Skip to content

Migrate from Cargo-bundled Maven repository to GitHub-hosted Maven artifact repository - #251

Merged
complexspaces merged 5 commits into
mainfrom
android-maven-repo-migration
Sep 22, 2026
Merged

complexspaces merged 5 commits into
mainfrom
android-maven-repo-migration

Conversation

@complexspaces

@complexspaces complexspaces commented Sep 19, 2026 •

Copy link
Copy Markdown
Collaborator

This PR implements the plan that I outlined last year to redo the Android distribution channels (hopefully for the last time!) with a few improvements for simplicity.

We are switching from shipping AAR builds with Cargo releases to using rustls-platform-verifier-android as solely a version synchronization tool and distributing the AAR via a stateful Maven "local" repository that is going to be hosted in the maven-archive branch of this repository. Gradle will depend on this remote filesystem structure transparently, treating it exactly like a regular Maven package registry.

The main branch of this repository (and any release branches) now hold a maven-metadata-local.xml file that contains the persistent state required for a Maven remote. main is the source of truth for the data and during releases it gets copied into the maven-archive branch to "enable" finding the newly built artifacts. This is also intended to prevent ever running into Git conflicts when switching between the two.

This now means there shouldn't be anymore weird dependencies between the Rust part of this library and the Android part for downstream users who have a split between their Java libraries and actual host applications. Both can fetch from the same remote without any dependency on eachother and the final version of the Android component can be selected by the top-level app.

I tested this plan out in https://github.com/complexspaces/rustls-platform-verifier-android-sandbox originally with 1Password's Android app as the downstream user using the new README code snippets and all. Here's a screenshot of Android Studio showing successful version resolution and downloading of the AAR library:
image

More PRs follow this one to assemble the rest of the components and then demonstrate preparing for a new release using the updated process and releasing guide:

Commit-by-commit review is heavily recommended.

Closes #115, #226

This must have the same structure as the Maven repo paths
@complexspaces
complexspaces force-pushed the android-maven-repo-migration branch from 7a4dd16 to 48fc34f Compare September 21, 2026 14:45
@complexspaces

Copy link
Copy Markdown
Collaborator Author

Ah I forgot one thing last week: Before this merges I want to test reverting the test-only workaround for CRL fetching failures and confirm the new manifest is working as intended in our CI environment:

// LetsEncrypt no longer include OCSP information (as OCSP is being deprecated) which Android is not
// happy with since it *only* tries OCSP by default. We aren't 100% decided on how to fix this yet for real
// (see https://github.com/rustls/rustls-platform-verifier/pull/179) so for now we implement an out for
// tests to allow regular maintenance to proceed.
if (BuildConfig.TEST && e.reason == CertPathValidatorException.BasicReason.UNSPECIFIED) {
return VerificationResult(StatusCode.Ok)
}

@complexspaces

Copy link
Copy Markdown
Collaborator Author

I confirmed its working locally. With the inline workaround removed and changing the manifest locally to allow no cleartext traffic I get the same error everyone runs into:
image

Putting the manifest back to its main state allowing cleartext traffic for the CRL endpoints makes all tests pass 🎉
image

I needed to bump our build tooling versions locally to work with the latest Android Studio as well so I've pushed that up here.

@djc

djc commented Sep 22, 2026

Copy link
Copy Markdown
Member

The commit history looks a bit messy? IMO the Kotlin formatting/lint stuff should be fixed in the same commit where the version that causes these to pop up is bumped.

It's not clear to me why CI against 48fc34f failed but fixing that by reordering commits might be nice, too.

Gradle/Android Studio will automatically merge this into any hosting
applications including the library. In addition, now that this is present,
we no longer need the test-only workaround for CRL fetching failures.
…rtifacts

Start tracking Maven repository state data (backfilled from GitHub releases).
This metadata file will be shared between the main branches and Maven archive branch
in the future.
@complexspaces
complexspaces force-pushed the android-maven-repo-migration branch from f8d49ea to 044fcd9 Compare September 22, 2026 16:13
@complexspaces

complexspaces commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator Author

Good point on the commit history 😅. I squashed the Kotlin lint fixes and workaround removal into larger ones since I think neither of those make sense on their own because they are dependent on a bigger change.

I also reordered history to have "fixing builds to make everything work" be before anything that changes Android Studio related things.

@complexspaces
complexspaces merged commit 0e76b93 into main Sep 22, 2026
20 checks passed
@complexspaces
complexspaces deleted the android-maven-repo-migration branch September 22, 2026 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Simplify Android release support by including a jar directly

2 participants