Skip to content

Device Guard Pilot 0.5.0

Pre-release
Pre-release

Choose a tag to compare

@ShalomMaman ShalomMaman released this 12 Aug 09:54
1a1b6e7

Superseded by Pilot 0.5.1. Pilot 0.5.0 was published without its compiled update-channel constants and cannot discover later releases. Do not install it on new devices.

Device Guard 0.5 introduces dedicated-device kiosk profiles on top of the existing verified Device Owner application-policy foundation.

Highlights

  • Managed filtering with an administrator-controlled allowlist.
  • Single-app kiosk for dedicated Android displays.
  • Single-site HTTPS kiosk with strict same-origin WebView navigation.
  • Secure custom HOME host and Lock Task orchestration.
  • Complete English and Hebrew localization.
  • Runtime System / English / Hebrew language selection with LTR and RTL support.
  • Monotonic, reboot-aware PIN lockout and short administrator sessions.
  • Fail-closed policy reconciliation for activation, failure states, and kiosk exit.
  • Bidirectional-control sanitization for untrusted application labels.
  • Generic pre-authentication status that does not expose policy or package details.
  • Expanded operator, recovery, provisioning, and security documentation.

Security hardening

This release closes the reviewed kiosk escape and false-success boundaries for cross-origin POST/redirect/script/history navigation, ACTIVE versus FAULT containment, protected package targeting, administrator-selected system-package precedence, and unverified kiosk exit.

The final changes passed an independent adversarial review with no surviving P0-P3 finding in the reviewed boundaries.

Upgrade compatibility

This pilot keeps package com.example.lockdowndpc and the existing pilot signer, so it can update Pilot 0.4.1 in place on an already provisioned test device.

APK SHA-256:

8e5d71b329f9c9d95fc5bb4f5d4e9abb100b40fb65d53bf32aef66f66421f026

Pilot warning

Kiosk behavior has not yet been validated on a physical Device Owner-provisioned device or across OEM builds. Do not enable kiosk remotely on an unreachable device until the administrator PIN and recovery code are stored safely and the local recovery gesture has been verified on that exact device. This release is not represented as production-ready.

See the repository documentation for kiosk setup, limitations, and production-release requirements.