3.1 KiB
Android 1.0.4 isolated candidate
Status: local signed candidate built and verified on 2026-09-24. Not published, not installed on a physical device, and not accepted as a stable release.
VersionName 1.0.4 / base versionCode 10004; the existing playstore ABI mapping produces APK versionCode 4010004 (previous candidate: 4010003). Includes the 2026-09-17 authorization-session isolation fix without changing the VPN or network policy.
The candidate was built in a fresh ASCII directory using cached JDK 21 / SDK 37 / Gradle 9.4.1 with --offline --no-daemon --max-workers=2. All 41 JVM tests passed with zero failures/errors/skips, including 10 authorization lifecycle cases for old success/401/403 responses, replaced or removed login, transient failure, and cancellation. All five ABI/universal release APKs were assembled. No emulator, Android service instrumentation or production API was used.
All five APK manifests independently report package cn.toplc.zonghengjia, versionName 1.0.4, versionCode 4010004. APK Signature Scheme v2/v3 verification passed. The certificate SHA256 is 0f1a09870d6ee1e73b62138f99463e7066f4228ce28b7f16ff0aeccca59ea14f, independently compared with retained 1.0.2 and 1.0.3 universal APKs. Signing material was not exported. Old APKs remain unchanged.
| Artifact suffix | Bytes | SHA256 |
|---|---|---|
| android-universal.apk | 64228400 | fc8ef82ba2ef28cb26991401c8ea5feca492f929a7bad4aa6b39e4787baaf416 |
| android-arm64-v8a.apk | 27503013 | 7527441177d858b48975aa882d1313e7cb693653ced5c5de6d17fd3abce83a9f |
| android-armeabi-v7a.apk | 27855275 | 4121ea1f442cc3ec507ede50a19587bcaca983d147ec3af6ad27b7c62f229ca5 |
| android-x86_64.apk | 28387740 | f24a1f9b753030a4bd68278d685a03d0fdb7d8e0e34e96bd16e8fa6eba164125 |
| android-x86.apk | 28842387 | bd912c09f338f57f34806914fa45f86a8d7792a56bb24552ebf5a13888234b61 |
Every APK filename starts with UCVL-Zonghengjia-1.0.4-. The immutable build-input manifest SHA256 is 404c9c802321c39c2589c7d7c10e0e2d418af6e2d03d86f7de2ee8354f3bedeb. The candidate report additionally binds signed APK ZIP-entry bytes to the unsigned Gradle outputs and the GPL snapshot to each compiled source input; seven AAR/JNI inputs are checked against the existing public restoration locks.
The first wrapper run stopped after successful Gradle completion because its PowerShell result aggregation used dictionaries with Measure-Object. The aggregation was corrected, and signing resumed against the same verified input manifest and completed outputs; tests/build were not falsely reported failed or silently rerun against different source.
Remaining device gates: real Android VPN permission and data path, service/broadcast behavior when a login replaces an in-flight authorization request, disconnect/recovery, Wi-Fi/mobile transitions, sleep/wake and authenticated sustained business traffic. JVM tests and APK signatures do not establish these results.
GPL source is exported separately using the publication tool that excludes the private Zero3 helper. No phone, board, host network, iOS or remote Git operation is part of this candidate preparation.