Skip to content

scripts: --new-keystore, and say when a password is refused for not being ASCII - #1106

Merged
cryptskii merged 1 commit into
mainfrom
cryptskii/eager-darwin-1668e4
Oct 2, 2026
Merged

cryptskii merged 1 commit into
mainfrom
cryptskii/eager-darwin-1668e4

Conversation

@cryptskii

Copy link
Copy Markdown
Collaborator

Java's PKCS12 keystores accept only ASCII passwords, and the two ways a password reaches them disagree on anything else:

  • keytool's own prompt decodes the terminal by its locale, so a character such as € or § can arrive as ?. The keystore is then created, and it opens at that prompt.
  • The deploy script reads the same password and passes it to keytool and Gradle intact, through the environment. The keystore refuses it with "keystore password was incorrect". Creating a keystore through the environment fails outright with "Password is not ASCII".

Both behaviours were reproduced with the JDK in this environment.

Changes to scripts/fast_deploy_android_release.sh:

  • --new-keystore creates the signing keystore from the script's own prompt, the same channel every later build reads the password from:
    • the password is asked for twice and must be ASCII (symbols such as !@#$%^&* are fine);
    • the old keystore is kept as <path>.<time>.bak, or put back if keytool fails.
  • A refused password that contains a non-ASCII character now gets a message saying so and pointing to --new-keystore, instead of another prompt.

Tested on a real TTY (via script):

  • At creation, a non-ASCII password is refused, a mismatched repeat is refused, and an ASCII password with symbols creates the keystore and builds.
  • A later run with the right password opens the keystore.
  • A keystore made at keytool's prompt with a € is refused with the explanation.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Y4wDTToHmJfkYYJvMKXt3u


Generated by Claude Code

…eing ASCII

Java's PKCS12 keystores take only ASCII passwords. keytool's own prompt
decodes the terminal by its locale, so a character such as € or § can
arrive there as '?' and the keystore is made and opens at that prompt;
the same password read by the deploy script reaches keytool and Gradle
intact through the environment, and the keystore refuses it ("keystore
password was incorrect"). Made through the environment, keytool refuses
it outright ("Password is not ASCII").

--new-keystore makes the signing keystore from the script's own prompt,
the channel every later build reads the password from: the password is
asked twice, must be ASCII (symbols such as !@#$%^&* are fine), and the
old keystore is kept as <path>.<time>.bak, or put back if keytool fails.
A refused password with a non-ASCII character now says so and names the
fix instead of asking again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y4wDTToHmJfkYYJvMKXt3u
@cryptskii
cryptskii merged commit 70ffe3b into main Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants