Merge remote-tracking branch 'origin/main' into atish/strip-media-metadata

* origin/main:
  fix(join-policy): require legal consent on hosted invites (#1987)
  [codex] Prevent actor-tag UI impersonation (#1931)
  chore(release): release Buzz Desktop version 0.4.9 (#1986)
  Restyle onboarding: branded landing screen, yellow/gradient backgrounds, new starter avatars (#1982)
  feat(acp): retry initial relay connection with terminal/transient error classification (#1922)
  feat(mobile): add external release signing mode for central APK Signer pipelines (#1972)
  Guide CLI installation and subscription sign-in (#1980)
  Scope relay runtime state by community (#1658)
  unify channel add + search into one entry point (#1964)
  Apply optional relay join policy across join flows (#1894)
  fix(desktop): preserve relaunch through mesh shutdown (#1966)
  Persist agent audiences with native inline mentions (#1949)
This commit is contained in:
Atish Patel
2026-07-16 14:13:49 -05:00
121 changed files with 7980 additions and 1111 deletions
+5
View File
@@ -42,6 +42,11 @@ environment:
The keystore path must be absolute, and the keystore must remain outside the
repository. Development and debug builds do not require these variables.
Release pipelines that sign through the central APK Signer service instead of
a local upload keystore must set `BUZZ_ANDROID_RELEASE_SIGNING=external`. That
mode produces an unsigned release bundle and refuses to run if any
`BUZZ_ANDROID_UPLOAD_*` value is also set.
## Architecture
```
+30 -1
View File
@@ -19,6 +19,28 @@ val uploadSigningValues =
val missingUploadSigningValues = uploadSigningValues.filterValues { it.isNullOrBlank() }.keys
val hasUploadSigning = missingUploadSigningValues.isEmpty()
// Release signing modes:
// - "upload-keystore" (default): sign with the CI-vended upload keystore;
// release builds fail loudly when any credential is missing.
// - "external": deliberately produce an UNSIGNED release bundle for a
// pipeline that signs through the central APK Signer service (Cashkite,
// BOT-1234). No keystore material may be present in this mode.
val releaseSigningMode =
providers.environmentVariable("BUZZ_ANDROID_RELEASE_SIGNING").orNull ?: "upload-keystore"
val externalReleaseSigning = releaseSigningMode == "external"
if (releaseSigningMode !in setOf("upload-keystore", "external")) {
throw GradleException(
"BUZZ_ANDROID_RELEASE_SIGNING must be \"upload-keystore\" or \"external\", got: " +
releaseSigningMode,
)
}
if (externalReleaseSigning && uploadSigningValues.values.any { !it.isNullOrBlank() }) {
throw GradleException(
"BUZZ_ANDROID_RELEASE_SIGNING=external must not be combined with " +
"BUZZ_ANDROID_UPLOAD_* credentials; unset one of them.",
)
}
android {
namespace = "xyz.block.buzz.mobile"
compileSdk = flutter.compileSdkVersion
@@ -67,10 +89,17 @@ gradle.taskGraph.whenReady {
val buildsRelease = allTasks.any { task ->
task.project == project && task.name in setOf("assembleRelease", "bundleRelease")
}
if (buildsRelease && externalReleaseSigning) {
// External signing: the unsigned bundle goes to the central APK
// Signer. All keystore checks are intentionally skipped; the
// guard above already rejected any BUZZ_ANDROID_UPLOAD_* values.
return@whenReady
}
if (buildsRelease && !hasUploadSigning) {
throw GradleException(
"Release builds require Android upload signing credentials. Missing: " +
missingUploadSigningValues.sorted().joinToString(", "),
missingUploadSigningValues.sorted().joinToString(", ") +
". For central APK Signer pipelines set BUZZ_ANDROID_RELEASE_SIGNING=external.",
)
}
if (buildsRelease) {