name: Android build permissions: contents: write releases: write on: push: branches: - '**' pull_request: release: types: - published workflow_dispatch: jobs: build: runs-on: ubuntu-latest timeout-minutes: 90 steps: - name: Checkout uses: actions/checkout@v4 - name: Set up Java 17 uses: actions/setup-java@v5 with: distribution: temurin java-version: '17' - name: Install Android SDK command-line tools and packages shell: bash run: | set -euxo pipefail export ANDROID_SDK_ROOT="$HOME/.android/sdk" export ANDROID_HOME="$ANDROID_SDK_ROOT" mkdir -p "$ANDROID_SDK_ROOT/cmdline-tools" if [ ! -x "$ANDROID_SDK_ROOT/cmdline-tools/latest/bin/sdkmanager" ]; then tools_url="$(curl -fsSL https://developer.android.com/studio | grep -o 'https://dl.google.com/android/repository/commandlinetools-linux-[0-9][0-9]*_latest.zip' | head -n 1)" test -n "$tools_url" curl -fsSL -o /tmp/commandlinetools.zip "$tools_url" rm -rf "$ANDROID_SDK_ROOT/cmdline-tools/latest" "$ANDROID_SDK_ROOT/cmdline-tools/cmdline-tools" unzip -q /tmp/commandlinetools.zip -d "$ANDROID_SDK_ROOT/cmdline-tools" mv "$ANDROID_SDK_ROOT/cmdline-tools/cmdline-tools" "$ANDROID_SDK_ROOT/cmdline-tools/latest" fi export PATH="$ANDROID_SDK_ROOT/cmdline-tools/latest/bin:$ANDROID_SDK_ROOT/platform-tools:$PATH" set +o pipefail yes | sdkmanager --licenses >/dev/null set -o pipefail sdkmanager \ "platform-tools" \ "platforms;android-36" \ "build-tools;36.0.0" \ "ndk;27.2.12479018" \ "cmake;3.22.1" - name: Prepare optional release signing if: github.event_name == 'release' continue-on-error: true env: ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }} ANDROID_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }} ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }} ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }} shell: bash run: | set -euo pipefail missing=() for key in ANDROID_KEYSTORE_BASE64 ANDROID_KEYSTORE_PASSWORD ANDROID_KEY_ALIAS ANDROID_KEY_PASSWORD; do if [ -z "${!key:-}" ]; then missing+=("$key") fi done if [ ${#missing[@]} -gt 0 ]; then printf -v missing_csv '%s, ' "${missing[@]}" missing_csv="${missing_csv%, }" echo "::error::Release signing secrets missing: ${missing_csv}. Continuing with unsigned/default-signed release AAB." exit 1 fi mkdir -p .ci-secrets printf '%s' "$ANDROID_KEYSTORE_BASE64" | base64 -d > .ci-secrets/release-keystore.jks cat > keystore.properties < local.properties - name: Install Rust toolchain shell: bash run: | set -euxo pipefail if ! command -v cargo >/dev/null 2>&1; then curl https://sh.rustup.rs -sSf | sh -s -- -y --profile minimal fi echo "$HOME/.cargo/bin" >> "$GITHUB_PATH" export PATH="$HOME/.cargo/bin:$PATH" cargo --version rustc --version rustup target add aarch64-linux-android armv7-linux-androideabi i686-linux-android x86_64-linux-android - name: Compile bundled native Git binaries shell: bash run: | set -euxo pipefail export PATH="$HOME/.cargo/bin:$PATH" export ANDROID_SDK_ROOT="$HOME/.android/sdk" export ANDROID_HOME="$ANDROID_SDK_ROOT" chmod +x ./AndroidProjectTooling.sh bash ./AndroidProjectTooling.sh --compile-android-git - name: Prepare CI build metadata id: build_meta shell: bash run: | set -euxo pipefail timestamp_utc="$(date -u +%Y%m%d-%H%M%S)" version_code="$(date -u +%s)" project_name="$(basename "$GITHUB_REPOSITORY")" python3 - "$version_code" <<'PY' from pathlib import Path import re, sys path = Path('app/build.gradle.kts') text = path.read_text(encoding='utf-8') new_text, count = re.subn(r'(\bversionCode\s*=\s*)\d+', rf'\g<1>{sys.argv[1]}', text, count=1) if count != 1: raise SystemExit('versionCode not found in app/build.gradle.kts') path.write_text(new_text, encoding='utf-8') PY echo "Using CI versionCode: $version_code" echo "project_name=$project_name" >> "$GITHUB_OUTPUT" echo "timestamp_utc=$timestamp_utc" >> "$GITHUB_OUTPUT" echo "version_code=$version_code" >> "$GITHUB_OUTPUT" - name: Build debug APK if: github.event_name != 'release' shell: bash run: | set -euxo pipefail export ANDROID_SDK_ROOT="$HOME/.android/sdk" export ANDROID_HOME="$ANDROID_SDK_ROOT" ./gradlew --no-daemon clean assembleDebug - name: Verify debug APK bundles native Git if: github.event_name != 'release' shell: bash run: | set -euxo pipefail python3 - <<'PY' from pathlib import Path import zipfile apk = next(Path('app/build/outputs/apk/debug').glob('*.apk')) with zipfile.ZipFile(apk) as zf: names = zf.namelist() required = { 'lib/arm64-v8a/libgit.so', 'lib/armeabi-v7a/libgit.so', 'lib/x86/libgit.so', 'lib/x86_64/libgit.so', } found = {name for name in names if name in required} print('APK_NATIVE_GIT', sorted(found)) missing = sorted(required - found) if missing: raise SystemExit(f'Missing native Git libraries in {apk}: {missing}') PY - name: Build release AAB if: github.event_name == 'release' shell: bash run: | set -euxo pipefail export ANDROID_SDK_ROOT="$HOME/.android/sdk" export ANDROID_HOME="$ANDROID_SDK_ROOT" ./gradlew --no-daemon bundleRelease - name: Verify release AAB bundles native Git if: github.event_name == 'release' shell: bash run: | set -euxo pipefail python3 - <<'PY' from pathlib import Path import zipfile aab = next(Path('app/build/outputs/bundle/release').glob('*.aab')) with zipfile.ZipFile(aab) as zf: names = zf.namelist() required = { 'base/lib/arm64-v8a/libgit.so', 'base/lib/armeabi-v7a/libgit.so', 'base/lib/x86/libgit.so', 'base/lib/x86_64/libgit.so', } found = {name for name in names if name in required} print('AAB_NATIVE_GIT', sorted(found)) missing = sorted(required - found) if missing: raise SystemExit(f'Missing native Git libraries in {aab}: {missing}') PY - name: Rename release AAB for upload if: github.event_name == 'release' id: release_aab shell: bash run: | set -euxo pipefail aab="$(find app/build/outputs/bundle/release -name '*.aab' | head -n 1)" renamed="app/build/outputs/bundle/release/${{ steps.build_meta.outputs.project_name }}-${{ steps.build_meta.outputs.timestamp_utc }}-release.aab" mv -f "$aab" "$renamed" echo "Renamed release AAB to $(basename "$renamed")" echo "path=$renamed" >> "$GITHUB_OUTPUT" - name: Upload debug APK if: github.event_name != 'release' uses: actions/upload-artifact@v3 with: name: debug-apk path: app/build/outputs/apk/debug/*.apk if-no-files-found: error - name: Attach release AAB to Gitea release if: github.event_name == 'release' env: GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} GITHUB_TOKEN: ${{ github.token }} shell: bash run: | set -euxo pipefail token="${GITHUB_TOKEN:-${GITEA_TOKEN:-}}" if [ -z "$token" ]; then echo "::error::No release upload token is available from secrets.GITEA_TOKEN or github.token" exit 1 fi release_id="$(python3 -c 'import json, os; print(json.load(open(os.environ["GITHUB_EVENT_PATH"], encoding="utf-8"))["release"]["id"])')" aab="${{ steps.release_aab.outputs.path }}" curl --fail-with-body \ --request POST \ --header "Authorization: token ${token}" \ --form "attachment=@${aab}" \ "${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}/releases/${release_id}/assets?name=$(basename "$aab")"