It is no longer "local" -- it serves over WireGuard rather than the LAN -- and it is specifically for developing new apps. Renaming the references here at the same time keeps one name to search for across both repos. Also drops the last references to gen-dev-cert.sh, which the in-process certificate generation replaced: the build script and the Gradle task now say to start the server once, and test-wg-tunnel.sh reads the certificates from the XDG directory rather than the repo. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017xn8nHw1tw1R6PtiY1eEtw
70 lines
2.9 KiB
Bash
Executable File
70 lines
2.9 KiB
Bash
Executable File
#!/bin/sh
|
|
# Builds the app's APK, ready to install on a phone through Dev Updater.
|
|
#
|
|
# ./build-apk.sh
|
|
#
|
|
# The APK pins the CA on *this* machine ($XDG_CONFIG_HOME/ai-app/certs/ca.pem,
|
|
# or AI_APP_CA), so build it on the machine that runs the backend: an app
|
|
# built somewhere else trusts a CA that backend can't present, and simply
|
|
# won't connect. Start ai-server once first if there are no certificates
|
|
# yet -- it generates them; the build stops with that instruction if it
|
|
# can't find one.
|
|
#
|
|
# Unlike ./run-android.sh, this touches no emulator: it only produces the
|
|
# file. Installing on a real phone goes through Dev Updater, which serves
|
|
# whatever is under this project's build directory.
|
|
set -eu
|
|
|
|
SCRIPT_DIR=$(cd "$(dirname "$0")" && pwd)
|
|
cd "$SCRIPT_DIR"
|
|
|
|
# Prefer an SDK this machine has already configured -- the host and the dev
|
|
# VM don't keep it in the same place, and android-env.sh is written for the
|
|
# VM's layout (it also installs missing packages, which isn't wanted here).
|
|
if [ -n "${ANDROID_HOME:-}" ] && [ -d "${ANDROID_HOME}" ]; then
|
|
echo "==> Using ANDROID_HOME=$ANDROID_HOME"
|
|
elif [ -n "${ANDROID_SDK_ROOT:-}" ] && [ -d "${ANDROID_SDK_ROOT}" ]; then
|
|
ANDROID_HOME="$ANDROID_SDK_ROOT"
|
|
export ANDROID_HOME
|
|
echo "==> Using ANDROID_SDK_ROOT=$ANDROID_SDK_ROOT"
|
|
elif [ -d "$HOME/Android/Sdk" ]; then
|
|
ANDROID_HOME="$HOME/Android/Sdk"
|
|
ANDROID_SDK_ROOT="$ANDROID_HOME"
|
|
export ANDROID_HOME ANDROID_SDK_ROOT
|
|
echo "==> Using $ANDROID_HOME"
|
|
else
|
|
echo "No Android SDK found. Set ANDROID_HOME to it, or install one" >&2
|
|
echo "(Android Studio's default location is ~/Android/Sdk)." >&2
|
|
exit 1
|
|
fi
|
|
|
|
CA="${AI_APP_CA:-${XDG_CONFIG_HOME:-$HOME/.config}/ai-app/certs/ca.pem}"
|
|
if [ -f "$CA" ]; then
|
|
# Printed so a wrong or stale certificate is visible here rather than as
|
|
# a handshake failure on the phone. Compare with the server's own
|
|
# the CA the server is actually presenting.
|
|
FINGERPRINT=$(openssl x509 -in "$CA" -pubkey -noout 2>/dev/null \
|
|
| openssl pkey -pubin -outform der 2>/dev/null \
|
|
| openssl dgst -sha256 -binary 2>/dev/null \
|
|
| openssl base64 2>/dev/null || echo "(openssl unavailable)")
|
|
echo "==> Pinning the CA at $CA"
|
|
echo " fingerprint: $FINGERPRINT"
|
|
else
|
|
echo "No CA certificate at $CA -- start ai-server once on this machine" >&2
|
|
echo "(it generates them), or set AI_APP_CA. The APK embeds it at build time." >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "==> Building"
|
|
./gradlew :androidApp:assembleDebug
|
|
|
|
APK="$SCRIPT_DIR/androidApp/build/outputs/apk/debug/androidApp-debug.apk"
|
|
echo
|
|
echo "==> Built $APK"
|
|
[ -f "$APK" ] && ls -lh "$APK" | awk '{print " " $5}'
|
|
echo
|
|
echo "To get it onto the phone: add this project to Dev Updater (or hit"
|
|
echo "Update on it if it's already there) and install from there."
|
|
echo "Then start the backend and scan the enrollment QR it prints:"
|
|
echo " ./server/target/release/ai-server --rotate-token"
|