HNS DANE Browser 0.5.0
Android 0.5.0 adds a proof-gated Handshake P2P DNS relay while keeping all authenticity decisions local to the browser.
Changes:
- Enables P2P DNS relay discovery by default for new Android installs.
- Keeps the independent legacy HNS DoH fallback enabled, so resolution continues while peers upgrade.
- Adds manual relay peers with live capability verification and IP-literal endpoint validation.
- Adds local HNS proof, DNSSEC, TLSA, and DANE validation for relayed answers.
- Adds a separate non-overlapping relay-test build and four-node regtest acceptance tooling.
- Updates Android, Rust, and Apple versions to 0.5.0 (Android version code 40).
Verification:
- Complete local Rust, supply-chain, cargo-deny, fuzz, iOS C ABI, and exporter gate.
- 192 Android unit tests; debug and release lint with zero errors.
- Upload-signed APK/AAB signer, structure, native-hardening, symbols, and 16 KiB alignment gates.
- Isolated relay topology, bounded load tier, and full four-
hsdregtest tier with a registered name, matching Urkel state, DNSSEC, DANE, HTTPS success, and relay failover. - Focused
hsdresponder suite: 47 passing; ESLint clean.
GitHub Actions is disabled for this repository, so no hosted CI result is claimed. Exact-build physical-device acceptance remains pending because the attached Pixel disconnected before installation.
APK SHA-256:
bff5ba468b0c5ad2d134603127f089ad6fdc9e9b5ceab921825e570cfefd60fb
Google Play uses the separately verified Android App Bundle; it is intentionally not attached to this GitHub release. The non-overlapping relay-test APK also remains a local testing artifact.