release: harden Android network security

This commit is contained in:
key
2026-07-29 01:13:18 +08:00
parent 9ea5d79a62
commit ba68fc8326
16 changed files with 198 additions and 29 deletions
+29 -3
View File
@@ -205,19 +205,45 @@ try {
$application = $decodedManifest.manifest.application
$debuggable = $application.GetAttribute('debuggable', $androidNamespace) -eq 'true'
$usesCleartextTraffic = $application.GetAttribute('usesCleartextTraffic', $androidNamespace) -eq 'true'
$networkSecurityConfig = $application.GetAttribute('networkSecurityConfig', $androidNamespace)
if ($BuildKind -eq 'custom-base' -and -not $debuggable) {
throw 'Custom base APK must remain debuggable.'
}
if ($BuildKind -eq 'dcloud-test' -and $debuggable) {
throw 'DCloud internal test APK must not be debuggable.'
}
if ($BuildKind -in @('dcloud-test', 'release') -and $usesCleartextTraffic) {
throw "$BuildKind APK must not allow cleartext HTTP traffic."
}
if ($BuildKind -in @('dcloud-test', 'release')) {
if ($networkSecurityConfig -ne '@xml/network_security_config') {
throw "$BuildKind APK must reference @xml/network_security_config."
}
$decodedNetworkSecurityPath = Join-Path $decodePath 'res\xml\network_security_config.xml'
if (-not (Test-Path -LiteralPath $decodedNetworkSecurityPath)) {
throw "$BuildKind APK is missing res/xml/network_security_config.xml."
}
$decodedNetworkSecurity = Get-Content -Raw -Encoding UTF8 -LiteralPath $decodedNetworkSecurityPath
if ($decodedNetworkSecurity -notmatch 'cleartextTrafficPermitted=\"false\"') {
throw "$BuildKind APK network security config must reject cleartext traffic."
}
if ($decodedNetworkSecurity -match 'cleartextTrafficPermitted=\"true\"') {
throw "$BuildKind APK network security config must not contain a cleartext exception."
}
if ($decodedNetworkSecurity -notmatch '<certificates src=\"system\"\s*/>') {
throw "$BuildKind APK network security config must trust system certificates only."
}
if ($decodedNetworkSecurity -match '<certificates src=\"(?!system\")[^\"]+\"') {
throw "$BuildKind APK network security config must not trust user or bundled certificates."
}
if ($decodedNetworkSecurity -match '<debug-overrides\b') {
throw "$BuildKind APK network security config must not contain debug trust overrides."
}
}
if ($BuildKind -eq 'release') {
if ($debuggable) {
throw 'Release APK must not be debuggable.'
}
if ($usesCleartextTraffic) {
throw 'Release APK must not allow cleartext HTTP traffic.'
}
if ([string]::IsNullOrWhiteSpace($ExpectedSignerSha256)) {
throw 'Release verification requires -ExpectedSignerSha256 for the enterprise signing certificate.'
}