mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 06:00:33 +02:00
Verify pinned JAR/CMS signatures, v2 index hashes and APK downloads; support signed v1 fallback and persist TOFU identities. Reuse the catalogue reducer and document repository publishing with offline and live verification evidence. Co-Authored-By: GPT-6 Astra <noreply@openai.com>
15 lines
799 B
Markdown
15 lines
799 B
Markdown
# F-Droid verification fixtures
|
|
|
|
`entry.jar` and `index-v1.jar` are synthetic RSA-2048/SHA-256 signed JARs,
|
|
including CMS signed attributes. `fingerprint.txt` identifies their throwaway
|
|
certificate. Their JSON describes org.example.app; `example.apk` is deliberately
|
|
plain test data, not an installable app. The v2 index includes incompatible
|
|
Android-31 and x86-only versions to exercise the shared reducer.
|
|
|
|
`izzy-entry.jar` was recorded from
|
|
https://apt.izzysoft.de/fdroid/repo/entry.jar on 2026-09-28. Its certificate
|
|
fingerprint matches the operator's published fingerprint:
|
|
3BF0D6ABFEAE2F401707B6D966BE743BF0EEE49C2561B9BA39073711F628937A.
|
|
It exercises an independent production JAR/CMS encoder without network access.
|
|
The index it references is not needed by this signature-only fixture test.
|