fix(android): ship R8 keep rules for DocuSign's esign models - #15
Merged
Merged
Conversation
DocuSign's androidsdk AAR ships consumer rules for com.docusign.androidsdk only. The Gson models in sdk-esign-api are named in generic signatures but never used directly, so R8 removes them. An app with minification on lost login and captive signing at runtime, with no crash at launch. android/consumer-rules.pro keeps com.docusign.esign.model.** and the module's class names, and consumerProguardFiles applies it in every consuming app. In an Expo SDK 57 app with enableMinifyInReleaseBuilds, the 2.0.0 release APK kept 0 of the 580 model classes. With the packed 2.0.1 the rule is in the merged R8 configuration, all 580 classes and ViewUrl.url survive, and the APK grows by 0.6 MB.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ships R8 keep rules with the module, so an app that turns on minification keeps DocuSign login and captive signing working without adding rules of its own. Released as 2.0.1.
Why
androidsdk-2.1.7.aarships consumer rules that keepcom.docusign.androidsdk.**only.sdk-esign-api-2.1.7.jar(com.docusign.esign.model, 580 classes), a plain JAR with noMETA-INF/proguardrules. The SDK names them only in generic signatures, so R8 finds no use and removes all of them. Login and captive signing then fail at runtime, and nothing crashes at launch.consumerProguardFileswith no setup.Changes
android/consumer-rules.pro(new): keepscom.docusign.esign.model.** { *; }. Keeping all ofcom.docusign.esign.**fails R8 on the missingorg.apache.oltuclasses the esign client references, so the rule covers the models only. It also has-keepnames class expo.modules.docusign.**, soDocuSignError.native.domainstays readable in an obfuscated build.android/build.gradle:consumerProguardFiles 'consumer-rules.pro'indefaultConfig.package.json,package-lock.json: 2.0.1.CHANGELOG.md: a 2.0.1 Fixes entry.README.md: a "Minified release builds (R8)" section after the Glide workaround.The module's own Kotlin needs no rules. Error codes are explicit, expo-modules-core's consumer rules keep the Records, the recipient-view request uses
JSONObject, and the JS network classifier matchesjava.net.*names, which R8 never renames.Verification
npm packincludesandroid/consumer-rules.pro.enableMinifyInReleaseBuilds, built with./gradlew :app:assembleRelease(arm64):configuration.txtcom.docusign.esign.modelclasses in dexViewUrl.url17babf5with no blocking findings. Its one follow-up is the device run below, which would back the README's claim that apps need no DocuSign keep rules of their own.Notes
./gradlew assembleReleasefrom the root of a consuming app fails in:react-native-docusign:bundleReleaseAar, because AGP rejects the local sdk-pdf.aarwhen it bundles a library AAR. This predates 2.0.1.:app:assembleReleaseand EAS builds are unaffected.