scripts: --new-keystore, and say when a password is refused for not being ASCII - #1106
Merged
Merged
Conversation
…eing ASCII
Java's PKCS12 keystores take only ASCII passwords. keytool's own prompt
decodes the terminal by its locale, so a character such as € or § can
arrive there as '?' and the keystore is made and opens at that prompt;
the same password read by the deploy script reaches keytool and Gradle
intact through the environment, and the keystore refuses it ("keystore
password was incorrect"). Made through the environment, keytool refuses
it outright ("Password is not ASCII").
--new-keystore makes the signing keystore from the script's own prompt,
the channel every later build reads the password from: the password is
asked twice, must be ASCII (symbols such as !@#$%^&* are fine), and the
old keystore is kept as <path>.<time>.bak, or put back if keytool fails.
A refused password with a non-ASCII character now says so and names the
fix instead of asking again.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y4wDTToHmJfkYYJvMKXt3u
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Java's PKCS12 keystores accept only ASCII passwords, and the two ways a password reaches them disagree on anything else:
€or§can arrive as?. The keystore is then created, and it opens at that prompt.Both behaviours were reproduced with the JDK in this environment.
Changes to
scripts/fast_deploy_android_release.sh:--new-keystorecreates the signing keystore from the script's own prompt, the same channel every later build reads the password from:!@#$%^&*are fine);<path>.<time>.bak, or put back if keytool fails.--new-keystore, instead of another prompt.Tested on a real TTY (via
script):€is refused with the explanation.🤖 Generated with Claude Code
https://claude.ai/code/session_01Y4wDTToHmJfkYYJvMKXt3u
Generated by Claude Code