Skip to content

Releases: ctrl-mietze/Veyra

Veyra Root v2.0.0 — Public Release

Choose a tag to compare

@github-actions github-actions released this 09 Oct 15:04

Veyra Root v2.0.0 — Public Release

Veyra Root 2.0 is the second public release of Veyra Root and the first public release based on the current Builder Workingbench, DF+, Magic Builder, Market/API and mandatory-update generation.

This release keeps the established Android package identity and Veyra signing certificate so it remains update-compatible with prior official Veyra Root builds that use the same signer.

Release identity

  • Package: ctrl.mietze.veyraroot
  • Version: 2.0.0
  • versionCode: 200000000
  • Signer SHA-256: f1d8f55217d1149f88db9e1642735363d0198c33c8da8d77547987cedf08c582
  • APK SHA-256: edc2af1e93861d60e94e99fff7aa776ba119280d63fa8bd5473e2ed84b55bb7c

The release asset is the already prepared and signed Public 2.0 APK. It is not a newly generated CI replacement artifact.

Mandatory public update channel

Veyra Root 2.0 introduces the public release channel used by the hardened build.

When the published GitHub channel reports a versionCode higher than the installed public build, the Public Release treats that update as mandatory.

The update path verifies:

  • the Veyra package name,
  • the published versionCode,
  • the downloaded APK SHA-256 when supplied,
  • the Veyra signing certificate.

The stable public baseline for this release is 200000000. Future public releases must use a higher versionCode.

ReleaseGuard / anti-tamper hardening

Public 2.0 contains the dedicated Veyra ReleaseGuard layer rather than relying only on Android's normal package-signature checks.

The current protection set includes:

  • official signing-certificate pinning,
  • package and build identity checks,
  • non-debuggable / non-test-only verification,
  • split/repack detection,
  • trusted APK source/path checks,
  • SHA-256 integrity checks for 22 critical APK entries and native libraries,
  • debugger detection,
  • TracerPid / tracing checks,
  • Frida marker detection,
  • Xposed / LSPosed marker detection,
  • Substrate marker detection,
  • LD_PRELOAD checks,
  • suspicious process-map checks,
  • suspicious thread checks,
  • suspicious file-descriptor checks,
  • repeated runtime guard/watchdog verification.

The public manifest also disables backups, disables cleartext traffic and does not expose shell profiling.

No client-side Android protection is mathematically unbreakable. These layers are intended to make casual resigning, repacking, asset replacement, binary patching and runtime instrumentation substantially harder while preserving legitimate root use.

Public packaging pipeline

The final Public 2.0 packaging path uses the proven lighter Android packaging route while retaining public-release security semantics.

For the distributed build:

  • Android debuggable state is disabled,
  • JNI debugging is disabled,
  • PUBLIC_RELEASE=true,
  • RELEASE_HARDENED=true,
  • the established Veyra signer is used,
  • ReleaseGuard remains active,
  • the release identity is 2.0.0 / 200000000.

In other words, the lightweight Gradle path is only a packaging route; the shipped APK is not a debuggable public build.

Version information and Veyra links

Veyra Root 2.0 exposes the public release identity directly in the application:

  • System Management → Version Info,
  • About → Version Info,
  • Veyra Root 2.0 / Public Release labeling,
  • Explore Veyra opens the official Veyra website instead of the older disabled placeholder.

Builder Workingbench

The current Builder Workingbench generation is included.

It consolidates builder workflows into a dedicated area while keeping per-builder configuration with the corresponding builder.

Current functionality includes:

  • Veyra Builder sessions and resume,
  • OTA range extraction,
  • local image/hash comparison,
  • strategy matrix,
  • evidence grouping and conflict tracking,
  • risk modes,
  • candidate/session/report export,
  • report import,
  • Termux helper generation,
  • dependency checking and automatic package preparation,
  • Android Download output handling with fallback paths,
  • ADB and Shizuku/rish-aware helper paths.

DF Compatible / Veyra DF+

The DF route now uses explicit kernel/KMI evidence instead of blindly following the userspace Android version.

Included work covers:

  • DF Compatible,
  • Veyra DF+,
  • Samsung / DEFEX-aware routing,
  • OnePlus / Oppo / realme profiles,
  • generic GKI routing,
  • installed manager/ksud awareness,
  • KernelSU-Next package awareness,
  • kernel-release-first KMI selection,
  • recovery/runtime controls,
  • root-on-boot and soft-reboot options where supported,
  • module-disable controls,
  • image-partition protection controls.

Legacy 4.19 targets such as Kona remain evidence-driven and are not falsely promoted into a runnable modern GKI route.

Magic Builder and source intelligence

Magic Builder retains Veyra's evidence-first model:

  • OTA/catalog-assisted source discovery,
  • boot/kernel evidence extraction,
  • device/kernel-family matching,
  • local and remote research sources,
  • analysis-only outcomes when a runnable baseline is not proven.

Veyra does not invent kernel addresses, payload constants or physical-load values merely because a nearby device or kernel family looks similar.

Market / API / remote-data foundation

The current generation also contains the newer Veyra Market, API and remote-data foundation used by the application:

  • public update metadata,
  • market manifest/schema,
  • diagnostics-pack foundation,
  • Magic OTA catalog,
  • HTTPS-only update transport,
  • package/version/hash/signer validation for downloaded updates.

Compatibility

Veyra Root 2.0 keeps:

  • package ctrl.mietze.veyraroot,
  • the established Veyra signing certificate,
  • Android minimum API 26 at application level.

Individual root routes can have stricter device, kernel and firmware requirements.

Validation baseline

The Public-v2 source state passed the complete unit-test suite:

796 / 796 tests passed

  • 0 failures
  • 0 errors
  • 0 skipped

A passing application test suite is not a claim that every kernel-specific root route is runnable on every device. Exact-device evidence remains part of Veyra's design.

Upgrade from v1.0.0

Because the official public builds use the same package and signing identity and v2.0.0 has the higher versionCode 200000000, Android can install v2.0.0 as an update over compatible earlier official Veyra Root builds.

Release files

  • VeyraRoot-2.0.0.apk — official signed APK
  • VeyraRoot-2.0.0.sha256 — APK SHA-256
  • VeyraRoot-2.0.0-source.tar.gz — sanitized Public-v2 source snapshot used for this release
  • VeyraRoot-2.0.0-source.tar.gz.sha256 — source archive SHA-256

The Git tag is created only after the Public-v2 source is synchronized to the repository, so GitHub's generated source archives correspond to the v2 source state rather than the historical v1 tree.

Veyra Root v1.0.0 — First Public Release

Choose a tag to compare

@github-actions github-actions released this 06 Oct 21:07

Veyra Root v1.0.0 — First Public Release

Veyra Root v1.0.0 is the first public release of the Veyra Root project.

Veyra is an Android root and kernel-research application built around exact-device evidence rather than blind cross-device assumptions. The project combines the original compatible Root My Galaxy route with Veyra-owned device analysis, CVeyra privilege management, KernelSU integration, payload/source management, recovery tools and an expanded Magic Builder.

Important: support detection is not the same as a guaranteed runnable exploit. Veyra deliberately keeps analysis-only paths separate from verified runnable baselines. It does not invent kernel addresses, payload constants or physical-load values when the required evidence is missing.

Highlights

Root detection and provider awareness

The Home status no longer treats the presence of a manager app as proof that Veyra has root.

Veyra verifies whether its own process can actually execute as UID 0 and distinguishes the active route:

  • Veyra temporary/jailbreak root
  • external temporary-root providers
  • KernelSU root
  • Magisk-style boot root
  • other real root providers

External providers can be routed into the provider-migration flow instead of being mislabeled as a Veyra session.

Standard and Magic root workflows

Veyra keeps the proven Standard route as a compatibility anchor and adds the much larger Magic Builder research workflow.

Magic Builder includes:

  • exact boot-image capture
  • ARM64 Image-header and ELF architecture detection
  • kernel banner detection independent from kallsyms decoding
  • exact kernel-family gating
  • legacy 4.x analysis
  • 5.x legacy analysis
  • 6.x mainline/GKI analysis
  • 7.x analysis routing with runnable output blocked until an exact baseline exists
  • source-assisted analysis for difficult vendor kernels
  • support-bundle export
  • generated target header / offsets analysis
  • no automatic guessing of physical kernel addresses

Magic Builder deep diagnostics

v1.0.0 includes dedicated diagnostics for difficult ports:

  • Source Match Matrix — ranks research sources against the current OEM/kernel family.
  • Kernel Gate — shows exact baseline/family decisions.
  • KMI Matrix — checks the local DF/KMI inventory against the current kernel.
  • Live Symbols — reads selected live kernel symbols when the privileged backend permits it.
  • Boot Evidence Report — parses the captured boot image and exports exact architecture/version evidence.

vivo / iQOO and Kona research

The Magic Builder contains a dedicated vivo legacy intelligence path.

For the vivo X60/Kona family it can use source evidence such as:

  • Qualcomm Kona / SM8250
  • ARM64
  • Linux 4.19.152 source family
  • -perf local version evidence
  • kallsyms-related source configuration
  • exact source matching without converting research evidence into an unverified runnable baseline

When a generic kallsyms decode is not sufficient, Veyra can preserve the captured device evidence as analysis artifacts rather than terminating with a generic architecture error.

Research sources integrated into Payload Sources

The following projects are represented as built-in Local / Research sources where they do not expose Veyra's runnable targets-v3.json feed format:

  • p2p3p/GhostLock-for-OnePlus
  • NanoTurtle1145/root-my-s24
  • yakidango-official/GhostLock-H80GT
  • JoinChang/ghostlock-oneplus
  • sarabpal-dev/IonStack-S22U
  • zenyxx-xd/RootMyVivo and RootMyVivo-Payloads
  • rushiranpise/Shizuku-Next

These entries are deliberately research-only until an exact Veyra-compatible runnable manifest exists. Veyra will not fabricate payload binaries or offsets simply because a repository targets a similar kernel.

CVeyra Permission Provider 2.0.0

CVeyra is no longer presented as a permission-preview concept.

The 2.0.0 flow contains a real activation state machine:

  1. provider information must be read,
  2. VeyraKSU 2.0.0 must be installed,
  3. KernelSU soft reboot is requested where required,
  4. the live bridge is verified,
  5. existing direct KernelSU grants are backed up,
  6. CVeyra Access is accepted and the root broker becomes the enforced privileged backend.

After activation, the old "use CVeyra / start as root / promote after boot" switches are no longer needed. CVeyra Access is treated as an always-on root-broker mode.

Permission Management

The permission manager has separate modes:

  • Offline — keeps rules but manages no applications.
  • Self — the user selects managed applications.
  • Auto — reserved for the future policy engine and intentionally returns to the prior mode for now.

The manager displays applications with direct KernelSU Superuser grants separately so those grants are not silently rewritten.

Provider changes are persisted only after the device-side action succeeds.

Current enforcement includes:

  • CVeyra broker allow-list state
  • ADB / WRITE_SECURE_SETTINGS grant handling when the target app actually requests it
  • Shizuku API permission handling when the target app requests it
  • real KernelSU-grant detection for Superuser state
  • real Android UID 1000 state detection
  • real Android Device Owner state detection

Unsupported state transitions are refused rather than shown as successful fake grants.

VeyraKSU 2.0.0

The bundled VeyraKSU compatibility module is now version 2.0.0.

It provides:

  • CVeyra permission-bridge state
  • access activation marker
  • migration-compatible state files
  • boot/service/late-load status
  • persistent firewall re-application
  • retained provider-migration compatibility

CVeyra App Module Loader

CVeyra Management includes system-state modules for:

  • Hide accessibility
  • Hide developer options
  • Hide USB debugging
  • Hide Private DNS

These modules operate on the real Android setting while enabled and remember the exact previous value for restoration. They are not per-app hook spoofers.

CVeyra Firewall

The CVeyra firewall uses more than one layer:

  • Android package networking control where supported
  • persistent root-owned IPv4 UID rules
  • persistent root-owned IPv6 UID rules
  • VeyraKSU re-application after module/service startup

Only Veyra-managed package state is persisted.

ADB Manager

ADB start methods are grouped into the Veyra ADB Manager:

  • Start via Wireless Debugging
  • Start via USB debugging
  • Start via Computer

The implementation retains Veyra's own authenticated Wireless ADB/session handling rather than cloning another application's UI.

Navigation

After CVeyra Access 2.0.0 becomes active, the Veyra flower is added as the center item in the Home / History / Logs / Settings navigation island and opens CVeyra Management directly.

System Update control

The System Manager can disable automatic OTA behavior through CVeyra and selected installed OEM updater components.

Veyra remembers only updater packages that Veyra itself disabled, so restoring updates does not blindly enable packages the user had disabled beforehand.

UI and performance

v1.0.0 keeps the native Android/Veyra visual language:

  • dark/OLED-first themes
  • native settings rows
  • restrained purple accent
  • persistent page/home state
  • cached Home readiness state
  • background refresh instead of visibly resetting status cards during tab changes
  • optional 120 Hz display-mode request where the device provides a matching mode

Release hardening

The official release APK contains a separate hardened runtime layer that is not enabled in normal development builds.

Protections include:

  • official signing-certificate SHA-256 pinning
  • package identity verification
  • non-debuggable release manifest
  • backup disabled
  • shell profiling disabled
  • critical APK entry SHA-256 verification
  • debugger detection
  • TracerPid / ptrace detection
  • process-local Frida/Xposed/LSPosed/Substrate marker detection
  • suspicious injected thread detection
  • suspicious process file-descriptor detection
  • repeated runtime integrity watchdog
  • R8 obfuscation/minification focused on Veyra-owned code
  • explicit preservation of the legacy JNI ABI required by libs25u_native.so

No client-side Android protection is mathematically unbreakable. These layers are intended to make casual repacking, resigning and runtime patching substantially harder while still allowing normal KernelSU/Magisk/root use.

Security model

Veyra is intentionally conservative around kernel evidence.

A repository name, matching kernel family or installed manager is not treated as sufficient proof for a runnable kernel payload.

Where exact data is missing, Veyra prefers:

  • analysis-only output,
  • support-bundle collection,
  • live-device verification,
  • source cross-checks,
  • explicit "not runnable yet" status,

instead of substituting nearby offsets.

Compatibility notes

The application package remains:

ctrl.mietze.veyraroot

The official v1.0.0 APK is signed with the established Veyra certificate so it can update over prior Veyra builds using the same signer.

Android minimum API remains API 26, while individual root routes have their own stricter kernel/device requirements.

Credits and research

Veyra's research layer references public work from multiple Android/kernel projects. See docs/THIRD_PARTY_RESEARCH.md for the distinction between research evidence, compatibility inspiration and runnable Veyra payload sources.

First public release

This is the first public Veyra Root release. The project is intentionally shipping the architecture, diagnostics and safety boundaries together rather than publishing a list of kernels that Veyra cannot actually prove it can handle.

Future releases can expand exact device baselines and the automatic CVeyra policy engine without weakening the evidence requirements introduced here.

Veyra Marked + registry foundation

v1.0.0 also introduces the backend structure for Veyra Marked + without changing the existing visible screen.

The repository now c...

Read more