From 4feff660e031f4381a87ce5b96d2f32cb1e959b2 Mon Sep 17 00:00:00 2001 From: franzap <_@franzap.com> Date: Tue, 20 Jan 2026 11:06:35 -0300 Subject: [PATCH] Clean up --- .github/workflows/repro.yml | 96 ----------------------------------- .gitignore | 2 - README.md | 10 +--- pubspec.lock | 24 ++++----- spec/guidelines/INVARIANTS.md | 2 +- 5 files changed, 14 insertions(+), 120 deletions(-) delete mode 100644 .github/workflows/repro.yml diff --git a/.github/workflows/repro.yml b/.github/workflows/repro.yml deleted file mode 100644 index 9c1a9ce..0000000 --- a/.github/workflows/repro.yml +++ /dev/null @@ -1,96 +0,0 @@ -name: Reproducible APK Proof - -on: - # push: - # branches: - # - reproducible-build - workflow_dispatch: - -jobs: - repro: - runs-on: ubuntu-22.04 - timeout-minutes: 90 - permissions: - contents: read - - steps: - - name: Free disk space (Docker/Android toolchain is large) - run: | - df -h - sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android /usr/local/share/boost || true - sudo apt-get clean || true - docker system prune -af || true - df -h - - - name: Checkout - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Show runner info - run: | - uname -a - lscpu | sed -n '1,30p' - docker version - docker info | sed -n '1,80p' - - - name: Make scripts executable - run: | - chmod +x repro/prove_repro.sh || true - chmod +x repro/build_in_container.sh || true - - - name: Set cache dirs (host paths) - run: | - echo "GRADLE_USER_HOME=${{ runner.temp }}/gradle" >> $GITHUB_ENV - echo "PUB_CACHE=${{ runner.temp }}/pub-cache" >> $GITHUB_ENV - mkdir -p "${{ runner.temp }}/gradle" "${{ runner.temp }}/pub-cache" - # The Docker image runs as a non-root "builder" user (uid != runner uid). - # Make the bind-mounted caches writable inside the container. - chmod -R a+rwx "${{ runner.temp }}/gradle" "${{ runner.temp }}/pub-cache" || true - - - name: Cache Gradle - uses: actions/cache@v4 - with: - path: ${{ runner.temp }}/gradle - key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }} - - - name: Cache Pub - uses: actions/cache@v4 - with: - path: ${{ runner.temp }}/pub-cache - key: pub-${{ runner.os }}-${{ hashFiles('pubspec.lock') }} - - - name: Run reproducibility proof (Docker) - run: | - bash repro/prove_repro.sh - - - name: Install diff tools - if: failure() - run: | - sudo apt-get update - sudo apt-get install -y diffoscope unzip - - - name: Diff APKs (if present) - if: failure() - run: | - ls -la .repro_out || true - A="$(ls -1 .repro_out/*-A-release.apk 2>/dev/null | head -n1 || true)" - B="$(ls -1 .repro_out/*-B-release.apk 2>/dev/null | head -n1 || true)" - echo "A=$A" - echo "B=$B" - if [ -n "$A" ] && [ -n "$B" ]; then - diffoscope "$A" "$B" --text .repro_out/diffoscope.txt || true - mkdir -p /tmp/apkA /tmp/apkB - unzip -q "$A" -d /tmp/apkA - unzip -q "$B" -d /tmp/apkB - diff -qr /tmp/apkA /tmp/apkB | head -n 200 > .repro_out/unzip-diff.txt || true - fi - - - name: Upload artifacts (.repro_out) - if: always() - uses: actions/upload-artifact@v4 - with: - name: repro-out-${{ github.sha }} - path: .repro_out - if-no-files-found: warn - include-hidden-files: true diff --git a/.gitignore b/.gitignore index dd9bce9..cbc072f 100644 --- a/.gitignore +++ b/.gitignore @@ -46,8 +46,6 @@ app.*.map.json /android/app/release /tmp -/flutter_data -.repro_out/ # FVM (commit only the version pin/config; never the SDK itself) !.fvmrc diff --git a/README.md b/README.md index f712aae..3a33422 100644 --- a/README.md +++ b/README.md @@ -15,17 +15,9 @@ APK will be available at `build/app/outputs/flutter-apk`. Get it on ZapStore + alt="Get it on Zapstore" width="200"> -> **Note on releases and reproducibility** -> -> Zapstore Android release APKs are expected to be **bit-for-bit reproducible** from -> the same git commit. -> -> Builds intended for verification (e.g. F-Droid or release auditing) must follow -> the pinned toolchain and deterministic build invariants described in `INVARIANTS.md`. - ## Contributing Unless it's a minor fix, please reach out to us first before working on any contribution! diff --git a/pubspec.lock b/pubspec.lock index 96efb8a..607adb5 100644 --- a/pubspec.lock +++ b/pubspec.lock @@ -581,26 +581,26 @@ packages: dependency: transitive description: name: leak_tracker - sha256: "33e2e26bdd85a0112ec15400c8cbffea70d0f9c3407491f672a2fad47915e2de" + sha256: "6bb818ecbdffe216e81182c2f0714a2e62b593f4a4f13098713ff1685dfb6ab0" url: "https://pub.dev" source: hosted - version: "11.0.2" + version: "10.0.9" leak_tracker_flutter_testing: dependency: transitive description: name: leak_tracker_flutter_testing - sha256: "1dbc140bb5a23c75ea9c4811222756104fbcd1a27173f0c34ca01e16bea473c1" + sha256: f8b613e7e6a13ec79cfdc0e97638fddb3ab848452eff057653abd3edba760573 url: "https://pub.dev" source: hosted - version: "3.0.10" + version: "3.0.9" leak_tracker_testing: dependency: transitive description: name: leak_tracker_testing - sha256: "8d5a2d49f4a66b49744b23b018848400d23e54caf9463f4eb20df3eb8acb2eb1" + sha256: "6ba465d5d76e67ddf503e1161d1f4a6bc42306f9d66ca1e8f079a47290fb06d3" url: "https://pub.dev" source: hosted - version: "3.0.2" + version: "3.0.1" lints: dependency: transitive description: @@ -653,10 +653,10 @@ packages: dependency: transitive description: name: meta - sha256: "23f08335362185a5ea2ad3a4e597f1375e78bce8a040df5c600c8d3552ef2394" + sha256: e3641ec5d63ebf0d9b41bd43201a66e3fc79a65db5f61fc181f04cd27aab950c url: "https://pub.dev" source: hosted - version: "1.17.0" + version: "1.16.0" mime: dependency: transitive description: @@ -1141,10 +1141,10 @@ packages: dependency: transitive description: name: test_api - sha256: ab2726c1a94d3176a45960b6234466ec367179b87dd74f1611adb1f3b5fb9d55 + sha256: fb31f383e2ee25fbbfe06b40fe21e1e458d14080e3c67e7ba0acfde4df4e0bbd url: "https://pub.dev" source: hosted - version: "0.7.7" + version: "0.7.4" timezone: dependency: transitive description: @@ -1261,10 +1261,10 @@ packages: dependency: transitive description: name: vector_math - sha256: d530bd74fea330e6e364cda7a85019c434070188383e1cd8d9777ee586914c5b + sha256: "80b3257d1492ce4d091729e3a67a60407d227c27241d6927be0130c98e741803" url: "https://pub.dev" source: hosted - version: "2.2.0" + version: "2.1.4" vm_service: dependency: transitive description: diff --git a/spec/guidelines/INVARIANTS.md b/spec/guidelines/INVARIANTS.md index 4712cd1..1f6fc55 100644 --- a/spec/guidelines/INVARIANTS.md +++ b/spec/guidelines/INVARIANTS.md @@ -46,7 +46,7 @@ If any invariant is violated, the implementation is incorrect. - Silent failures are unacceptable. -## Reproducible Android builds (Invariant) +## Reproducible Android builds Zapstore Android release artifacts MUST be bit-for-bit reproducible from the same git commit.