Files
saphid--frame-control/tests/fixtures/fdroid/README.md
T
saphidandGPT-6 Astra 784a48f218 Add authenticated F-Droid user repositories and management CLI
Verify pinned JAR/CMS signatures, v2 index hashes and APK downloads; support signed v1 fallback and persist TOFU identities. Reuse the catalogue reducer and document repository publishing with offline and live verification evidence.

Co-Authored-By: GPT-6 Astra <noreply@openai.com>
2026-09-28 21:06:06 +10:00

15 lines
799 B
Markdown

# F-Droid verification fixtures
`entry.jar` and `index-v1.jar` are synthetic RSA-2048/SHA-256 signed JARs,
including CMS signed attributes. `fingerprint.txt` identifies their throwaway
certificate. Their JSON describes org.example.app; `example.apk` is deliberately
plain test data, not an installable app. The v2 index includes incompatible
Android-31 and x86-only versions to exercise the shared reducer.
`izzy-entry.jar` was recorded from
https://apt.izzysoft.de/fdroid/repo/entry.jar on 2026-09-28. Its certificate
fingerprint matches the operator's published fingerprint:
3BF0D6ABFEAE2F401707B6D966BE743BF0EEE49C2561B9BA39073711F628937A.
It exercises an independent production JAR/CMS encoder without network access.
The index it references is not needed by this signature-only fixture test.