Skip to content

Releases: ShalomMaman/android-lockdown-dpc

Device Guard Pilot 0.5.4

Pre-release

Choose a tag to compare

@github-actions github-actions released this 16 Aug 14:54
291e7dc

Device Guard Pilot 0.5.4 adds an explicit, administrator-controlled Google Play compatibility mode for applications that require the Play Store package. Strict store blocking remains the default. When compatibility is enabled, Device Guard keeps only Google Play available and requires a verified installation lock; any failed read-back hides the Store and prevents protection from reporting success.

This release also improves delayed HTTP/HTTPS handler verification, maintenance restoration safety, release automation, and public project documentation. The offline signed update drill, Android CI, lint, JVM tests, and CodeQL pass.

Security and deployment boundary

This is a public pilot prerelease. Google Play compatibility, kiosk containment, provisioning, recovery, and signed self-update still require recorded physical-device evidence for each supported firmware family. The Play Store package may remain visible on an ordinary launcher while compatibility mode is enabled; installation is what Device Guard blocks and verifies.

Traceability

Device Guard Pilot 0.5.3

Pre-release

Choose a tag to compare

@github-actions github-actions released this 16 Aug 10:13
ebc6e70

What's Changed

Full Changelog: pilot-v0.5.2...pilot-v0.5.3

Device Guard Pilot 0.5.2

Pre-release

Choose a tag to compare

@ShalomMaman ShalomMaman released this 16 Aug 00:15
7a0c45a

Device Guard Pilot 0.5.2 advances the public managed-device pilot with verified maintenance restoration, system controls, kiosk profiles, and a compact-device administration experience.

Highlights

  • Verified timed access to application stores: a maintenance window makes approved stores visible, keeps unrelated escape surfaces blocked, and restores the hidden state only after Android confirms it.
  • Complete system-application inventory with explicit safety tiers, administrator risk acceptance for unknown OEM components, and support for both blocklist and strict allowlist policies.
  • Optional single-application and single-site kiosk profiles with fail-closed navigation and exit verification.
  • Verified Android system-policy controls, including developer options and ADB, USB transfer, unknown-source installation, accounts, VPN, network settings, Safe Boot, factory reset, and application-control settings.
  • Compact-screen inventory UX: the explanation, search, and filters scroll away with the list, while the smaller save bar preserves the selected-system count and labelled action.
  • Signed self-update support for existing pilot devices. This artifact is build 12 so that devices running the unpublished 0.5.2 build 11 can update automatically.
  • Complete English and Hebrew localization with LTR/RTL support and automated locale-parity checks.

Verification

  • The explicit pilotChannelRelease gate passed: unit tests, Android lint, release build, APK identity, version, signer, embedded manifest URL, and P-256 metadata-key fingerprint.
  • The offline signed-update drill passed from both published Pilot 0.5.1 and the unpublished hardware Pilot 0.5.2 build 11 to this build.
  • GitHub CI and CodeQL status are recorded on the linked pull request.

Pilot warning

This remains a public pilot prerelease, not a production customer artifact. The pilot identity and Android debug-compatible signing certificate are retained only for in-place compatibility with already enrolled test devices. Production deployments require the separate production identity, externally managed APK signing key, completed hardware matrix, and documented recovery exercise.

סיכום בעברית

גרסת הפיילוט 0.5.2 משפרת את פתיחת החנות לזמן מוגבל ואת השחזור המאומת שלה, מוסיפה ניהול רכיבי מערכת ומצבי קיוסק, ומשפרת את הגלילה במסכים קטנים. build 12 מאפשר גם למכשיר שכבר קיבל build פנימי 11 להתעדכן אוטומטית. זו עדיין גרסת פיילוט ציבורית ולא חבילת Production ללקוחות.

Device Guard Pilot 0.5.1

Pre-release

Choose a tag to compare

@ShalomMaman ShalomMaman released this 12 Aug 12:18
165c4b0

Pilot 0.5.1 restores the signed self-update channel for the existing managed-device pilot.

Highlights:

  • explicit, fail-closed pilot update-channel build
  • release artifact verification for package, version, signer, compiled URL, and P-256 metadata key
  • exact signed-manifest-to-APK binding before publication
  • ordinary builds remain updater-disabled by construction
  • production identity and update configuration remain separate

Upgrade note: devices already on Pilot 0.5.0 require this one final ADB update because 0.5.0 was published without its update-channel constants. Future pilot updates can then use the authenticated in-app updater.

This remains a public pilot pre-release, not a production deployment artifact. Kiosk mode is not enabled automatically.

Production roadmap

Device Guard Pilot 0.5.0

Pre-release

Choose a tag to compare

@ShalomMaman ShalomMaman released this 12 Aug 09:54
1a1b6e7

Superseded by Pilot 0.5.1. Pilot 0.5.0 was published without its compiled update-channel constants and cannot discover later releases. Do not install it on new devices.

Device Guard 0.5 introduces dedicated-device kiosk profiles on top of the existing verified Device Owner application-policy foundation.

Highlights

  • Managed filtering with an administrator-controlled allowlist.
  • Single-app kiosk for dedicated Android displays.
  • Single-site HTTPS kiosk with strict same-origin WebView navigation.
  • Secure custom HOME host and Lock Task orchestration.
  • Complete English and Hebrew localization.
  • Runtime System / English / Hebrew language selection with LTR and RTL support.
  • Monotonic, reboot-aware PIN lockout and short administrator sessions.
  • Fail-closed policy reconciliation for activation, failure states, and kiosk exit.
  • Bidirectional-control sanitization for untrusted application labels.
  • Generic pre-authentication status that does not expose policy or package details.
  • Expanded operator, recovery, provisioning, and security documentation.

Security hardening

This release closes the reviewed kiosk escape and false-success boundaries for cross-origin POST/redirect/script/history navigation, ACTIVE versus FAULT containment, protected package targeting, administrator-selected system-package precedence, and unverified kiosk exit.

The final changes passed an independent adversarial review with no surviving P0-P3 finding in the reviewed boundaries.

Upgrade compatibility

This pilot keeps package com.example.lockdowndpc and the existing pilot signer, so it can update Pilot 0.4.1 in place on an already provisioned test device.

APK SHA-256:

8e5d71b329f9c9d95fc5bb4f5d4e9abb100b40fb65d53bf32aef66f66421f026

Pilot warning

Kiosk behavior has not yet been validated on a physical Device Owner-provisioned device or across OEM builds. Do not enable kiosk remotely on an unreachable device until the administrator PIN and recovery code are stored safely and the local recovery gesture has been verified on that exact device. This release is not represented as production-ready.

See the repository documentation for kiosk setup, limitations, and production-release requirements.

Device Guard Pilot 0.4.1

Pre-release

Choose a tag to compare

@ShalomMaman ShalomMaman released this 11 Aug 22:03
2fd58a6

Device Guard Pilot 0.4.1

This prerelease bootstraps the signed self-update channel for the existing com.example.lockdowndpc test device.

Highlights

  • verified policy state with fail-closed reconciliation
  • modern Hebrew-first Jetpack Compose administration console
  • persistent allowlist inventory, including currently hidden packages
  • WebView compatibility for approved apps such as Tefilary
  • signed ECDSA update metadata and APK hash, identity, version, and signer verification
  • silent Device Owner installation after all verification gates pass
  • daily background checks and an authorized manual update action

Important

This APK is a pilot prerelease, retained for compatibility with an already provisioned test device. It uses the pilot application ID and signer. Do not provision customer or production devices from this artifact. Build production deployments with the separate identity and external signing process documented in docs/production-release.md.

The administrator PIN, recovery code, device configuration, APK-signing key, and update metadata private key are not published.