Compare commits

...
9 Commits
Author SHA1 Message Date
Enginex0 d21822eb9d docs(release): bump to v4.3 with changelog and update metadata 2026-03-11 13:12:03 +01:00
Enginex0 095a658996 ci(build): fix pipeline trigger and release job gating
paths-ignore for .github/** was preventing workflow-only pushes
from triggering the pipeline at all. Release job was gated to
push events only, so workflow_dispatch never published. Simplify
paths-ignore to just **.md and allow both push and dispatch to
trigger the release job.
2026-03-11 13:03:35 +01:00
Enginex0 70e8968e44 ci(build): use mv instead of cp to avoid duplicate artifacts
cp left the original zip alongside the renamed copy, so the glob
matched both — doubling artifact size. mv removes the original.
2026-03-11 12:51:02 +01:00
Enginex0 c122ded7bf perf(daemon): add restart backoff, process priority, and map eviction
Supervisor had zero-delay restart on crash loops — pins CPU core at
100% if daemon keeps dying. Add exponential backoff (500ms to 30s cap,
resets after 30s stable). Set nice=10 on daemon child to yield CPU
to foreground apps. Evict stale entries from fileLocks and rate limiter
ConcurrentHashMaps that grew unbounded. Upload pre-built flashable zips
in CI instead of unpacking and re-compressing loose files.
2026-03-11 12:41:57 +01:00
Enginex0 7b510a9915 perf(logging): gate debug-level logs behind isDebugBuild
debug() was hitting Log.d() unconditionally in release builds —
every intercepted binder transaction triggered string formatting
and logcat syscalls. verbose() already had the guard; debug() was
just missing it. Also remove dead SERVICE_SLEEP_MS constant.
2026-03-11 12:41:46 +01:00
Enginex0 8f63dda31b ci(build): add release job with changelog and both ZIPs
The workflow only uploaded unzipped contents as CI artifacts —
no GitHub release was ever created from CI. Restructured into
build + release jobs: build produces both debug and release ZIPs
(renamed to clean `TEESimulator-vX.Y-{Variant}.zip` format),
release extracts changelog from module/changelog.md and publishes
a GitHub release with both ZIPs attached.
2026-03-11 04:06:20 +01:00
Enginex0 9896df93de build(gradle): keep debug symbols in debug variant
Debug ZIPs now ship unstripped native libs sourced from
merged_native_libs instead of stripped_native_libs. Gives
meaningful stack traces for crash debugging on-device.
2026-03-11 00:45:00 +01:00
Enginex0 0280bcf189 docs(readme): add build badge and building-from-source section 2026-03-11 00:28:28 +01:00
Enginex0 438a462bdf ci(build): add Rust toolchain and cargo-ndk for native-certgen
Gradle's buildRustCertgen task requires cargo-ndk and Android NDK
targets to cross-compile libcertgen.so. Without these, CI fails on
any commit after 32cfcb3 which wired the Rust crate into the pipeline.
2026-03-11 00:12:02 +01:00
10 changed files with 164 additions and 83 deletions
+95 -68
View File
@@ -3,16 +3,10 @@ name: Build
on: on:
push: push:
branches: [ "main" ] branches: [ "main" ]
paths-ignore: paths-ignore: [ '**.md' ]
- '**.md'
- '.github/**'
- '!.github/workflows/**'
pull_request: pull_request:
branches: [ "main" ] branches: [ "main" ]
paths-ignore: paths-ignore: [ '**.md' ]
- '**.md'
- '.github/**'
- '!.github/workflows/**'
workflow_dispatch: workflow_dispatch:
concurrency: concurrency:
@@ -22,18 +16,9 @@ concurrency:
jobs: jobs:
build: build:
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
id-token: write
attestations: write
contents: read
outputs:
releaseName: ${{ steps.prepareArtifact.outputs.releaseName }}
debugName: ${{ steps.prepareArtifact.outputs.debugName }}
steps: steps:
- name: Check out - uses: actions/checkout@v4
uses: actions/checkout@v4
with: with:
submodules: "recursive" submodules: "recursive"
fetch-depth: 0 fetch-depth: 0
@@ -45,6 +30,25 @@ jobs:
java-version: 21 java-version: 21
cache: 'gradle' cache: 'gradle'
- name: Setup Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
targets: aarch64-linux-android,armv7-linux-androideabi,i686-linux-android,x86_64-linux-android
- name: Cache Rust artifacts
uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
~/.cargo/bin/cargo-ndk
native-certgen/target
key: rust-${{ runner.os }}-${{ hashFiles('native-certgen/Cargo.lock') }}
restore-keys: rust-${{ runner.os }}-
- name: Install cargo-ndk
run: command -v cargo-ndk || cargo install cargo-ndk
- name: Set up ccache - name: Set up ccache
uses: hendrikmuhs/ccache-action@v1.2 uses: hendrikmuhs/ccache-action@v1.2
with: with:
@@ -60,73 +64,96 @@ jobs:
- name: Build with Gradle - name: Build with Gradle
run: | run: |
chmod +x ./gradlew chmod +x ./gradlew
./gradlew zipRelease zipDebug -Porg.gradle.parallel=true -Porg.gradle.vfs.watch=true -Dorg.gradle.jvmargs=-Xmx2048m ./gradlew zipRelease zipDebug -Porg.gradle.parallel=true -Porg.gradle.vfs.watch=true -Dorg.gradle.jvmargs=-Xmx2048m
- name: Prepare artifact - name: Read version
if: success() id: ver
id: prepareArtifact run: |
ver=$(grep 'val verName' app/build.gradle.kts | sed 's/.*"\(.*\)".*/\1/')
echo "version=${ver}" >> "$GITHUB_OUTPUT"
- name: Rename ZIPs for release
run: | run: |
set -e
RELEASE_FILE=$(find out -name "*Release*.zip" | head -1) RELEASE_FILE=$(find out -name "*Release*.zip" | head -1)
DEBUG_FILE=$(find out -name "*Debug*.zip" | head -1) DEBUG_FILE=$(find out -name "*Debug*.zip" | head -1)
if [[ -z "$RELEASE_FILE" || -z "$DEBUG_FILE" ]]; then if [[ -z "$RELEASE_FILE" || -z "$DEBUG_FILE" ]]; then
echo "Error: Could not find release or debug files in out/" echo "::error::Could not find release or debug ZIPs in out/"
echo "Contents of out/ directory:" ls -la out/ || echo "out/ does not exist"
ls -la out/ || echo "out/ directory does not exist"
exit 1 exit 1
fi fi
# Extract names
RELEASE_NAME=$(basename "$RELEASE_FILE" .zip)
DEBUG_NAME=$(basename "$DEBUG_FILE" .zip)
echo "releaseName=$RELEASE_NAME" >> $GITHUB_OUTPUT
echo "debugName=$DEBUG_NAME" >> $GITHUB_OUTPUT
mkdir -p module-release module-debug mv "$RELEASE_FILE" "out/TEESimulator-${VER}-Release.zip"
unzip -q "$RELEASE_FILE" -d module-release mv "$DEBUG_FILE" "out/TEESimulator-${VER}-Debug.zip"
unzip -q "$DEBUG_FILE" -d module-debug
echo " Release: $RELEASE_NAME"
echo " Debug: $DEBUG_NAME"
- name: Upload release echo "Release: TEESimulator-${VER}-Release.zip ($(du -h "out/TEESimulator-${VER}-Release.zip" | cut -f1))"
if: success() echo "Debug: TEESimulator-${VER}-Debug.zip ($(du -h "out/TEESimulator-${VER}-Debug.zip" | cut -f1))"
id: release env:
uses: actions/upload-artifact@v4 VER: ${{ steps.ver.outputs.version }}
- uses: actions/upload-artifact@v4
with: with:
name: ${{ steps.prepareArtifact.outputs.releaseName }} name: TEESimulator-release-zip
path: "./module-release/*" path: out/TEESimulator-*-Release.zip
retention-days: 30 retention-days: 30
compression-level: 6 compression-level: 0
- name: Upload debug - uses: actions/upload-artifact@v4
if: success()
id: debug
uses: actions/upload-artifact@v4
with: with:
name: ${{ steps.prepareArtifact.outputs.debugName }} name: TEESimulator-debug-zip
path: "./module-debug/*" path: out/TEESimulator-*-Debug.zip
retention-days: 7 retention-days: 7
compression-level: 6 compression-level: 0
- name: Upload release mappings - uses: actions/upload-artifact@v4
if: success()
uses: actions/upload-artifact@v4
with: with:
name: release-mappings-${{ github.run_number }} name: release-mappings
path: "./app/build/outputs/mapping/release" path: app/build/outputs/mapping/release
retention-days: 30 retention-days: 30
compression-level: 9 compression-level: 9
- name: Summary release:
if: always() needs: build
if: (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- name: Read version
id: ver
run: | run: |
echo "## Build Summary" >> $GITHUB_STEP_SUMMARY ver=$(grep 'val verName' app/build.gradle.kts | sed 's/.*"\(.*\)".*/\1/')
echo "- **Status**: ${{ job.status }}" >> $GITHUB_STEP_SUMMARY echo "version=${ver}" >> "$GITHUB_OUTPUT"
echo "- **Gradle Tasks**: assembleRelease, assembleDebug" >> $GITHUB_STEP_SUMMARY
if [[ "${{ job.status }}" == "success" ]]; then - uses: actions/download-artifact@v4
echo "- **Release Artifact**: ${{ steps.prepareArtifact.outputs.releaseName }}" >> $GITHUB_STEP_SUMMARY with:
echo "- **Debug Artifact**: ${{ steps.prepareArtifact.outputs.debugName }}" >> $GITHUB_STEP_SUMMARY name: TEESimulator-release-zip
fi path: zips
- uses: actions/download-artifact@v4
with:
name: TEESimulator-debug-zip
path: zips
- name: Extract changelog
run: |
ver="${VER#v}"
awk "/^## TEESimulator v${ver}/{flag=1; next} /^## TEESimulator v/{if(flag) exit} flag" module/changelog.md > /tmp/notes.md
cat /tmp/notes.md
env:
VER: ${{ steps.ver.outputs.version }}
- name: Create release
run: |
gh release delete "$VER" --yes 2>/dev/null || true
gh release create "$VER" \
--title "$VER" \
--latest \
--notes-file /tmp/notes.md \
"zips/TEESimulator-${VER}-Release.zip" \
"zips/TEESimulator-${VER}-Debug.zip"
env:
VER: ${{ steps.ver.outputs.version }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+20 -1
View File
@@ -3,7 +3,8 @@
<p align="center"><b>Full TEE Emulation for Rooted Android</b></p> <p align="center"><b>Full TEE Emulation for Rooted Android</b></p>
<p align="center">Hardware attestation. Software keys. Zero detection.</p> <p align="center">Hardware attestation. Software keys. Zero detection.</p>
<p align="center"> <p align="center">
<img src="https://img.shields.io/badge/version-v4.0-blue?style=for-the-badge" alt="v4.0"> <a href="https://github.com/Enginex0/TEESimulator/actions/workflows/build.yml"><img src="https://github.com/Enginex0/TEESimulator/actions/workflows/build.yml/badge.svg" alt="Build"></a>
<img src="https://img.shields.io/badge/version-v4.2-blue?style=for-the-badge" alt="v4.2">
<img src="https://img.shields.io/badge/Android-10%2B-green?style=for-the-badge&logo=android" alt="Android 10+"> <img src="https://img.shields.io/badge/Android-10%2B-green?style=for-the-badge&logo=android" alt="Android 10+">
<img src="https://img.shields.io/badge/Telegram-community-blue?style=for-the-badge&logo=telegram" alt="Telegram"> <img src="https://img.shields.io/badge/Telegram-community-blue?style=for-the-badge&logo=telegram" alt="Telegram">
</p> </p>
@@ -112,6 +113,24 @@ TEESimulator replaces TrickyStore, TrickyStoreOSS, and their forks. Existing con
--- ---
## 🔨 Building from Source
The CI workflow builds on every push to `main`. You can also build locally or trigger a build from your own fork.
**Prerequisites:** JDK 21, Android SDK/NDK 27, Rust stable with `aarch64-linux-android` target, `cargo-ndk`.
```bash
git clone https://github.com/Enginex0/TEESimulator.git
cd TEESimulator
./gradlew zipRelease zipDebug
```
Output ZIPs land in `out/`. The Gradle build automatically invokes `cargo ndk` to cross-compile `libcertgen.so` before packaging.
To rebuild from a fork, push to `main` or use **Actions → Build → Run workflow**. The workflow installs all toolchains (Java, Rust, cargo-ndk, ccache) and uploads Release + Debug ZIPs as artifacts.
---
## ⚙️ Configuration ## ⚙️ Configuration
All configuration files live at `/data/adb/tricky_store/` and are monitored by `FileObserver` — changes take effect immediately without rebooting. All configuration files live at `/data/adb/tricky_store/` and are monitored by `FileObserver` — changes take effect immediately without rebooting.
+9 -8
View File
@@ -29,7 +29,7 @@ val gitExecutor = objects.newInstance(GitExecutor::class.java)
val gitCommitCount = gitExecutor.execute("git rev-list HEAD --count", rootDir).toInt() val gitCommitCount = gitExecutor.execute("git rev-list HEAD --count", rootDir).toInt()
val gitCommitHash = gitExecutor.execute("git rev-parse --verify --short HEAD", rootDir) val gitCommitHash = gitExecutor.execute("git rev-parse --verify --short HEAD", rootDir)
val verName = "v4.2" val verName = "v4.3"
android { android {
namespace = "org.matrix.TEESimulator" namespace = "org.matrix.TEESimulator"
@@ -121,8 +121,8 @@ androidComponents {
dependsOn("package${capitalized}") dependsOn("package${capitalized}")
} else { } else {
dependsOn("minify${capitalized}WithR8") dependsOn("minify${capitalized}WithR8")
dependsOn("strip${capitalized}DebugSymbols")
} }
dependsOn("strip${capitalized}DebugSymbols")
dependsOn(buildRustCertgen) dependsOn(buildRustCertgen)
if (isDebug) { if (isDebug) {
@@ -140,12 +140,13 @@ androidComponents {
} }
} }
from( val nativeLibsDir = if (isDebug) {
project.layout.buildDirectory.dir( "intermediates/merged_native_libs/${variant.name}/merge${capitalized}NativeLibs/out/lib"
"intermediates/stripped_native_libs/${variant.name}/strip${capitalized}DebugSymbols/out/lib" } else {
) "intermediates/stripped_native_libs/${variant.name}/strip${capitalized}DebugSymbols/out/lib"
) { }
into("lib") // Place them in the 'lib' subfolder of the staging directory. from(project.layout.buildDirectory.dir(nativeLibsDir)) {
into("lib")
include("**/libinject.so", "**/libTEESimulator.so", "**/libsupervisor.so", "**/libcertgen.so") include("**/libinject.so", "**/libTEESimulator.so", "**/libsupervisor.so", "**/libcertgen.so")
} }
+20 -1
View File
@@ -2,11 +2,13 @@
#include <unistd.h> #include <unistd.h>
#include <sys/wait.h> #include <sys/wait.h>
#include <sys/prctl.h> #include <sys/prctl.h>
#include <sys/resource.h>
#include <signal.h> #include <signal.h>
#include <stdlib.h> #include <stdlib.h>
#include <stdio.h> #include <stdio.h>
#include <string.h> #include <string.h>
#include <errno.h> #include <errno.h>
#include <time.h>
static volatile sig_atomic_t should_exit = 0; static volatile sig_atomic_t should_exit = 0;
@@ -27,7 +29,12 @@ int main(int argc, char *argv[]) {
const char *daemon_path = argv[1]; const char *daemon_path = argv[1];
char **daemon_argv = &argv[1]; char **daemon_argv = &argv[1];
int backoff_ms = 500;
while (!should_exit) { while (!should_exit) {
struct timespec child_start;
clock_gettime(CLOCK_MONOTONIC, &child_start);
pid_t pid = fork(); pid_t pid = fork();
if (pid < 0) { if (pid < 0) {
@@ -39,6 +46,7 @@ int main(int argc, char *argv[]) {
if (pid == 0) { if (pid == 0) {
// Child: become the daemon // Child: become the daemon
prctl(PR_SET_PDEATHSIG, SIGKILL); // Die if parent dies prctl(PR_SET_PDEATHSIG, SIGKILL); // Die if parent dies
setpriority(PRIO_PROCESS, 0, 10); // lower CPU priority than foreground
execv(daemon_path, daemon_argv); execv(daemon_path, daemon_argv);
perror("execv failed"); perror("execv failed");
_exit(127); _exit(127);
@@ -50,7 +58,18 @@ int main(int argc, char *argv[]) {
if (should_exit) break; if (should_exit) break;
// Instant restart - no delay // Exponential backoff on rapid crashes, reset if child was stable
struct timespec now;
clock_gettime(CLOCK_MONOTONIC, &now);
long lived_ms = (now.tv_sec - child_start.tv_sec) * 1000 +
(now.tv_nsec - child_start.tv_nsec) / 1000000;
if (lived_ms > 30000) {
backoff_ms = 500;
} else {
usleep(backoff_ms * 1000);
if (backoff_ms < 30000) backoff_ms *= 2;
}
} }
return 0; return 0;
@@ -23,8 +23,6 @@ import org.matrix.TEESimulator.util.AndroidDeviceUtils
object App { object App {
// The delay in milliseconds before retrying to initialize the interceptor. // The delay in milliseconds before retrying to initialize the interceptor.
private const val RETRY_DELAY_MS = 1000L private const val RETRY_DELAY_MS = 1000L
// The sleep duration in milliseconds for the main service loop to keep the process alive.
private const val SERVICE_SLEEP_MS = 1000000L
/** /**
* The main entry point of the TEESimulator application. * The main entry point of the TEESimulator application.
@@ -129,6 +129,7 @@ object GeneratedKeyPersistence {
val file = File(PERSISTENCE_DIR, keyFileName(keyId.uid, keyId.alias)) val file = File(PERSISTENCE_DIR, keyFileName(keyId.uid, keyId.alias))
if (file.exists()) { if (file.exists()) {
if (file.delete()) { if (file.delete()) {
fileLocks.remove(keyFileName(keyId.uid, keyId.alias))
SystemLogger.debug("Deleted persisted key: $keyId") SystemLogger.debug("Deleted persisted key: $keyId")
} else { } else {
SystemLogger.warning("Failed to delete persisted key file: ${file.name}") SystemLogger.warning("Failed to delete persisted key file: ${file.name}")
@@ -158,6 +159,7 @@ object GeneratedKeyPersistence {
if (file.delete()) count++ if (file.delete()) count++
} }
} }
fileLocks.clear()
SystemLogger.info("Deleted $count persisted key files") SystemLogger.info("Deleted $count persisted key files")
}.onFailure { e -> }.onFailure { e ->
SystemLogger.error("Failed to delete all persisted keys", e) SystemLogger.error("Failed to delete all persisted keys", e)
@@ -546,6 +546,10 @@ class KeyMintSecurityLevelInterceptor(
val timestamps = uidKeygenTimestamps.computeIfAbsent(uid) { mutableListOf() } val timestamps = uidKeygenTimestamps.computeIfAbsent(uid) { mutableListOf() }
synchronized(timestamps) { synchronized(timestamps) {
timestamps.removeAll { now - it > BURST_WINDOW_MS } timestamps.removeAll { now - it > BURST_WINDOW_MS }
if (timestamps.isEmpty()) {
uidKeygenTimestamps.remove(uid, timestamps)
uidHardwareKeygenCount.remove(uid)
}
return timestamps.size return timestamps.size
} }
} }
@@ -19,6 +19,7 @@ object SystemLogger {
* @param message The message to log. * @param message The message to log.
*/ */
fun debug(message: String) { fun debug(message: String) {
if (!isDebugBuild) return
Log.d(TAG, message) Log.d(TAG, message)
} }
+10
View File
@@ -1,3 +1,13 @@
## TEESimulator v4.3: Performance & Reliability
- **Debug log gating** — `SystemLogger.debug()` now skipped entirely in release builds, eliminating unnecessary logcat syscalls on every intercepted transaction.
- **Supervisor backoff** — Exponential restart delay (500ms → 30s cap) prevents CPU spin if the daemon crashes repeatedly. Resets automatically once stable.
- **Process priority** — Daemon runs at nice=10, yielding CPU to foreground apps on constrained devices.
- **Map eviction** — Rate limiter and file lock maps now evict stale entries instead of growing unbounded.
- **CI pipeline** — Single-trigger build→release pipeline with proper changelog extraction and correctly sized artifacts.
---
## TEESimulator v4.2: Detection Evasion Hardening ## TEESimulator v4.2: Detection Evasion Hardening
Fixes 6 detection vectors flagged by attestation validator apps. Fixes 6 detection vectors flagged by attestation validator apps.
+3 -3
View File
@@ -1,6 +1,6 @@
{ {
"version": "v4.2", "version": "v4.3",
"versionCode": 98, "versionCode": 107,
"zipUrl": "https://github.com/Enginex0/TEESimulator/releases/download/v4.2/TEESimulator-v4.2-Release.zip", "zipUrl": "https://github.com/Enginex0/TEESimulator/releases/download/v4.3/TEESimulator-v4.3-Release.zip",
"changelog": "https://raw.githubusercontent.com/Enginex0/TEESimulator/main/module/changelog.md" "changelog": "https://raw.githubusercontent.com/Enginex0/TEESimulator/main/module/changelog.md"
} }