Skip to content

Release signing key with v3.1 key rotation (updates keep working) - #3

Merged
HighviewOne merged 1 commit into
masterfrom
claude/release-signing
Oct 5, 2026
Merged

HighviewOne merged 1 commit into
masterfrom
claude/release-signing

Conversation

@HighviewOne

Copy link
Copy Markdown
Owner

What does this PR do?

Moves releases off the Android debug key onto a dedicated release key without breaking updates.

Releases through v2.4 were signed with this machine's debug key. Signing the next release with a new key alone would make Android refuse it as an update, so players would have to uninstall and lose their progress. Instead, scripts/sign-release.sh signs with APK Signature Scheme v3.1 key rotation: a lineage file in which the old key vouches for the new one. The next release then installs as a normal update.

  • Verified on a real Android 14 device: a rotation-signed staging build installed as an update over the debug-signed staging app (install date kept), and the device now records both certificates.
  • The Gradle build is unchanged: release APKs stay unsigned, including in CI. All key material lives outside the repo, in ~/.config/circuitqueest/, backed up to hamptonserver. .gitignore now blocks keystore and lineage files.
  • docs/DEPLOYMENT.md gets a real Code Signing section covering the keys, the rotation, the backups, how to sign, and how to test an update before publishing.

Type of change

  • Bug fix
  • New topic / content addition
  • UI / animation enhancement
  • Refactor (no behavior change)
  • Build / tooling

Checklist

  • ./gradlew assembleDebug builds without errors (also assembleRelease and assembleStaging; the build files are unchanged)
  • ./gradlew detekt passes with no new violations
  • New topic follows *Content.kt format (n/a)
  • No hardcoded colors (n/a)
  • No new @Preview composables left in production files

🤖 Generated with Claude Code

Releases through v2.4 were signed with this machine's Android debug key.
Add a dedicated release key and sign releases with APK Signature Scheme
v3.1 key rotation (old key vouches for the new one via a lineage file), so
the next release still installs as an update over v2.4 — no uninstall, no
lost progress.

- scripts/sign-release.sh: signs an unsigned release APK with
  debug key -> release key rotation via apksigner; reads secrets from
  ~/.config/circuitqueest/ (passwords via env, not argv); no v4 sidecar.
- Gradle unchanged: release builds stay unsigned (CI too).
- Verified on a real Android 14 device: a rotated staging build installed
  as an update over the debug-signed staging app (firstInstallTime kept),
  and the package now records old + new signing certs.
- DEPLOYMENT.md: real Code Signing section (keys, rotation, backups,
  signing and pre-publish update test). .gitignore: key material patterns.
- RELEASE_NOTES: Unreleased entry.

Key material is outside the repo, backed up to
hamptonserver:~/backups/circuitqueest-signing/.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@HighviewOne
HighviewOne merged commit 117bb74 into master Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant