From 0646dc8b828a97fe4a2c889e9e329d1287766bec Mon Sep 17 00:00:00 2001 From: l0ng-ai <24760907+l0ng-ai@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:45:00 +0800 Subject: [PATCH] ci(mobile): match the signing digest whatever apksigner calls the signer (#1047) --- .github/workflows/mobile.yml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/.github/workflows/mobile.yml b/.github/workflows/mobile.yml index 3e6da266..21b1bb9b 100644 --- a/.github/workflows/mobile.yml +++ b/.github/workflows/mobile.yml @@ -108,9 +108,14 @@ jobs: set -euo pipefail APK=mobile/src-tauri/gen/android/app/build/outputs/apk/universal/release/app-universal-release.apk APKSIGNER=$(ls -d "$ANDROID_HOME"/build-tools/* | sort -V | tail -1)/apksigner - CERT=$("$APKSIGNER" verify --print-certs "$APK" | sed -n 's/^Signer #1 certificate SHA-256 digest: //p') - if [ "$CERT" != "$CERT_SHA256" ]; then - echo "::error::APK is signed with $CERT, not the release key" + # Newer apksigners name the signer by its SDK range ("Signer + # (minSdkVersion=24, …)") rather than "Signer #1", so only the + # digest itself is matched. Every signer must be the release key. + CERTS=$("$APKSIGNER" verify --print-certs "$APK") + DIGESTS=$(grep -o 'certificate SHA-256 digest: [0-9a-f]*' <<<"$CERTS" | awk '{print $NF}' | sort -u) + if [ "$DIGESTS" != "$CERT_SHA256" ]; then + echo "$CERTS" + echo "::error::APK is not signed with the release key alone" exit 1 fi mkdir dist