d1492ce4d091729e3a67a60407d227c27241d6927be0130c98e741803"
url: "https://pub.dev"
source: hosted
version: "2.2.0"
version: "2.1.4"
vm_service:
dependency: transitive
description:
+1 -1
View File
@@ -46,7 +46,7 @@ If any invariant is violated, the implementation is incorrect.
- Silent failures are unacceptable.
## Reproducible Android builds (Invariant)
## Reproducible Android builds
Zapstore Android release artifacts MUST be bit-for-bit reproducible from the same git commit.