Skip to content

Build Android against the published protocol by default - #836

Merged
kiftio merged 7 commits into
mainfrom
android-published-protocol-default
Oct 2, 2026
Merged

kiftio merged 7 commits into
mainfrom
android-published-protocol-default

Conversation

@kiftio

@kiftio kiftio commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

What changes are you making?

Android previously compiled the protocol from local source while its published POM pointed consumers at a separate Maven artifact. That allowed Kit to ship references to classes missing from its declared dependency.

The SDK and Android sample now compile against the pinned Maven Central protocol artifact in normal builds, CI, and releases. Joint development opts into source with dev android <command> --local (for example, dev android test --local or dev android api check --local), or -PuseLocalProtocol=true when invoking Gradle directly. The flag is supported by Android build, sample build, start, test, lint, format, check, and API commands. Remote Kit publication rejects local mode. React Native's dev rn android --local and dev rn test android --local flows automatically enable local protocol mode when publishing Kit and ECP to Maven Local.

The protocol release version and Kit's dependency pin are separate so a protocol release PR can merge before Kit adopts the new artifact. Protocol tests and lint run independently in CI, and Kit publication runs unit tests and API checks before uploading. Repository-wide dev test, dev lint, and dev format retain Kotlin protocol source coverage through standalone protocol commands, while Android continues resolving published ECP by default.

A small :lib:verifyPublishedProtocol task also requires release and unit-test classpaths to resolve the declared ECP module at exactly the catalog-pinned version. It catches project substitution and version drift introduced by dependency resolution, runs automatically with SDK unit tests and remote publication, and skips explicit local mode. This retains the useful safeguard from #832 without adding a fixture framework or another build-mode toggle.

Release process

For a feature spanning all three packages, the order is ECP → Android Kit → React Native:

  1. Release ECP to Maven Central. Bump embeddedCheckoutProtocolAndroidRelease with the protocol changes and API baseline. Keep Kit's embeddedCheckoutProtocolAndroid at the existing published version while this PR passes CI, merges, and releases.
  2. Adopt ECP and release Android Kit. Once the protocol artifact and metadata are available, update Kit's ECP dependency pin, make the SDK changes, and bump checkoutKitAndroid. Run normal SDK/sample CI and API checks against that published ECP version, then merge and publish Kit to Maven Central.
  3. Adopt Android Kit and release RN. Once Kit is available, update checkoutKit.nativeSdkVersions.android and the RN package's own version. Run normal RN Android tests and the sample build against the published Kit and its transitive ECP dependency, plus the other required RN checks. Merge and publish RN to npm. RN does not need its own ECP pin.

At each stage, use the Release package workflow's dry run and draft release flow. Wait for actual registry availability before verifying the next package; a GitHub release/tag alone is insufficient. The workflows do not automatically sequence the stages. The RN npm publish job builds/packs JavaScript and does not rerun Android compilation, so RN Android CI must pass before release.

Only changed dependencies need new releases: Android-only changes can keep the ECP pin, and RN-only changes can keep both native pins. Update RN's iOS pin only when needed, after its required Swift release is available on CocoaPods. Package versions remain independent.

This waterfall makes each package a consumer of the published dependency it declares. It catches missing API during compilation, gives each layer an explicit version boundary, and preserves ECP as a shared transitive dependency rather than embedding duplicate protocol classes. The cost is upstream publication time and a downstream CI run at each adoption. Local overrides support development across stacked branches, but normal CI must pass against published artifacts before those downstream PRs merge.

The coordinated release guide, RN release guide, Android README, and PR release checklists now document this process.

How to test

Verified locally after rebasing onto main (0d8f23739):

  • dev android test: 508 SDK tests and 99 sample tests passed against the published protocol, including the resolved-dependency guard.
  • dev protocol test kotlin: 50 protocol tests passed.
  • dev android api check: Android Kit and protocol API baselines passed.
  • env -u NO_COLOR ruby scripts/test_ruby: 332 tests / 921 assertions passed, including the regression test for independent protocol release and dependency versions.
  • Generated both Maven POMs with a temporary newer protocol release version: the ECP POM used the new release version while Kit's POM retained its existing published dependency pin. Restored the catalog afterward; no artifacts were published.
  • Android and ECP release-version validation, validator shell syntax, and git diff --check passed.

Before you merge

  • Added a regression test for independent protocol release and dependency versions.
  • Updated contributor, Android, and RN release documentation and the PR release checklists.
  • CI passes.

@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Sep 28, 2026
@kiftio
kiftio marked this pull request as ready for review September 28, 2026 09:12
@kiftio
kiftio requested a review from a team as a code owner September 28, 2026 09:12
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

React Native — Coverage Report

Lines Statements Branches Functions
Coverage: 91%
90.97% (363/399) 87.29% (213/244) 100% (92/92)

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Size budgets

Measured head: 91cb2ef38a4a2cc8dd019f8c43e6627d16670c7a; base: 0d8f23739a4d8d4aeb4c171005c3432d8f9d5995.

Platform / budget Measurement Base Head Delta Soft Hard Result
— — — — — — — No configured budgets affected

Repository writers, including the PR author, can accept current soft-budget breaches with a reason:

/accept-size web Explain why this increase is necessary.

Use one command per platform; several lines can share a comment. Post after this report is ready for the current head. Commands in edited comments are not accepted.

Acceptance applies to each currently exceeded metric up to its recorded size. Further growth or a newly exceeded metric needs fresh acceptance. Hard-budget increases require a reviewed change to .ci/bundle-size-budgets.json.

Bundle and package size

Web bundle sizes cover shipped runtime JavaScript. Package sizes cover the full published archive, including any source maps, declarations, and documentation it contains.

Platform Measurement Compression Base Head Delta
React Native npm package (.tgz) gzip 119.6 KiB 119.6 KiB 0 B
Android Library package (.aar) ZIP 407.6 KiB 407.6 KiB 0 B
React Native package files (uncompressed)

These are uncompressed file sizes; they do not sum to the compressed package size above.

File Base Head Delta
node_modules/@shopify/checkout-kit-protocol/src/generated/Models.ts 108.7 KiB 108.7 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/Models.d.ts 73.1 KiB 73.1 KiB 0 B
android/src/main/java/com/shopify/reactnative/checkoutkit/ShopifyCheckoutKitModule.java 16.2 KiB 16.2 KiB 0 B
ios/ShopifyCheckoutKit.swift 16.1 KiB 16.1 KiB 0 B
ios/AcceleratedCheckoutButtons.swift 14.1 KiB 14.1 KiB 0 B
src/components/AcceleratedCheckoutButtons.tsx 13.0 KiB 13.0 KiB 0 B
src/index.ts 12.7 KiB 12.7 KiB 0 B
lib/commonjs/index.js 12.4 KiB 12.4 KiB 0 B
lib/commonjs/components/AcceleratedCheckoutButtons.js 11.4 KiB 11.4 KiB 0 B
src/index.d.ts 11.3 KiB 11.3 KiB 0 B
lib/commonjs/components/AcceleratedCheckoutButtons.js.map 10.4 KiB 10.4 KiB 0 B
lib/module/index.js 10.4 KiB 10.4 KiB 0 B
lib/module/components/AcceleratedCheckoutButtons.js 10.2 KiB 10.2 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/ProtocolNotifications.ts 9.5 KiB 9.5 KiB 0 B
lib/module/components/AcceleratedCheckoutButtons.js.map 9.1 KiB 9.1 KiB 0 B
lib/module/index.js.map 8.1 KiB 8.1 KiB 0 B
src/present-dispatcher.ts 8.0 KiB 8.0 KiB 0 B
lib/commonjs/index.js.map 7.9 KiB 7.9 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/ProtocolRenameMap.ts 7.8 KiB 7.8 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/ProtocolNotifications.d.ts 7.6 KiB 7.6 KiB 0 B
…and 117 smaller files
Android package files (uncompressed)

These are uncompressed file sizes; they do not sum to the compressed package size above.

File Base Head Delta
classes.jar 434.3 KiB 434.3 KiB 0 B
res/layout/checkout_view_content.xml 2.6 KiB 2.6 KiB 0 B
res/layout/checkout_sheet_content.xml 2.0 KiB 2.0 KiB 0 B
res/values/values.xml 1.3 KiB 1.3 KiB 0 B
R.txt 1.2 KiB 1.2 KiB 0 B
AndroidManifest.xml 922 B 922 B 0 B
proguard.txt 798 B 798 B 0 B
res/drawable/close.xml 431 B 431 B 0 B
res/menu/checkout_menu.xml 354 B 354 B 0 B
META-INF/com/android/build/gradle/aar-metadata.properties 157 B 157 B 0 B

Measured from the PR base SHA and PR head SHA. Web bundle rows sum shipped .js, .mjs, and .cjs files under dist/, excluding source maps and declarations. The gzip bundle size sums files compressed individually with gzip -n -9. npm package sizes are gzip-compressed .tgz archives; Android AAR sizes are ZIP archives. Package sizes are not final app binary sizes.

@bitrise

bitrise Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Install this build

Open Tophat, select your target device, then click Install. Links open on the Mac running Tophat.

SDK Install
React Native Install with Tophat
Kotlin Install with Tophat

Checkout Kit E2E results

Status Tags Target Platform OS version tag Device
✅ launch, checkout-presentation, checkout-completion, buyer-identity react-native ios latest iPhone 15
iOS 27 Beta
✅ launch, checkout-presentation, checkout-completion, buyer-identity react-native android latest Google Pixel 9
Android 17.0
✅ launch, checkout-presentation, checkout-completion, buyer-identity, preload kotlin android latest Google Pixel 9
Android 17.0


VERSION=$(version_catalog_value "$ANDROID_VERSION_FILE" "checkoutKitAndroid")
ANDROID_PROTOCOL_VERSION=$(version_catalog_value "$ANDROID_VERSION_FILE" "embeddedCheckoutProtocolAndroid")
ANDROID_PROTOCOL_VERSION=$(version_catalog_value "$ANDROID_VERSION_FILE" "embeddedCheckoutProtocolAndroidDependency")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need the "dependency" suffix?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've tweaked the naming in the last commit

@kiftio
kiftio force-pushed the android-published-protocol-default branch from d7323f1 to 91cb2ef Compare October 2, 2026 13:12
@kiftio
kiftio merged commit 35b0269 into main Oct 2, 2026
34 of 37 checks passed
@kiftio
kiftio deleted the android-published-protocol-default branch October 2, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants