chore(release): v6.0.1-305

This commit is contained in:
Enginex0
2026-07-11 17:38:22 +01:00
parent 5b7373ad7a
commit 000e926693
2 changed files with 20 additions and 3 deletions
+17
View File
@@ -3,6 +3,23 @@
---
## TEESimulator-RS v6.0.1-305
Closes the five gaps Duck-Detector's supplementary probes (#73/#78) surfaced. Two are functional app-crypto fixes, not just probe fixes: on a broken-TEE device, any app using an AndroidKeyStore HMAC key or an RSA-OAEP-SHA256 key was throwing. Beta — the confirmation logs ride in the debug build; not yet field-verified.
### App crypto correctness
- HMAC operations now execute instead of throwing. An AndroidKeyStore HMAC key is symmetric, so an HMAC SIGN entered the asymmetric SIGN path and died on a null keyPair, and no MAC primitive existed. A MacPrimitive now runs `Mac` (HmacSHA256/384/512), truncates to the requested MAC_LENGTH (defaulting to the full digest), and verifies with a constant-time compare. SIGN and VERIFY both work.
- RSA-OAEP-SHA256 decrypt no longer fails with BadPaddingException. The cipher was initialized with no OAEPParameterSpec, so JCA defaulted the OAEP digest to SHA-1 and rejected SHA-256 ciphertext. The correct main and MGF1 digests are now applied; the transformation string is unchanged.
- Grant-domain attest keys now resolve. A self-granted PURPOSE_ATTEST_KEY (a Domain.GRANT descriptor) could not resolve its signer alias, so generateKey errored and the subject key was never stored (KEY_NOT_FOUND on readback). The grant now resolves to the owner key's alias; the subject key stays Domain.APP-readable.
### Supplementary attestation
- MODULE_HASH is now sourced from the framework's own getSupplementaryAttestationInfo so the value byte-matches what a verifier derives, falling back to local re-derivation when that API is unreachable.
### Diagnostics (debug builds only)
- Per-operation oaep-op, hmac-op, and attest-grant lines, plus device-level module-hash and vintf-version source lines, route through the debug logger and stay silent under R8 in release builds.
---
## TEESimulator-RS v6.0.1-282
AUTO-mode key attestation now forges plain attestation from the keybox instead of deferring to the real TEE.
+3 -3
View File
@@ -1,6 +1,6 @@
{
"version": "v6.0.1-282",
"versionCode": 282,
"zipUrl": "https://github.com/Enginex0/TEESimulator-RS/releases/download/v6.0.1-282/TEESimulator-RS-v6.0.1-282-Release.zip",
"version": "v6.0.1-305",
"versionCode": 305,
"zipUrl": "https://github.com/Enginex0/TEESimulator-RS/releases/download/v6.0.1-305/TEESimulator-RS-v6.0.1-305-Release.zip",
"changelog": "https://raw.githubusercontent.com/Enginex0/TEESimulator-RS/main/module/changelog.md"
}