Releases: handshake-rs/hns-dane-browser-mobile
Release list
HNS DANE Browser 0.5.7
Android-only compatibility release.
Highlights
- Lowers Android minimum support from Android 14 / API 34 to Android 11 / API 30.
- Aligns the Rust NDK platform with API 30 for both arm64-v8a and x86_64.
- Keeps explicit UTF-8 query encoding while using the API-compatible URLEncoder overload, with regression coverage for Unicode and URL delimiters.
- Shared Rust remains 0.5.6; iOS remains 0.5.5 (build 57).
- Google Play remains 0.5.6 (code 47); no AAB is included in this release.
Artifact verification
- APK:
hns-dane-browser-v0.5.7-release.apk - Size: 51,340,183 bytes
- SHA-256:
566a3db9c6da9e2e9cf2685396b49027518946682a924d9d1f6ae330ef87590b - Signing certificate SHA-256:
D2:2F:F3:25:17:53:11:EB:E6:D6:E9:3D:A3:FD:F5:1D:84:89:22:A1:B8:1A:CB:B3:2F:22:39:CC:F9:4A:51:14 - APK signature verification and 16 KiB ZIP alignment passed.
- Full Android unit tests, debug lint, release lint-vital, supply-chain policy tests, runtime-boundary checks, and version consistency checks passed.
Commit: e5a5440
HNS DANE Browser 0.5.6
HNS DANE Browser 0.5.6 is an Android-only hotfix for the strict, cross-platform Handshake browser.
Highlights
- Restores Android native-runtime startup and HNS synchronization by replacing Rust 1.92's unsupported Android
File::lockpath with equivalent Android bioniclibc::flockcoordination. - Keeps Android HNS Proof Details bound to Rust's retained dual-root namespace decision, preventing valid Handshake results from being relabeled as ICANN DNS.
- Leaves iOS unchanged at 0.5.5 / build 57, which remains in direct App Review with manual release selected and no TestFlight distribution.
Downloads
hns-dane-browser-v0.5.6-release.apk— signed, 16 KiB-aligned Android installer; 51,323,995 bytes; SHA-25646022ec141aa5e700592ab6f81d4d246c71b6a2fb80c2e30139f42fa24effeeb.
Google Play received the signed AAB separately; it is not published as a GitHub download.
Verification and deployment
- Release tag
v0.5.6peels to shipping source417af67efd68198de4871c0a339d1e456b60cb68. - The signed code 47 APK/AAB passed ABI, 16 KiB alignment, ELF hardening, symbol, path-sanitization, R8, notices, upload-signature, APK-signature, and ZIP-alignment gates. The Play AAB SHA-256 is
de668002cbcf803a5704028f06331a57c29998d6f9540dd8ccdeede545cb7b69. - The exact signed APK upgraded and cold-launched successfully on a Pixel 9 running Android 17 / API 37. HNS synchronization reached current status without an error, and device testing confirmed the corrected HNS Proof Details behavior.
- Required CI run 30484282637 passed repository-policy, Rust/supply-chain, Android, Apple, emulator-regression, and Required CI gates on workflow-only descendant
cb930e867b0ddc1f08aaa64e6bf707ff36f0667a, whose application tree is identical to shipping source. - Android Publisher edit
07330408575596336357completed code 47 directly in Google Play production, andgeneratedApks/47returned HTTP 200 with one generated APK set.
Full changelog: v0.5.5...v0.5.6
HNS DANE Browser 0.5.5
HNS DANE Browser 0.5.5 is the coordinated Android and iOS update of the strict, cross-platform Handshake browser.
Highlights
- Preserves authenticated ICANN negative evidence by expanding compressed NS and SOA names before retaining record data.
- Evaluates namespace-plan freshness after DNS/TLSA resolution so newly gathered evidence is not rejected against an older clock sample.
- Hardens the iOS shell’s factual readiness and bounded navigation recovery, keeps semantic Proof Details capture stable, and revalidates a cached main frame through the Rust proxy before presenting new trust status.
- Aligns the release identities at shared Rust 0.5.5, Android 0.5.5 (code 46), and iOS 0.5.5 (build 57).
Downloads
hns-dane-browser-v0.5.5-release.apk— signed, 16 KiB-aligned Android installer; 51,326,667 bytes; SHA-256b36a4346ffcba14c081500ef3dc7c5012cabd30f42cdaa80a354eefb5da210ba.hns-dane-browser-v0.5.5-ios-app-store.ipa— App Store-signed iPhone distribution package; 47,930,601 bytes; SHA-256efea01f912035d0e2cde880a59cbe9e5b2e3f546e781fa5d9606942629225345.
The IPA is signed for App Store distribution and is not a general-purpose sideload package. Google Play received the signed AAB separately; it is not published as a GitHub download.
Verification and deployment
- Release tag
v0.5.5peels to shipping sourced926561091634cd69fc9b7e79a4b76003fa4ee47. The Android code 46 artifacts were built at version-bump sourced24f85158854abb8be4a7bb9e914aebe5e7e4679; the later source changes are Apple-specific. - Full cross-platform CI run 30448341156 passed repository policy, Rust/supply-chain, Android, Apple, and Required CI. Exact-head Apple CI run 30454904736 passed after the final iOS corrections.
- Live Release screenshot run 30454926117 produced four fixture-free, exact-source iPhone images with DANE-verified HNS, same-navigation Proof Details, and authenticated ICANN WebPKI provenance.
- The signed Android APK/AAB passed signature, 16 KiB alignment, native hardening, symbol, path-sanitization, R8 mapping, and notices gates. Android Publisher edit
17438779769069438085completed code 46 directly in Google Play production, andgeneratedApks/46returned HTTP 200. - Protected iOS upload run 30456522039 passed the complete Apple gate, signed build 57, uploaded it to App Store Connect, and retained the exact IPA published here. App Store Connect reports the build
VALIDand the direct App Review submissionWAITING_FOR_REVIEW, with manual release selected. No TestFlight distribution was created.
Signed physical-device matrices remain separate Android/iPhone qualification work; they do not change the completed package, store-upload, or direct-review evidence above.
Full changelog: v0.5.4...v0.5.5
HNS DANE Browser 0.5.4
HNS DANE Browser 0.5.4 is the coordinated Android and iOS release of the strict, cross-platform Handshake browser.
Highlights
- Adds automatic ICANN DANE across Android and iOS while retaining fail-closed DNSSEC/TLSA policy.
- Adds separately configured recovery DoH and optional requester-only P2P relay recovery, both inactive unless explicitly enabled.
- Makes live header synchronization atomic and generation-bound so incomplete or superseded state cannot be published to browser requests.
- Adds a hardened, click-only recovery page for confirmed port 53 interception.
- Aligns the release identities at shared Rust 0.5.4, Android 0.5.4 (build 44), and iOS 0.5.4 (build 48).
Downloads
hns-dane-browser-v0.5.4-release.apk— signed, zip-aligned Android installer. SHA-256:0a1078bf259fcc0209a049c3c69f7a9f9dc23083282f8e8af75b56c2923f9709hns-dane-browser-v0.5.4-ios-app-store.ipa— App Store-signed iOS distribution package. SHA-256:c930df041ea9897c0e7b88f59b2ce1288ff202df4fefa7c40a43576683a7f640
The IPA is signed for App Store distribution and is not a general-purpose sideload package. Google Play receives the signed AAB separately; it is not published as a GitHub download.
Verification
- Candidate commit:
8ffc296e4d034ccc07110c34cdf606658416edaf - Required cross-platform CI passed for the candidate.
- The iOS package identity was verified as
com.denuoweb.hnsdane.iosversion 0.5.4 build 48 before publication.
Full changelog: v0.5.0...v0.5.4
HNS DANE Browser 0.5.0
Android 0.5.0 adds a proof-gated Handshake P2P DNS relay while keeping all authenticity decisions local to the browser.
Changes:
- Enables P2P DNS relay discovery by default for new Android installs.
- Keeps the independent legacy HNS DoH fallback enabled, so resolution continues while peers upgrade.
- Adds manual relay peers with live capability verification and IP-literal endpoint validation.
- Adds local HNS proof, DNSSEC, TLSA, and DANE validation for relayed answers.
- Adds a separate non-overlapping relay-test build and four-node regtest acceptance tooling.
- Updates Android, Rust, and Apple versions to 0.5.0 (Android version code 40).
Verification:
- Complete local Rust, supply-chain, cargo-deny, fuzz, iOS C ABI, and exporter gate.
- 192 Android unit tests; debug and release lint with zero errors.
- Upload-signed APK/AAB signer, structure, native-hardening, symbols, and 16 KiB alignment gates.
- Isolated relay topology, bounded load tier, and full four-
hsdregtest tier with a registered name, matching Urkel state, DNSSEC, DANE, HTTPS success, and relay failover. - Focused
hsdresponder suite: 47 passing; ESLint clean.
GitHub Actions is disabled for this repository, so no hosted CI result is claimed. Exact-build physical-device acceptance remains pending because the attached Pixel disconnected before installation.
APK SHA-256:
bff5ba468b0c5ad2d134603127f089ad6fdc9e9b5ceab921825e570cfefd60fb
Google Play uses the separately verified Android App Bundle; it is intentionally not attached to this GitHub release. The non-overlapping relay-test APK also remains a local testing artifact.
HNS DANE Browser 0.4.1
Android 0.4.1 is a maintenance release for the renamed cross-platform repository.
Changes:
- Updates the in-app source-code link to https://github.com/Denuo-Web/hns-dane-browser.
- Keeps the unchanged shared Rust engine and Apple shell at 0.4.0 while versioning the Android app independently as 0.4.1 (version code 39).
- Adds affected-platform CI routing: shared Rust changes validate Rust, Android, and Apple; platform-only changes skip the opposing application shell.
Verification:
- Complete local Rust and supply-chain gate.
- 187 Android unit tests; debug and release lint with zero errors.
- Upload-signed APK and AAB structural, native-hardening, signer, and 16 KiB alignment gates.
- Successful Pixel 9 upgrade from Android app 0.4.0 / code 38 and cold launch as 0.4.1 / code 39.
- Hosted Rust, Android, and Apple gates: https://github.com/Denuo-Web/hns-dane-browser/actions/runs/29477163745
APK SHA-256:
a5a9d50d5b19302af488f7f5e6c68281364070edc7edcb14e16dbb1e1a5d61a2
Google Play uses the separately verified Android App Bundle; it is intentionally not attached to this GitHub release.
HNS DANE Browser 0.4.0
Shared cross-platform runtime
- Moves security-sensitive HNS resolution, DNSSEC/DANE, proxy parsing, browser isolation, and local TLS termination into the shared Rust runtime.
- Keeps Android UI and WebView integration native while preserving the deployed Android behavior.
- Adds the iOS 17+ UIKit/WKWebView foundation using the same Rust engine, Apple C ABI, and XCFramework instead of reimplementing protocol logic in Swift.
- Adds authenticated fail-closed loopback proxying, bounded runtime handles and buffers, deterministic Apple builds, and platform-boundary checks.
Android release
- Version:
0.4.0(versionCode 38) - Minimum Android version: Android 14 / API 34
- The signed APK upgraded a Pixel 9 from
0.3.16and cold-launched successfully.
Validation
- Rust, fuzz, dependency policy, and supply-chain checks passed.
- Cold-cache Android build, unit tests, lint, and release-bundle validation passed.
- Xcode 26.5 ABI, XCFramework, simulator tests, and unsigned arm64 device link passed.
- Release PR: #22
- Hosted CI: https://github.com/Denuo-Web/hns-dane-browser-android/actions/runs/29473737565
Signed APK SHA-256: d210b115b4c5a6ea49a54b51e80d6895770ecdbfa5c12050ae60c83f475c2d34
HNS DANE Browser 0.3.16
HNS-name authoritative DoH
- Adds generic proof-pinned RFC 8484 authoritative DoH for single-label HNS endpoints such as
https://denuoweb:8443/dns-query, using verified HNS GLUE and proof TLSA pins without requiring an ICANN domain or WebPKI. - Uses the availability order owner ADoH, authoritative UDP/TCP 53, then the configured third-party HNS DoH resolver in Compatibility mode; Strict mode omits only the last fallback.
- Shows the successful transport explicitly:
DANE via ADoH,DANE via DNS53,DANE via 3rd DoH,Stateless DANE, orDANE via ICANN DoH, with equivalent HTTP labels. - Hardens resolver provenance and trace accuracy and prevents the internal security-path header from reaching Chromium or page content, including WebSocket upgrades.
Signed APK SHA-256: bcc4c5cc892ef16dbe565013c58cc104384c61bb001b99f8aec9c4da3a501ae1.
HNS DANE Browser 0.3.15
HNS DANE Browser 0.3.15 fixes proof-bootstrapped authoritative DNS-over-HTTPS interoperability by adding exact transport-owned Content-Length metadata to every non-empty HTTP/2 and HTTP/3 request body. Caller-supplied lengths are discarded and recomputed from the actual body; this is a general transport fix with no site-specific exception.
Validation:
- Full formatting, warning-denied Clippy, supply-chain, version, notice, dependency-policy, fuzz, exporter, and 401 Rust test gates passed
- 193 Android unit tests passed; debug and release lint completed with zero errors
- Clean signed APK and Play App Bundle built with the pinned r28c toolchain
- APK signature, expected signer, and 16 KiB ZIP alignment verified
- Signed Play App Bundle structure, native hardening, debug symbols, and signer verified
- Installed the exact release APK on a Pixel 9; denuoweb used only its HNS-proof-bootstrapped authoritative DoH endpoint, skipped UDP/TCP port 53 and compatibility fallback, validated DNSSEC, and verified DANE
HNS DANE Browser 0.3.14
HNS DANE Browser 0.3.14 changes the default compatibility DNS-over-HTTPS resolver from the failing global HNSDoH pool to the working Zorro node. Resolver selection remains user-configurable, and compatibility answers continue to be validated locally against the HNS-proven DNSSEC chain.
Validation:
- Full Rust, fuzz, exporter, dependency-policy, supply-chain, version, and notice checks passed
- 193 Android unit tests passed
- Debug and release lint completed with zero errors
- Clean signed APK and Play App Bundle built with the pinned r28c toolchain
- APK signature and 16 KiB ZIP alignment verified
- Signed Play App Bundle structure, native hardening, debug symbols, and signer verified
- Installed release APK on a Pixel 9; aboutlife loaded with DNSSEC secure and DANE verified through Zorro DoH