Compare commits

..
13 Commits
Author SHA1 Message Date
Enginex0 d21822eb9d docs(release): bump to v4.3 with changelog and update metadata 2026-03-11 13:12:03 +01:00
Enginex0 095a658996 ci(build): fix pipeline trigger and release job gating
paths-ignore for .github/** was preventing workflow-only pushes
from triggering the pipeline at all. Release job was gated to
push events only, so workflow_dispatch never published. Simplify
paths-ignore to just **.md and allow both push and dispatch to
trigger the release job.
2026-03-11 13:03:35 +01:00
Enginex0 70e8968e44 ci(build): use mv instead of cp to avoid duplicate artifacts
cp left the original zip alongside the renamed copy, so the glob
matched both — doubling artifact size. mv removes the original.
2026-03-11 12:51:02 +01:00
Enginex0 c122ded7bf perf(daemon): add restart backoff, process priority, and map eviction
Supervisor had zero-delay restart on crash loops — pins CPU core at
100% if daemon keeps dying. Add exponential backoff (500ms to 30s cap,
resets after 30s stable). Set nice=10 on daemon child to yield CPU
to foreground apps. Evict stale entries from fileLocks and rate limiter
ConcurrentHashMaps that grew unbounded. Upload pre-built flashable zips
in CI instead of unpacking and re-compressing loose files.
2026-03-11 12:41:57 +01:00
Enginex0 7b510a9915 perf(logging): gate debug-level logs behind isDebugBuild
debug() was hitting Log.d() unconditionally in release builds —
every intercepted binder transaction triggered string formatting
and logcat syscalls. verbose() already had the guard; debug() was
just missing it. Also remove dead SERVICE_SLEEP_MS constant.
2026-03-11 12:41:46 +01:00
Enginex0 8f63dda31b ci(build): add release job with changelog and both ZIPs
The workflow only uploaded unzipped contents as CI artifacts —
no GitHub release was ever created from CI. Restructured into
build + release jobs: build produces both debug and release ZIPs
(renamed to clean `TEESimulator-vX.Y-{Variant}.zip` format),
release extracts changelog from module/changelog.md and publishes
a GitHub release with both ZIPs attached.
2026-03-11 04:06:20 +01:00
Enginex0 9896df93de build(gradle): keep debug symbols in debug variant
Debug ZIPs now ship unstripped native libs sourced from
merged_native_libs instead of stripped_native_libs. Gives
meaningful stack traces for crash debugging on-device.
2026-03-11 00:45:00 +01:00
Enginex0 0280bcf189 docs(readme): add build badge and building-from-source section 2026-03-11 00:28:28 +01:00
Enginex0 438a462bdf ci(build): add Rust toolchain and cargo-ndk for native-certgen
Gradle's buildRustCertgen task requires cargo-ndk and Android NDK
targets to cross-compile libcertgen.so. Without these, CI fails on
any commit after 32cfcb3 which wired the Rust crate into the pipeline.
2026-03-11 00:12:02 +01:00
Enginex0 40b08cd648 docs(release): bump to v4.2 with changelog and update metadata 2026-03-10 16:55:39 +01:00
Enginex0 c5ed627f68 chore(module): bump versionCode to 95 2026-03-10 16:37:58 +01:00
Enginex0 bee73eb39b perf(binder): skip interception for system transaction codes
AIDL methods use codes 1..0x00ffffff. System transactions like
PING_TRANSACTION (0x5f4e4750) fall above that range. Intercepting
pings forces a full JNI round-trip to Java and back, adding enough
latency for timing detectors to flag the ratio (3.85x vs 3.0x
threshold). Early-return for codes above LAST_CALL_TRANSACTION
eliminates this overhead while preserving all AIDL interception.
2026-03-10 16:37:50 +01:00
Enginex0 a0ee77202c fix(attestation): correct leaf CN casing and enforce keystore2 parameter policy
Leaf cert Subject CN used "KeyStore" (capital S) but AOSP
KeyGenParameterSpec uses "Keystore" (lowercase s). Fixed in both
the Rust native certgen and BouncyCastle paths.

Replicate keystore2's security_level.rs parameter validation for
software-generated keys: reject CREATION_DATETIME (output-only tag,
ResponseCode 20) and device ID attestation tags (CANNOT_ATTEST_IDS
-66) that real keystore2 blocks before they reach the HAL.

Also fix createErrorReply parcel write order — AIDL protocol expects
exception_code, message, error_code but we had message and error_code
swapped, causing malformed replies for positive error codes.
2026-03-10 14:23:33 +01:00
14 changed files with 209 additions and 86 deletions
+95 -68
View File
@@ -3,16 +3,10 @@ name: Build
on: on:
push: push:
branches: [ "main" ] branches: [ "main" ]
paths-ignore: paths-ignore: [ '**.md' ]
- '**.md'
- '.github/**'
- '!.github/workflows/**'
pull_request: pull_request:
branches: [ "main" ] branches: [ "main" ]
paths-ignore: paths-ignore: [ '**.md' ]
- '**.md'
- '.github/**'
- '!.github/workflows/**'
workflow_dispatch: workflow_dispatch:
concurrency: concurrency:
@@ -22,18 +16,9 @@ concurrency:
jobs: jobs:
build: build:
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
id-token: write
attestations: write
contents: read
outputs:
releaseName: ${{ steps.prepareArtifact.outputs.releaseName }}
debugName: ${{ steps.prepareArtifact.outputs.debugName }}
steps: steps:
- name: Check out - uses: actions/checkout@v4
uses: actions/checkout@v4
with: with:
submodules: "recursive" submodules: "recursive"
fetch-depth: 0 fetch-depth: 0
@@ -45,6 +30,25 @@ jobs:
java-version: 21 java-version: 21
cache: 'gradle' cache: 'gradle'
- name: Setup Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
targets: aarch64-linux-android,armv7-linux-androideabi,i686-linux-android,x86_64-linux-android
- name: Cache Rust artifacts
uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
~/.cargo/bin/cargo-ndk
native-certgen/target
key: rust-${{ runner.os }}-${{ hashFiles('native-certgen/Cargo.lock') }}
restore-keys: rust-${{ runner.os }}-
- name: Install cargo-ndk
run: command -v cargo-ndk || cargo install cargo-ndk
- name: Set up ccache - name: Set up ccache
uses: hendrikmuhs/ccache-action@v1.2 uses: hendrikmuhs/ccache-action@v1.2
with: with:
@@ -60,73 +64,96 @@ jobs:
- name: Build with Gradle - name: Build with Gradle
run: | run: |
chmod +x ./gradlew chmod +x ./gradlew
./gradlew zipRelease zipDebug -Porg.gradle.parallel=true -Porg.gradle.vfs.watch=true -Dorg.gradle.jvmargs=-Xmx2048m ./gradlew zipRelease zipDebug -Porg.gradle.parallel=true -Porg.gradle.vfs.watch=true -Dorg.gradle.jvmargs=-Xmx2048m
- name: Prepare artifact - name: Read version
if: success() id: ver
id: prepareArtifact run: |
ver=$(grep 'val verName' app/build.gradle.kts | sed 's/.*"\(.*\)".*/\1/')
echo "version=${ver}" >> "$GITHUB_OUTPUT"
- name: Rename ZIPs for release
run: | run: |
set -e
RELEASE_FILE=$(find out -name "*Release*.zip" | head -1) RELEASE_FILE=$(find out -name "*Release*.zip" | head -1)
DEBUG_FILE=$(find out -name "*Debug*.zip" | head -1) DEBUG_FILE=$(find out -name "*Debug*.zip" | head -1)
if [[ -z "$RELEASE_FILE" || -z "$DEBUG_FILE" ]]; then if [[ -z "$RELEASE_FILE" || -z "$DEBUG_FILE" ]]; then
echo "Error: Could not find release or debug files in out/" echo "::error::Could not find release or debug ZIPs in out/"
echo "Contents of out/ directory:" ls -la out/ || echo "out/ does not exist"
ls -la out/ || echo "out/ directory does not exist"
exit 1 exit 1
fi fi
# Extract names
RELEASE_NAME=$(basename "$RELEASE_FILE" .zip)
DEBUG_NAME=$(basename "$DEBUG_FILE" .zip)
echo "releaseName=$RELEASE_NAME" >> $GITHUB_OUTPUT
echo "debugName=$DEBUG_NAME" >> $GITHUB_OUTPUT
mkdir -p module-release module-debug mv "$RELEASE_FILE" "out/TEESimulator-${VER}-Release.zip"
unzip -q "$RELEASE_FILE" -d module-release mv "$DEBUG_FILE" "out/TEESimulator-${VER}-Debug.zip"
unzip -q "$DEBUG_FILE" -d module-debug
echo " Release: $RELEASE_NAME"
echo " Debug: $DEBUG_NAME"
- name: Upload release echo "Release: TEESimulator-${VER}-Release.zip ($(du -h "out/TEESimulator-${VER}-Release.zip" | cut -f1))"
if: success() echo "Debug: TEESimulator-${VER}-Debug.zip ($(du -h "out/TEESimulator-${VER}-Debug.zip" | cut -f1))"
id: release env:
uses: actions/upload-artifact@v4 VER: ${{ steps.ver.outputs.version }}
- uses: actions/upload-artifact@v4
with: with:
name: ${{ steps.prepareArtifact.outputs.releaseName }} name: TEESimulator-release-zip
path: "./module-release/*" path: out/TEESimulator-*-Release.zip
retention-days: 30 retention-days: 30
compression-level: 6 compression-level: 0
- name: Upload debug - uses: actions/upload-artifact@v4
if: success()
id: debug
uses: actions/upload-artifact@v4
with: with:
name: ${{ steps.prepareArtifact.outputs.debugName }} name: TEESimulator-debug-zip
path: "./module-debug/*" path: out/TEESimulator-*-Debug.zip
retention-days: 7 retention-days: 7
compression-level: 6 compression-level: 0
- name: Upload release mappings - uses: actions/upload-artifact@v4
if: success()
uses: actions/upload-artifact@v4
with: with:
name: release-mappings-${{ github.run_number }} name: release-mappings
path: "./app/build/outputs/mapping/release" path: app/build/outputs/mapping/release
retention-days: 30 retention-days: 30
compression-level: 9 compression-level: 9
- name: Summary release:
if: always() needs: build
if: (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- name: Read version
id: ver
run: | run: |
echo "## Build Summary" >> $GITHUB_STEP_SUMMARY ver=$(grep 'val verName' app/build.gradle.kts | sed 's/.*"\(.*\)".*/\1/')
echo "- **Status**: ${{ job.status }}" >> $GITHUB_STEP_SUMMARY echo "version=${ver}" >> "$GITHUB_OUTPUT"
echo "- **Gradle Tasks**: assembleRelease, assembleDebug" >> $GITHUB_STEP_SUMMARY
if [[ "${{ job.status }}" == "success" ]]; then - uses: actions/download-artifact@v4
echo "- **Release Artifact**: ${{ steps.prepareArtifact.outputs.releaseName }}" >> $GITHUB_STEP_SUMMARY with:
echo "- **Debug Artifact**: ${{ steps.prepareArtifact.outputs.debugName }}" >> $GITHUB_STEP_SUMMARY name: TEESimulator-release-zip
fi path: zips
- uses: actions/download-artifact@v4
with:
name: TEESimulator-debug-zip
path: zips
- name: Extract changelog
run: |
ver="${VER#v}"
awk "/^## TEESimulator v${ver}/{flag=1; next} /^## TEESimulator v/{if(flag) exit} flag" module/changelog.md > /tmp/notes.md
cat /tmp/notes.md
env:
VER: ${{ steps.ver.outputs.version }}
- name: Create release
run: |
gh release delete "$VER" --yes 2>/dev/null || true
gh release create "$VER" \
--title "$VER" \
--latest \
--notes-file /tmp/notes.md \
"zips/TEESimulator-${VER}-Release.zip" \
"zips/TEESimulator-${VER}-Debug.zip"
env:
VER: ${{ steps.ver.outputs.version }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+20 -1
View File
@@ -3,7 +3,8 @@
<p align="center"><b>Full TEE Emulation for Rooted Android</b></p> <p align="center"><b>Full TEE Emulation for Rooted Android</b></p>
<p align="center">Hardware attestation. Software keys. Zero detection.</p> <p align="center">Hardware attestation. Software keys. Zero detection.</p>
<p align="center"> <p align="center">
<img src="https://img.shields.io/badge/version-v4.0-blue?style=for-the-badge" alt="v4.0"> <a href="https://github.com/Enginex0/TEESimulator/actions/workflows/build.yml"><img src="https://github.com/Enginex0/TEESimulator/actions/workflows/build.yml/badge.svg" alt="Build"></a>
<img src="https://img.shields.io/badge/version-v4.2-blue?style=for-the-badge" alt="v4.2">
<img src="https://img.shields.io/badge/Android-10%2B-green?style=for-the-badge&logo=android" alt="Android 10+"> <img src="https://img.shields.io/badge/Android-10%2B-green?style=for-the-badge&logo=android" alt="Android 10+">
<img src="https://img.shields.io/badge/Telegram-community-blue?style=for-the-badge&logo=telegram" alt="Telegram"> <img src="https://img.shields.io/badge/Telegram-community-blue?style=for-the-badge&logo=telegram" alt="Telegram">
</p> </p>
@@ -112,6 +113,24 @@ TEESimulator replaces TrickyStore, TrickyStoreOSS, and their forks. Existing con
--- ---
## 🔨 Building from Source
The CI workflow builds on every push to `main`. You can also build locally or trigger a build from your own fork.
**Prerequisites:** JDK 21, Android SDK/NDK 27, Rust stable with `aarch64-linux-android` target, `cargo-ndk`.
```bash
git clone https://github.com/Enginex0/TEESimulator.git
cd TEESimulator
./gradlew zipRelease zipDebug
```
Output ZIPs land in `out/`. The Gradle build automatically invokes `cargo ndk` to cross-compile `libcertgen.so` before packaging.
To rebuild from a fork, push to `main` or use **Actions → Build → Run workflow**. The workflow installs all toolchains (Java, Rust, cargo-ndk, ccache) and uploads Release + Debug ZIPs as artifacts.
---
## ⚙️ Configuration ## ⚙️ Configuration
All configuration files live at `/data/adb/tricky_store/` and are monitored by `FileObserver` — changes take effect immediately without rebooting. All configuration files live at `/data/adb/tricky_store/` and are monitored by `FileObserver` — changes take effect immediately without rebooting.
+9 -8
View File
@@ -29,7 +29,7 @@ val gitExecutor = objects.newInstance(GitExecutor::class.java)
val gitCommitCount = gitExecutor.execute("git rev-list HEAD --count", rootDir).toInt() val gitCommitCount = gitExecutor.execute("git rev-list HEAD --count", rootDir).toInt()
val gitCommitHash = gitExecutor.execute("git rev-parse --verify --short HEAD", rootDir) val gitCommitHash = gitExecutor.execute("git rev-parse --verify --short HEAD", rootDir)
val verName = "v4.1" val verName = "v4.3"
android { android {
namespace = "org.matrix.TEESimulator" namespace = "org.matrix.TEESimulator"
@@ -121,8 +121,8 @@ androidComponents {
dependsOn("package${capitalized}") dependsOn("package${capitalized}")
} else { } else {
dependsOn("minify${capitalized}WithR8") dependsOn("minify${capitalized}WithR8")
dependsOn("strip${capitalized}DebugSymbols")
} }
dependsOn("strip${capitalized}DebugSymbols")
dependsOn(buildRustCertgen) dependsOn(buildRustCertgen)
if (isDebug) { if (isDebug) {
@@ -140,12 +140,13 @@ androidComponents {
} }
} }
from( val nativeLibsDir = if (isDebug) {
project.layout.buildDirectory.dir( "intermediates/merged_native_libs/${variant.name}/merge${capitalized}NativeLibs/out/lib"
"intermediates/stripped_native_libs/${variant.name}/strip${capitalized}DebugSymbols/out/lib" } else {
) "intermediates/stripped_native_libs/${variant.name}/strip${capitalized}DebugSymbols/out/lib"
) { }
into("lib") // Place them in the 'lib' subfolder of the staging directory. from(project.layout.buildDirectory.dir(nativeLibsDir)) {
into("lib")
include("**/libinject.so", "**/libTEESimulator.so", "**/libsupervisor.so", "**/libcertgen.so") include("**/libinject.so", "**/libTEESimulator.so", "**/libsupervisor.so", "**/libcertgen.so")
} }
+6
View File
@@ -358,6 +358,12 @@ void inspectAndRewriteTransaction(binder_transaction_data *txn_data) {
if (txn_data->data_size > kMaxInterceptableDataSize) if (txn_data->data_size > kMaxInterceptableDataSize)
return; return;
// AIDL methods use codes in [FIRST_CALL_TRANSACTION, LAST_CALL_TRANSACTION] (1..0x00ffffff).
// System transactions (PING, INTERFACE, DUMP, SHELL_COMMAND) use codes above that range.
// Skip those — intercepting a ping adds measurable latency that timing detectors flag.
if (txn_data->code > 0x00ffffffu && txn_data->code != intercept::kBackdoorCode)
return;
bool hijack = false; bool hijack = false;
ThreadTransactionInfo info; ThreadTransactionInfo info;
+20 -1
View File
@@ -2,11 +2,13 @@
#include <unistd.h> #include <unistd.h>
#include <sys/wait.h> #include <sys/wait.h>
#include <sys/prctl.h> #include <sys/prctl.h>
#include <sys/resource.h>
#include <signal.h> #include <signal.h>
#include <stdlib.h> #include <stdlib.h>
#include <stdio.h> #include <stdio.h>
#include <string.h> #include <string.h>
#include <errno.h> #include <errno.h>
#include <time.h>
static volatile sig_atomic_t should_exit = 0; static volatile sig_atomic_t should_exit = 0;
@@ -27,7 +29,12 @@ int main(int argc, char *argv[]) {
const char *daemon_path = argv[1]; const char *daemon_path = argv[1];
char **daemon_argv = &argv[1]; char **daemon_argv = &argv[1];
int backoff_ms = 500;
while (!should_exit) { while (!should_exit) {
struct timespec child_start;
clock_gettime(CLOCK_MONOTONIC, &child_start);
pid_t pid = fork(); pid_t pid = fork();
if (pid < 0) { if (pid < 0) {
@@ -39,6 +46,7 @@ int main(int argc, char *argv[]) {
if (pid == 0) { if (pid == 0) {
// Child: become the daemon // Child: become the daemon
prctl(PR_SET_PDEATHSIG, SIGKILL); // Die if parent dies prctl(PR_SET_PDEATHSIG, SIGKILL); // Die if parent dies
setpriority(PRIO_PROCESS, 0, 10); // lower CPU priority than foreground
execv(daemon_path, daemon_argv); execv(daemon_path, daemon_argv);
perror("execv failed"); perror("execv failed");
_exit(127); _exit(127);
@@ -50,7 +58,18 @@ int main(int argc, char *argv[]) {
if (should_exit) break; if (should_exit) break;
// Instant restart - no delay // Exponential backoff on rapid crashes, reset if child was stable
struct timespec now;
clock_gettime(CLOCK_MONOTONIC, &now);
long lived_ms = (now.tv_sec - child_start.tv_sec) * 1000 +
(now.tv_nsec - child_start.tv_nsec) / 1000000;
if (lived_ms > 30000) {
backoff_ms = 500;
} else {
usleep(backoff_ms * 1000);
if (backoff_ms < 30000) backoff_ms *= 2;
}
} }
return 0; return 0;
@@ -23,8 +23,6 @@ import org.matrix.TEESimulator.util.AndroidDeviceUtils
object App { object App {
// The delay in milliseconds before retrying to initialize the interceptor. // The delay in milliseconds before retrying to initialize the interceptor.
private const val RETRY_DELAY_MS = 1000L private const val RETRY_DELAY_MS = 1000L
// The sleep duration in milliseconds for the main service loop to keep the process alive.
private const val SERVICE_SLEEP_MS = 1000000L
/** /**
* The main entry point of the TEESimulator application. * The main entry point of the TEESimulator application.
@@ -17,8 +17,8 @@ object InterceptorUtils {
fun createErrorReply(errorCode: Int): BinderInterceptor.TransactionResult.OverrideReply { fun createErrorReply(errorCode: Int): BinderInterceptor.TransactionResult.OverrideReply {
val parcel = Parcel.obtain().apply { val parcel = Parcel.obtain().apply {
writeInt(EX_SERVICE_SPECIFIC) writeInt(EX_SERVICE_SPECIFIC)
writeInt(errorCode)
writeString(null) writeString(null)
writeInt(errorCode)
} }
return BinderInterceptor.TransactionResult.OverrideReply(parcel) return BinderInterceptor.TransactionResult.OverrideReply(parcel)
} }
@@ -129,6 +129,7 @@ object GeneratedKeyPersistence {
val file = File(PERSISTENCE_DIR, keyFileName(keyId.uid, keyId.alias)) val file = File(PERSISTENCE_DIR, keyFileName(keyId.uid, keyId.alias))
if (file.exists()) { if (file.exists()) {
if (file.delete()) { if (file.delete()) {
fileLocks.remove(keyFileName(keyId.uid, keyId.alias))
SystemLogger.debug("Deleted persisted key: $keyId") SystemLogger.debug("Deleted persisted key: $keyId")
} else { } else {
SystemLogger.warning("Failed to delete persisted key file: ${file.name}") SystemLogger.warning("Failed to delete persisted key file: ${file.name}")
@@ -158,6 +159,7 @@ object GeneratedKeyPersistence {
if (file.delete()) count++ if (file.delete()) count++
} }
} }
fileLocks.clear()
SystemLogger.info("Deleted $count persisted key files") SystemLogger.info("Deleted $count persisted key files")
}.onFailure { e -> }.onFailure { e ->
SystemLogger.error("Failed to delete all persisted keys", e) SystemLogger.error("Failed to delete all persisted keys", e)
@@ -254,6 +254,18 @@ class KeyMintSecurityLevelInterceptor(
return InterceptorUtils.createErrorReply(KEYMINT_INVALID_INPUT_LENGTH) return InterceptorUtils.createErrorReply(KEYMINT_INVALID_INPUT_LENGTH)
} }
if (params.any { it.tag == Tag.CREATION_DATETIME }) {
SystemLogger.warning("[TX_ID: $txId] Rejecting CREATION_DATETIME in generateKey params")
return InterceptorUtils.createErrorReply(RESPONSE_INVALID_ARGUMENT)
}
if (parsedParams.serial != null || parsedParams.imei != null ||
parsedParams.meid != null || parsedParams.secondImei != null ||
params.any { it.tag == Tag.DEVICE_UNIQUE_ATTESTATION }) {
SystemLogger.warning("[TX_ID: $txId] Rejecting device ID attestation for uid=$callingUid")
return InterceptorUtils.createErrorReply(KEYMINT_CANNOT_ATTEST_IDS)
}
val keyId = KeyIdentifier(callingUid, keyDescriptor.alias) val keyId = KeyIdentifier(callingUid, keyDescriptor.alias)
val isAttestKeyRequest = parsedParams.isAttestKey() val isAttestKeyRequest = parsedParams.isAttestKey()
@@ -515,6 +527,8 @@ class KeyMintSecurityLevelInterceptor(
// Binder buffer is ~1MB; 256KB provides 4x safety margin for transaction overhead // Binder buffer is ~1MB; 256KB provides 4x safety margin for transaction overhead
private const val MAX_ALIAS_LENGTH = 256 * 1024 private const val MAX_ALIAS_LENGTH = 256 * 1024
private const val KEYMINT_INVALID_INPUT_LENGTH = -21 private const val KEYMINT_INVALID_INPUT_LENGTH = -21
private const val RESPONSE_INVALID_ARGUMENT = 20
private const val KEYMINT_CANNOT_ATTEST_IDS = -66
private const val MAX_CONCURRENT_HW_KEYGEN_PER_UID = 2 private const val MAX_CONCURRENT_HW_KEYGEN_PER_UID = 2
// Sliding window: max hardware keygen permits per UID within the burst window // Sliding window: max hardware keygen permits per UID within the burst window
private const val MAX_HW_KEYGEN_PER_WINDOW = 2 private const val MAX_HW_KEYGEN_PER_WINDOW = 2
@@ -532,6 +546,10 @@ class KeyMintSecurityLevelInterceptor(
val timestamps = uidKeygenTimestamps.computeIfAbsent(uid) { mutableListOf() } val timestamps = uidKeygenTimestamps.computeIfAbsent(uid) { mutableListOf() }
synchronized(timestamps) { synchronized(timestamps) {
timestamps.removeAll { now - it > BURST_WINDOW_MS } timestamps.removeAll { now - it > BURST_WINDOW_MS }
if (timestamps.isEmpty()) {
uidKeygenTimestamps.remove(uid, timestamps)
uidHardwareKeygenCount.remove(uid)
}
return timestamps.size return timestamps.size
} }
} }
@@ -19,6 +19,7 @@ object SystemLogger {
* @param message The message to log. * @param message The message to log.
*/ */
fun debug(message: String) { fun debug(message: String) {
if (!isDebugBuild) return
Log.d(TAG, message) Log.d(TAG, message)
} }
@@ -213,7 +213,7 @@ object CertificateGenerator {
uid: Int, uid: Int,
securityLevel: Int, securityLevel: Int,
): Certificate { ): Certificate {
val subject = params.certificateSubject ?: X500Name("CN=Android KeyStore Key") val subject = params.certificateSubject ?: X500Name("CN=Android Keystore Key")
val leafNotAfter = val leafNotAfter =
(signingKeyPair.public as? X509Certificate)?.notAfter (signingKeyPair.public as? X509Certificate)?.notAfter
?: Date(System.currentTimeMillis() + 31536000000L) ?: Date(System.currentTimeMillis() + 31536000000L)
+32
View File
@@ -1,3 +1,35 @@
## TEESimulator v4.3: Performance & Reliability
- **Debug log gating** — `SystemLogger.debug()` now skipped entirely in release builds, eliminating unnecessary logcat syscalls on every intercepted transaction.
- **Supervisor backoff** — Exponential restart delay (500ms → 30s cap) prevents CPU spin if the daemon crashes repeatedly. Resets automatically once stable.
- **Process priority** — Daemon runs at nice=10, yielding CPU to foreground apps on constrained devices.
- **Map eviction** — Rate limiter and file lock maps now evict stale entries instead of growing unbounded.
- **CI pipeline** — Single-trigger build→release pipeline with proper changelog extraction and correctly sized artifacts.
---
## TEESimulator v4.2: Detection Evasion Hardening
Fixes 6 detection vectors flagged by attestation validator apps.
### Attestation Policy Enforcement
Replicate AOSP keystore2's `add_required_parameters()` validation that our software keygen path was bypassing:
- **CREATION_DATETIME** — Reject caller-provided input with `INVALID_ARGUMENT (20)`, matching `security_level.rs:424`. Our cert gen still adds its own timestamp, same as real keystore2.
- **Device ID attestation** — Reject ATTESTATION_ID_SERIAL, IMEI, MEID, SECOND_IMEI, and DEVICE_UNIQUE_ATTESTATION with `CANNOT_ATTEST_IDS (-66)`. No consumer app has READ_PRIVILEGED_PHONE_STATE.
- **Error reply format** — Fixed AIDL ServiceSpecificException parcel write order (was errorCode→message, now message→errorCode).
### Certificate Fix
Leaf certificate Subject CN corrected from "Android KeyStore Key" to "Android Keystore Key" (lowercase s), matching AOSP `KeyGenParameterSpec.java:282`. Both Kotlin and Rust paths.
### Binder Timing
Skip interception for system transaction codes (PING, INTERFACE, DUMP) above LAST_CALL_TRANSACTION. Eliminates the JNI round-trip that inflated binder ping ratio to 3.85x (detector threshold: 3.0x).
---
## TEESimulator v4.1: Boot Identity Persistence ## TEESimulator v4.1: Boot Identity Persistence
Bugfix release. The vbmeta boot key digest was randomizing on every reboot, producing a different RootOfTrust in attestation certificates each boot. Bugfix release. The vbmeta boot key digest was randomizing on every reboot, producing a different RootOfTrust in attestation certificates each boot.
+3 -3
View File
@@ -1,6 +1,6 @@
{ {
"version": "v4.1", "version": "v4.3",
"versionCode": 94, "versionCode": 107,
"zipUrl": "https://github.com/Enginex0/TEESimulator/releases/download/v4.1/TEESimulator-v4.1-Release.zip", "zipUrl": "https://github.com/Enginex0/TEESimulator/releases/download/v4.3/TEESimulator-v4.3-Release.zip",
"changelog": "https://raw.githubusercontent.com/Enginex0/TEESimulator/main/module/changelog.md" "changelog": "https://raw.githubusercontent.com/Enginex0/TEESimulator/main/module/changelog.md"
} }
+1 -1
View File
@@ -51,7 +51,7 @@ fn build_leaf_cert(
let subject_dn_der = if let Some(ref subject) = params.cert_subject { let subject_dn_der = if let Some(ref subject) = params.cert_subject {
subject.clone() subject.clone()
} else { } else {
encode_simple_cn_dn("Android KeyStore Key") encode_simple_cn_dn("Android Keystore Key")
}; };
// Validity // Validity