From 74a4e3d494bff97166bc810bd64d8247b301bc95 Mon Sep 17 00:00:00 2001 From: WaterRain <109326062+CATMIAOZHI@users.noreply.github.com> Date: Mon, 20 Jul 2026 13:03:22 +0000 Subject: [PATCH] =?UTF-8?q?fix:=20=E7=AD=BE=E5=90=8D=20fallback=20?= =?UTF-8?q?=E9=99=90=E5=88=B6=E5=88=B0=20CI=20=E7=8E=AF=E5=A2=83=EF=BC=8C?= =?UTF-8?q?=E6=9C=AC=E5=9C=B0=E6=9E=84=E5=BB=BA=E7=BC=BA=20release.jks=20?= =?UTF-8?q?=E6=97=B6=E6=8A=A5=E9=94=99?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 修复 chatgpt-codex-connector review 指出的问题: 原逻辑在任何机器缺 release.jks 时都静默 fallback 到 debug keystore, 可能生成不安全的 debug 签名 Release APK 而无任何错误提示。 改为仅 CI=true 时才 fallback,本地构建直接 GradleException 报错。 --- AGENTS.md | 2 +- app/build.gradle.kts | 21 +++++++++++++++------ 2 files changed, 16 insertions(+), 7 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index cccc396..f09bb93 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -183,7 +183,7 @@ Expanded(平板,≥840dp): 1. `test`:`testDebugUnitTest` + `lintDebug`,上传 XML 测试报告 + lint 报告 artifact 2. `build-debug`:`assembleDebug`,上传 Debug APK artifact 3. `build-release`:`assembleRelease` + APK 完整性验证(`AndroidManifest.xml` + `resources.arsc` + `res/`),上传 Release APK artifact -- Release 签名 fallback:CI 无 `release.jks`,`build.gradle.kts` 自动 fallback 到 `~/.android/debug.keystore`;CI 额外步骤确保 debug keystore 存在 +- Release 签名 fallback:CI 无 `release.jks`,`build.gradle.kts` 仅在 `CI=true` 环境变量下 fallback 到 `~/.android/debug.keystore`;本地构建缺 `release.jks` 时直接 `GradleException` 报错,防止静默生成 debug 签名的 Release APK - artifact 保留 14 天 **重大修改 PR 审计红线**: diff --git a/app/build.gradle.kts b/app/build.gradle.kts index 28895d0..9993dcb 100644 --- a/app/build.gradle.kts +++ b/app/build.gradle.kts @@ -36,12 +36,21 @@ android { keyAlias = System.getenv("KEYSTORE_ALIAS") ?: "rainy" keyPassword = System.getenv("KEY_PASSWORD") ?: "RainyToken2026!" } else { - // Fallback: 使用 SDK 默认 debug keystore(CI 构建验证用) - val debugKeystore = file("${System.getProperty("user.home")}/.android/debug.keystore") - storeFile = debugKeystore - storePassword = "android" - keyAlias = "androiddebugkey" - keyPassword = "android" + // 仅在 CI 环境中 fallback 到 debug keystore(用于编译/资源完整性验证) + // 本地构建缺少 release.jks 时直接报错,避免静默生成 debug 签名的 Release APK + if (System.getenv("CI") != null) { + val debugKeystore = file("${System.getProperty("user.home")}/.android/debug.keystore") + storeFile = debugKeystore + storePassword = "android" + keyAlias = "androiddebugkey" + keyPassword = "android" + } else { + throw GradleException( + "release.jks 不存在,且当前不是 CI 环境。\n" + + "正式 Release 构建需要 release.jks 密钥库文件。\n" + + "如需本地验证编译,请设置环境变量 CI=true 或使用 assembleDebug。" + ) + } } } }