Skip to content

Commit bb0afdd

Browse files
Audit the Cromite Android source candidate
1 parent 380aca4 commit bb0afdd

11 files changed

Lines changed: 1269 additions & 36 deletions

File tree

‎.github/workflows/android-engine.yml‎

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,18 @@ jobs:
5454
pnpm install --frozen-lockfile
5555
5656
- name: Validate scaffold and report release blockers
57-
run: node scripts/preflight.mjs --mode scaffold
57+
run: |
58+
set -o pipefail
59+
report="$RUNNER_TEMP/android-engine-preflight.json"
60+
node scripts/preflight.mjs --mode scaffold --json | tee "$report"
61+
jq -e '.status == "ready" or .status == "blocked"' "$report" > /dev/null
62+
63+
- name: Validate recorded Android source candidate
64+
run: |
65+
set -o pipefail
66+
report="$RUNNER_TEMP/android-engine-candidate.json"
67+
node scripts/audit-candidate.mjs --mode record --json | tee "$report"
68+
jq -e '.status == "ready" or .status == "blocked"' "$report" > /dev/null
5869
5970
- name: Android engine checks
6071
working-directory: .

‎apps/android-engine/README.md‎

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,9 @@ path toward an Ungoogled Chromium engine and optional bundled Tor, built as an
1717
- ✅ Guarded pipeline and a tested release-readiness preflight.
1818
- ✅ Source evaluation and conditional recommendation documented in
1919
[ADR 0002](../../docs/adr/0002-android-engine-source-strategy.md).
20+
- ✅ A pinned Cromite candidate snapshot and offline adoption gate record
21+
license, release-lag, freshness, and extension-support decisions without
22+
treating external attestations as a verified build.
2023
- ⬜ Patch bodies (`chromium/patches/tronbrowser-android/*.patch`), real
2124
Android branding assets, and pinned/checksummed Tor artifacts.
2225
- ⬜ Current Chromium security pin and first real compile (Linux x64, at least
@@ -30,6 +33,9 @@ See [`chromium/README.md`](chromium/README.md). TL;DR (Linux host):
3033
```bash
3134
cd apps/android-engine/chromium
3235
node scripts/preflight.mjs --mode scaffold
36+
# Validate the recorded source snapshot without claiming it is adoptable.
37+
node scripts/audit-candidate.mjs --mode record
38+
node scripts/audit-candidate.mjs --mode adopt # fails while decisions are open
3339
# Checkout mode checks the host and reports release blockers before downloading.
3440
node scripts/preflight.mjs --mode checkout
3541
# Release mode additionally requires every patch, asset, and Tor input.
@@ -40,9 +46,10 @@ TB_RUN=1 ./scripts/build.sh && TB_RUN=1 ./scripts/package.sh
4046
```
4147

4248
CI ([`.github/workflows/android-engine.yml`](../../.github/workflows/android-engine.yml))
43-
validates the scaffold on every push. The manual heavy-build dispatch fails
44-
until the strict release preflight is clean; local source checkout remains
45-
available so the missing overlay can be developed and rebased.
49+
validates the scaffold and candidate-record structure on every push. The manual
50+
heavy-build dispatch fails until the strict release preflight is clean; local
51+
source checkout remains available so the missing overlay can be developed and
52+
rebased.
4653

4754
## Distinct app id
4855

‎apps/android-engine/chromium/README.md‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ Track 3.
1717
chromium/
1818
config/
1919
version.json # pinned chromium + ungoogled versions, targets, tor
20+
cromite-candidate.json # attested downstream snapshot + adoption policy
2021
gn-args/ # common.gni + android.gni (privacy + branding)
2122
branding/ # product strings + APK icon assets
2223
patches/ # required TronBrowser Android overlay (after ungoogled)
@@ -29,6 +30,8 @@ chromium/
2930
node scripts/preflight.mjs --mode scaffold
3031
node scripts/preflight.mjs --mode checkout
3132
node scripts/preflight.mjs --mode release
33+
node scripts/audit-candidate.mjs --mode record
34+
node scripts/audit-candidate.mjs --mode adopt
3235
```
3336

3437
Scaffold mode validates configuration and reports unresolved release inputs.
@@ -37,6 +40,27 @@ requiring release approval, so maintainers can develop patches against a real
3740
checkout. Release mode refuses to continue while the Chromium pin, required
3841
patches, branding assets, or pinned Tor integration are unapproved or missing.
3942

43+
Candidate `record` mode validates the pinned downstream snapshot and reports
44+
licensing, release-lag, freshness, security-SLA, and extension-support blockers
45+
without failing CI merely because a product decision remains open. `adopt` mode
46+
fails closed until every blocker is resolved. Both modes are offline: repository
47+
tags, commits, releases, and patch metadata are recorded attestations, not live
48+
network verification, and must be refreshed from primary upstream sources before
49+
an adoption decision. A stale or malformed attestation fails both modes.
50+
Refresh the record at least every `policy.maximumRecordAgeDays` (currently 30):
51+
re-check the candidate tag, commit, version, and release date; the recorded stable
52+
version and source; and the extension patch URL, blob SHA, reviewer, and date.
53+
54+
Use `--json` for machine-readable output. `--as-of YYYY-MM-DD` is available only
55+
in `record` mode for reproducing a historical snapshot; `adopt` always evaluates
56+
against the current UTC date. The audit exits with status 0 for a valid record
57+
(including unresolved product blockers in `record` mode), 1 for invalid evidence
58+
or a blocked adoption, and 2 for invalid command-line usage.
59+
60+
Cromite release tags contain a 40-character build identifier after the Chromium
61+
version. That identifier is not assumed to be a Git commit: `commitSha`
62+
independently pins the tag's resolved Git target.
63+
4064
## Build (100GB+ free disk, 16GB+ RAM recommended, hours, Linux x64)
4165

4266
Scripts are **guarded**: they dry-run unless `TB_RUN=1`. Source lands outside the
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
{
2+
"$schemaVersion": 1,
3+
"$comment": "Offline adoption record for the Cromite Android-engine candidate. The tag suffix is Cromite's build identifier; commitSha is the independently pinned Git tag-target commit. Upstream facts are attested snapshots, not live verification.",
4+
"candidate": {
5+
"name": "Cromite",
6+
"repository": "https://github.com/uazo/cromite",
7+
"tag": "v148.0.7778.168-cb3baf14f52eb4365d017f640f85310735c19b79",
8+
"commitSha": "cdf415cc86c8aa17faa26edf51e12f2fd49a274f",
9+
"chromiumVersion": "148.0.7778.168",
10+
"publishedAt": "2026-05-21T16:26:34Z"
11+
},
12+
"snapshot": {
13+
"observedOn": "2026-08-17",
14+
"recordedBy": "phucnguyen1707",
15+
"chromeAndroidStable": {
16+
"chromiumVersion": "151.0.7922.71",
17+
"sourceUrl": "https://chromereleases.googleblog.com/2026/07/chrome-for-android-update_01846374933.html"
18+
}
19+
},
20+
"policy": {
21+
"maximumMajorLag": 1,
22+
"maximumReleaseAgeDays": 35,
23+
"maximumRecordAgeDays": 30,
24+
"emergencySecurityUpdateSlaHours": null
25+
},
26+
"license": {
27+
"spdxId": "GPL-3.0",
28+
"sourceUrl": "https://github.com/uazo/cromite/blob/cdf415cc86c8aa17faa26edf51e12f2fd49a274f/LICENSE",
29+
"decision": "pending",
30+
"decidedBy": null,
31+
"decidedOn": null
32+
},
33+
"extensionSupport": {
34+
"requirement": "undecided",
35+
"status": "experimental",
36+
"enabledByDefault": false,
37+
"patchPath": "build/patches/Experimental-support-for-extensions-on-Android.patch",
38+
"patchUrl": "https://github.com/uazo/cromite/blob/v148.0.7778.168-cb3baf14f52eb4365d017f640f85310735c19b79/build/patches/Experimental-support-for-extensions-on-Android.patch",
39+
"patchBlobSha": "5058d366e52954b10dbea33369562d1a3f0556c0",
40+
"attestedBy": "phucnguyen1707",
41+
"attestedOn": "2026-08-17"
42+
}
43+
}

0 commit comments

Comments
 (0)