Release signing key with v3.1 key rotation (updates keep working) - #3
Merged
Merged
Conversation
Releases through v2.4 were signed with this machine's Android debug key. Add a dedicated release key and sign releases with APK Signature Scheme v3.1 key rotation (old key vouches for the new one via a lineage file), so the next release still installs as an update over v2.4 — no uninstall, no lost progress. - scripts/sign-release.sh: signs an unsigned release APK with debug key -> release key rotation via apksigner; reads secrets from ~/.config/circuitqueest/ (passwords via env, not argv); no v4 sidecar. - Gradle unchanged: release builds stay unsigned (CI too). - Verified on a real Android 14 device: a rotated staging build installed as an update over the debug-signed staging app (firstInstallTime kept), and the package now records old + new signing certs. - DEPLOYMENT.md: real Code Signing section (keys, rotation, backups, signing and pre-publish update test). .gitignore: key material patterns. - RELEASE_NOTES: Unreleased entry. Key material is outside the repo, backed up to hamptonserver:~/backups/circuitqueest-signing/. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Moves releases off the Android debug key onto a dedicated release key without breaking updates.
Releases through v2.4 were signed with this machine's debug key. Signing the next release with a new key alone would make Android refuse it as an update, so players would have to uninstall and lose their progress. Instead,
scripts/sign-release.shsigns with APK Signature Scheme v3.1 key rotation: a lineage file in which the old key vouches for the new one. The next release then installs as a normal update.~/.config/circuitqueest/, backed up to hamptonserver..gitignorenow blocks keystore and lineage files.docs/DEPLOYMENT.mdgets a real Code Signing section covering the keys, the rotation, the backups, how to sign, and how to test an update before publishing.Type of change
Checklist
./gradlew assembleDebugbuilds without errors (alsoassembleReleaseandassembleStaging; the build files are unchanged)./gradlew detektpasses with no new violations*Content.ktformat (n/a)@Previewcomposables left in production files🤖 Generated with Claude Code