Repository navigation
1.0.3
PassPony (Android) 1.0.3
1.0.2 crashed on launch for everyone who installed the release APK. The release build runs R8 minification, but the keep rules for the crypto layer were never added, so R8 renamed and stripped the UniFFI/JNA bindings and the BouncyCastle classes that the app looks up by reflection at runtime. The store engine is initialized during launch, so the first call into it threw and the process died, then restarted into the same crash. Debug builds are not minified, which is how this reached the 1.0.2 release.
Update to 1.0.3 if 1.0.2 would not open.
- Add R8 keep rules for the JNA/UniFFI bindings (com.sun.jna, uniffi.pass_ffi) and BouncyCastle (org.bouncycastle, com.pgpony.android.crypto) so the crypto engine survives minification.
Verification
- Content hash:
666d242c8954489dc2e52f13da9ea59a59a52badd80ee15302db0daefb4b586c - SHA-256 checksums: see
PassPonyAndroid-1.0.3-SHA256SUMS.txt - Reproduce this build yourself:
tools/verify_repro.sh rebuild v1.0.3 PassPonyAndroid-1.0.3-foss.apk
See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.