Files
saphid--frame-control/tests/fixtures/fdroid/README.md
T
saphidandGPT-6 Astra 784a48f218 Add authenticated F-Droid user repositories and management CLI
Verify pinned JAR/CMS signatures, v2 index hashes and APK downloads; support signed v1 fallback and persist TOFU identities. Reuse the catalogue reducer and document repository publishing with offline and live verification evidence.

Co-Authored-By: GPT-6 Astra <noreply@openai.com>
2026-09-28 21:06:06 +10:00

799 B

F-Droid verification fixtures

entry.jar and index-v1.jar are synthetic RSA-2048/SHA-256 signed JARs, including CMS signed attributes. fingerprint.txt identifies their throwaway certificate. Their JSON describes org.example.app; example.apk is deliberately plain test data, not an installable app. The v2 index includes incompatible Android-31 and x86-only versions to exercise the shared reducer.

izzy-entry.jar was recorded from https://apt.izzysoft.de/fdroid/repo/entry.jar on 2026-09-28. Its certificate fingerprint matches the operator's published fingerprint: 3BF0D6ABFEAE2F401707B6D966BE743BF0EEE49C2561B9BA39073711F628937A. It exercises an independent production JAR/CMS encoder without network access. The index it references is not needed by this signature-only fixture test.