TF-4268 Automate Sentry symbol upload for Android release builds (#4442)

This commit is contained in:
Dat Vu
2026-04-14 12:32:03 +07:00
committed by GitHub
parent 16376fccb4
commit 1d594804b5
4 changed files with 99 additions and 1 deletions
+50
View File
@@ -89,3 +89,53 @@ jobs:
APPLE_KEY_CONTENT: ${{ secrets.APPLE_KEY_CONTENT }} APPLE_KEY_CONTENT: ${{ secrets.APPLE_KEY_CONTENT }}
run: ../scripts/build-release.sh run: ../scripts/build-release.sh
working-directory: ${{ matrix.os }} working-directory: ${{ matrix.os }}
# --- UPLOAD SENTRY MAPPING AND SYMBOLS FOR ANDROID ---
- name: Upload Android ProGuard Mapping & Dart Debug Symbols to Sentry
if: matrix.os == 'android'
env:
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
SENTRY_ORG: ${{ secrets.SENTRY_ORG }}
SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }}
run: |
# 1. Install Sentry CLI
curl -sL https://sentry.io/get-cli/ | SENTRY_CLI_VERSION="2.42.2" bash
# 2. Validate tag version matches pubspec.yaml version
TAG_VERSION="${GITHUB_REF_NAME#v}"
TAG_VERSION="${TAG_VERSION%%-rc*}"
PUBSPEC_VERSION=$(awk '/^version:/{split($2,a,"+"); print a[1]; exit}' pubspec.yaml)
if [ "$PUBSPEC_VERSION" != "$TAG_VERSION" ]; then
echo "::error::Tag version ($TAG_VERSION) does not match pubspec version ($PUBSPEC_VERSION)."
exit 1
fi
SENTRY_RELEASE="$PUBSPEC_VERSION"
echo "Processing Sentry Release: $SENTRY_RELEASE"
# 3. Create Release
sentry-cli releases new "$SENTRY_RELEASE"
# 4. Upload ProGuard Mapping
MAPPING_FILE="build/app/outputs/mapping/release/mapping.txt"
if [ -f "$MAPPING_FILE" ]; then
echo "Found mapping.txt, uploading ProGuard mapping..."
sentry-cli upload-proguard "$MAPPING_FILE"
else
echo "::error::Could not find mapping.txt at $MAPPING_FILE."
exit 1
fi
# 5. Upload Dart Debug Symbols (Native Dart Stacktrace)
SYMBOLS_DIR="build/app/outputs/symbols"
if [ -d "$SYMBOLS_DIR" ]; then
echo "Uploading Dart debug symbols from $SYMBOLS_DIR..."
sentry-cli debug-files upload "$SYMBOLS_DIR"
else
echo "::error::Symbols directory not found at $SYMBOLS_DIR. Check your Fastfile build arguments."
exit 1
fi
# 6. Finalize
sentry-cli releases finalize "$SENTRY_RELEASE"
+3 -1
View File
@@ -31,7 +31,9 @@ platform :android do
json_key_data: ENV["PLAY_STORE_CONFIG_JSON"] json_key_data: ENV["PLAY_STORE_CONFIG_JSON"]
)[0].to_i )[0].to_i
build_name = last_git_tag.gsub("v", "").split("-").first build_name = last_git_tag.gsub("v", "").split("-").first
sh "flutter build appbundle --verbose --release --dart-define=SERVER_URL=$SERVER_URL --build-number=#{latest_build_number+1} --build-name=#{build_name}" # Add: --obfuscate --split-debug-info=build/app/outputs/symbols
# Note: We run `cd ..` first, so paths are relative to repository root.
sh "cd .. && flutter build appbundle --verbose --release --obfuscate --split-debug-info=build/app/outputs/symbols --dart-define=SERVER_URL=$SERVER_URL --build-number=#{latest_build_number+1} --build-name=#{build_name}"
upload_to_play_store( upload_to_play_store(
json_key_data: ENV["PLAY_STORE_CONFIG_JSON"], json_key_data: ENV["PLAY_STORE_CONFIG_JSON"],
track: track, track: track,
@@ -0,0 +1,45 @@
# 0076. Android Sentry Source Maps & Native Symbols Automation
Date: 2026-02-11
## Status
Accepted
## Context
Android crash reports on Sentry are unreadable due to two levels of obfuscation:
1. **Java/Kotlin:** Minified by R8/ProGuard (e.g., classes appear as `a.b.c`).
2. **Dart:** ARM binaries lack debug info — only raw memory addresses are shown.
This makes production crashes nearly impossible to debug.
## Decision
Update the Android CI/CD pipeline to automatically upload de-obfuscation artifacts to Sentry on every release.
### Build (Fastlane)
Add `--obfuscate --split-debug-info=build/app/outputs/symbols` to the Flutter build command (executed from repository root after `cd ..`). This strips debug info from the binary into a separate `symbols/` directory.
### CI Pipeline (GitHub Actions)
After a successful build, the `release.yaml` workflow:
1. Creates a Sentry release matching the version in `pubspec.yaml`.
2. Uploads `build/app/outputs/mapping/release/mapping.txt` (ProGuard — de-obfuscates Java/Kotlin).
3. Uploads `build/app/outputs/symbols/` (Dart debug symbols — de-obfuscates Flutter stack traces).
4. Finalizes the release.
## Consequences
**Benefits:**
- Full readable stack traces for both Dart and Java/Kotlin crashes in Sentry.
- Automated — no manual upload step needed.
- Smaller app binary (debug info stripped from the APK/AAB).
**Trade-offs:**
- Slightly longer CI build time (symbol separation + upload).
- `SENTRY_AUTH_TOKEN`, `SENTRY_ORG`, `SENTRY_PROJECT` must be maintained as CI secrets.
- Symbol files must be uploaded in the **same workflow run** as the build — running `flutter clean` between build and upload will break de-obfuscation.
+1
View File
@@ -17,6 +17,7 @@ publish_to: "none" # Remove this line if you wish to publish to pub.dev
# https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html # https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html
version: 0.28.2-rc01 version: 0.28.2-rc01
environment: environment:
sdk: ">=3.0.0 <4.0.0" sdk: ">=3.0.0 <4.0.0"