Signing and update trust #54
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
TheAnachronism/tt-rss-viewer#54
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #41
Blocked by: #52, #53
Question
What signing and update-trust story is the minimum for sideload-to-friends 1.0 beta (keystore ownership, how friends receive updates, when signature changes break updates)?
Resolution
Signing and update-trust bar for sideload-to-friends 1.0 beta (criteria only — implement later):
Must
dev.theanachronism.ttrssviewer,versionCoderises (epoch seconds per App identity and versioning), and the same release cert signs both APKs.Not must for beta
Why
Alpha APK signing reality shows debug-keystore signing cannot guarantee update-in-place. Friends beta needs a durable project signer and a simple Releases download path; v3 keeps a rotation door open without overbuilding day-one key ceremony. Friend docs stay simple; operators own the key risk.