Skip to content

Releases: itswill00/hypercore

HyperCore v6.11.0 — Thermal Guard Corrections

Choose a tag to compare

@itswill00 itswill00 released this 30 Sep 01:10

A full audit of the daemon, the WebUI and the packaging turned up that the 3-tier thermal guard was not enforcing two of its three tiers. Gaming at 70°C ran uncapped, and the vendor thermal stack was being suppressed on a hot device by the same code path that claims to stand down when it gets warm.

Both are fixed, along with the packaging gaps that let the module run code it had just rejected.

Nothing here is cosmetic. If you play games in a warm room, the behaviour change is real and it is in the direction of not cooking the phone.

Thermal guard

  • Tier 1 now actually caps Gaming — the tier-1 branch was gated on the MOBA profile, so a plain Gaming title at 70°C fell through to the hardware ceiling with no mitigation at all. Both profiles are capped now; MOBA keeps the higher 2.0 GHz Big allowance.
  • Ceilings are clamped to the hardware maximum — the tier values are constants, so a part reporting a lower ceiling must not be pushed above it.
  • The vendor thermal stack is no longer suppressed when hot — apply_profile wrote sconfig 10 (thermal-nolimits) and thrm_enable 0 at every tier, immediately undoing the skip that enforce_gaming_thermal_bypass performs at tier >= 1.
  • A dead sensor no longer reads as a cold SoC — a sensor reporting 0 has not produced a sample, but the raw read went into the threshold comparisons directly, pinning the device at Tier 0 with the bypass armed.
  • Thermal zones are selected by type, not by index — the scan skipped zones that had not published a reading yet, which on MTK parts is most of them for the first seconds after boot. The hardcoded fallback is now accepted only after its type confirms it is the wanted sensor.
  • GPU cooling device is matched properly — thermal-devfreq is the generic cpufreq type and matches the CPU policies too, so gaming could force cur_state 0 onto a CPU cooling device.

CPU

  • Governor and rate limits are applied per cluster — the stock baseline captures the Big cluster separately because MTK parts routinely boot the two clusters on different governors, but one value was written to all policies. Interactive was handing the Big cluster the Little cluster's values.
  • Devfreq ceiling is raised before the floor is lifted — devfreq returns -EINVAL for min above max. Latent today, silent failure tomorrow.

Packaging & security

  • update.json is generated at build time — it is what module.prop points updateJson at, and nothing in the repo read it, which is exactly why no build step touched it and the release URL went stale on every version bump.
  • Install no longer executes a payload that failed verification — the integrity layer asked the daemon to verify itself even after the manifest check had already failed.
  • status.json is created 0600 — it took whatever the inherited umask allowed, leaving the copy in /dev world-readable.
  • Uninstall preserves user configuration — it removed all of /data/adb/hypercore, taking charge limits, the hand-built gamelist and the HUD config with it. Settings now go to a timestamped sidecar under /data/adb/hypercore_removed/.
  • Grants are revoked on uninstall — the SYSTEM_ALERT_WINDOW appops outlived the module.
  • Gamelist autodetect no longer appends to shared storage — it wrote as root to a path an app could replace with a symlink.

Notes

  • Tier 2 keeps its existing 1.8 GHz ceiling. A never-applied 1.4/1.5 GHz value had been sitting in a comment; adopting it would have stacked a large behaviour change on top of a correctness fix.
  • A peer at uid 2000 (adb shell) is not a read-only client. It is deliberate, since the documented adb shell workflow depends on it, but anyone holding an adb pairing token can drive charge mode, PURGE_RAM and profile switching. Worth knowing before leaving wireless debugging enabled.

Verification

  • 81,648 tier transitions across every starting tier and a dense CPU/battery grid were replayed against the previous implementation: zero divergence whenever both sensors reported, which is what makes the Tier 1 change safe to land.
  • Clean under -Wall -Wextra -Werror and the clang static analyzer.

HyperCore v6.10.0 — ZRAM Pool Sizing & Density Pass

Choose a tag to compare

@itswill00 itswill00 released this 29 Sep 10:51

HyperOS hands a 6 GB compressed swap pool to a phone with 8 GB of RAM. The extra capacity is not free — it raises the ceiling for compression work and keeps kswapd busy, so this release lets you size the pool properly and reclaims the vertical space the WebUI was wasting while it did.

ZRAM pool sizing

WebUI → Home → Memory now resizes the compressed swap pool: Stock (ROM default), 4 GB (daily), 2 GB (gaming) and Off.

The choice is saved to zram.conf and applied once per boot, after the ROM's init.mt6789.rc has already run swapon_all — so the resize wins instead of being overwritten on the next boot.

Reboot-gated on purpose. swapoff has to pull every compressed page back into RAM in one go, and doing that mid-game is a freeze. The card therefore saves your pick and offers a Reboot button with a confirmation dialog, rather than pretending the change is instant. A 15-second cooldown sits between size changes because every one of them costs a reboot.

Two safety paths back it up: the resize is skipped when MemAvailable cannot absorb the swap in use plus a 512 MB margin, and a failed disksize write re-mkswap/swapons the device rather than leaving you swapless. The factory pool is captured at install time and restored on uninstall.

With no pool at all, swappiness settles on 20 instead of 100 — a high value with nothing to swap into only makes kswapd scan anonymous pages it can never reclaim.

Shrinking does not hand you free RAM instantly. What it buys is a smaller worst-case compression ceiling and calmer swap latency under load.

Fixes

The logs three-dot menu was unreachable. A header rule putting overflow: hidden on the button's wrapper also clipped the absolutely-positioned dropdown. The state toggled correctly on every tap, so it looked like a dead button rather than a CSS bug.

build.sh --deploy tripped its own integrity check. It refreshed the daemon binary but left customize.sh, scripts/stock_baseline.sh and checksums.txt at their installed hashes, so every local deploy logged [TAMPERING DETECTED]. All three are now synced.

Interface density

The WebUI was spending a lot of vertical space on chrome rather than content. List rows are 10 px instead of 12, section spacing and hero banners are trimmed, the Charger power grid is three columns instead of two, and the slider axis labels were dropped as duplicates of the quick-pick pills below them. The Dashboard fits about three more rows before it scrolls.

The standalone HyperMoon card became a single Quick Actions row with a live FPS readout in its subtitle, and the ZRAM card collapses to one line so the presets stay out of the way until you want them.

Upgrade notes

Nothing to do — flashing the zip is enough. The new Memory card is opt-in and defaults to Stock, so behaviour is untouched until you pick a size.

HyperCore v6.9.5 — Universal HyperMoon Positioning

Choose a tag to compare

@itswill00 itswill00 released this 28 Sep 07:52

On Android 14 QPR3+/15 the WindowManager rejects the root overlay pid, so HyperMoon falls back to a raw SurfaceControl surface with no input channel — finger-drag is impossible there by OS design. This release adds universal positioning: WebUI HUD Position section with D-pad nudge, X/Y sliders and live coordinates, honored by both render paths.

Also includes the v6.9.4 boot settle fix. Full changelog in changelog.md.

HyperCore v6.9.4 — Boot Settle & Late Touch Discovery

Choose a tag to compare

@itswill00 itswill00 released this 28 Sep 07:32

After reboot the daemon reported Interactive while the profile was never really applied. This release force re-applies Interactive at boot settle ticks, rediscovers late touch nodes on every transition, and verifies the result in the log.

Also adds universal HyperMoon positioning (WebUI HUD Position: D-pad + X/Y sliders). On Android 14 QPR3+/15 the WindowManager rejects the root overlay pid, so the HUD runs on a raw SurfaceControl surface with no input channel — finger-drag is impossible there by OS design, and these controls are its replacement.

Full changelog in changelog.md.

HyperCore v6.9.3 — Security Audit Remediation

Choose a tag to compare

@itswill00 itswill00 released this 27 Sep 00:11

HyperCore v6.9.3 — Security Audit Remediation

Full source audit (daemon, installer, build pipeline, WebUI) with 22 findings remediated.

Breaking

  • Install contract: customize.sh now requires checksums.txt in the ZIP and verifies the entire extracted payload before any payload file is sourced or executed. Always package via build.sh, which now generates the manifest and fails if any expected file is missing.

Security

  • Charging thermal ladder restored (src/charger.c): the ladder was disabled in cb6a602, leaving TEMP_OVERRIDE_ENTER/TEMP_EMERGENCY/TEMP_OVERRIDE_CLEAR as dead constants while README still claimed charging thermal protection existed. The selected mode is now a ceiling that temperature may only lower — one rung down at 45 °C (Violent → Fast → Balanced → Safe), hard floor to Safe Mode at 50 °C, restored only after 180 s continuously ≤41 °C. Dead band between 41–45 °C freezes position to prevent flapping. OEM and Bypass are exempt.
  • IPC socket authorised (src/ipc.c): /dev/hypercore.sock accepted any UID, so any app on the device could set charge modes, force Bypass, or trigger a global page-cache purge as root. Clients are now vetted with SO_PEERCRED (uid 0 for WebUI bridges and hypercore-bugreport, uid 2000 for adb shell) and untrusted peers are closed before the daemon reads from them, which also removes a main-loop stall vector.
  • Integrity manifest covers executables (build.sh, customize.sh): the manifest previously listed 7 non-executable files while ignoring every binary and every root-executed script — including customize.sh itself. Now 13 files, covering customize.sh, uninstall.sh, scripts/stock_baseline.sh, hypermoon_d, hypermoon.dex and hypercore-bugreport. Two-pass build: hash payload → embed table → relink → append libhypercore.so, which cannot embed its own hash. Verified by test: tampering with the daemon or the installer is now detected; previously both passed silently.
  • No cross-module tampering (service.sh): removed a loop that chmod'd any service.d / post-fs-data.d entry matching thermal|tweak|encore|ktweak to 0644, silently disabling third-party modules, recording no original mode, and never restored on uninstall.
  • Logs moved off /sdcard (src/include/common.hpp, src/log.c): telemetry is written to /data/adb/hypercore/hypercore.log instead of a world-readable path.
  • Root-shell injection hardening (webui/src/helpers/shell.js): am start -d now receives a single-quoted argument and only http(s) URLs.

Correctness

  • hypermoon_daemon → hypermoon_d: at 16 characters the name exceeded the kernel's 15-character comm limit, so pkill -x and pidof could never match it. One daemon leaked per HUD toggle and it survived uninstall entirely, still globbing sysfs and forking app_process every 30 s. build.sh now fails the build if a daemon binary name exceeds 15 characters.
  • Single-instance lock implemented (src/main.c): struct hw_nodes.lock_file was declared and never used, so nothing prevented two daemons fighting over the same sysfs nodes. Now an advisory flock(LOCK_EX|LOCK_NB) taken after daemon().
  • Gaming thermal bypass tier-gated (src/thermal.c): sconfig=10, FPSGO thrm_enable=0 and the GPU devfreq cooler reset ran at every tier, fighting mi_thermald even at 75 °C. Now Tier 0 only; from Tier 1 up the daemon defers to the vendor thermal stack.
  • Tier 2 ceilings corrected (src/thermal.c): documented as 1.5/1.4 GHz but implemented as 1.8/1.8 GHz. Now matches the documented intent.
  • popen no longer in the hot loop (src/gamelist.c): with an empty gamelist and no matching games, pm list packages was spawning app_process up to twice a second forever. Auto-detection is now capped at once per hour; the dumpsys window fallback went 3 s → 10 s and is skipped when the screen is off or asleep.
  • Overlay watchdog (src/hud/hypermoon_daemon.c): the dex fallback resolved to /data/adb/hypercore/bin/, a directory that never existed. Now checks real install paths, then /proc/self/exe, then disables itself with one warning instead of forking a shell every 30 s forever.
  • IPC read loop (src/ipc.c): a single read() truncated split commands, so SET_PROFILE:GAM silently fell through to Interactive. Now loops to newline under SO_RCVTIMEO.
  • GPU governor detection (src/hud/hypermoon_daemon.c): a pattern matching zero paths exited the loop on a stale buffer and never set the governor. Also fixed a glob() reuse without globfree() and a usleep() call with a >1 s user-controlled interval.
  • HyperMoon "restart" (webui/src/stores/hypermoon.js): now actually kills the processes instead of re-running a liveness check against the still-running daemon.
  • Exec timeout (webui/src/helpers/shell.js): rejects instead of resolving '', so a stuck root call is no longer indistinguishable from an empty result.
  • SIGTERM grace (service.sh, uninstall.sh): waits up to 10 s / 5 s for restore_baseline_nodes() to rewrite ~60 sysfs nodes before escalating to SIGKILL.

Docs

  • Corrected the "4-Tier thermal mitigation (Tier 0–3)" claim in README and docs/DOCUMENTATION.txt — there are three tiers; the fourth was removed in cb6a602 and the docs were never updated. Same for the GET_PROFILE and ADD_GAME IPC commands, which do not exist, and the documented socket path.
  • Documented the security model: two-layer integrity, SO_PEERCRED trust list, single-instance lock, log location.

Housekeeping

  • Untracked webui/node_modules (1263 files already listed in .gitignore but committed before it existed). Repository .git shrinks from 64 MB to 17 MB.

HyperCore v6.9.1 — Snap Navigation & Logs Stability

Choose a tag to compare

@itswill00 itswill00 released this 18 Sep 05:02

Snap navigation rebuilt with mandatory scroll-snap and delayed header sync. About/Logs order fixed. Logs drawer polished, double-header reflow and snap shutter eliminated. No daemon bump — full foundation audit passed.

  • Tabs: Home → Charger → Games → About → Logs
  • Header unified to outer with live nav / delayed title, mandatory snap always one-page-per-swipe
  • Logs: horizontal scroll isolated, terminal pan-y pan-x, no statusbar bleed
  • Nav ticks instantly on drag, header settles on snap end

HyperCore v6.9.0 — Foundation Hardening & MT6789 Consistency Release

Choose a tag to compare

@itswill00 itswill00 released this 16 Sep 03:40

HyperCore v6.9.0 — Foundation Hardening & MT6789 Consistency Release

What's Changed

Refactor & Hardening

  • Charger dedup: collapsed 10 copy-paste save/load_*_conf pairs into save_int_conf/load_int_conf + thin wrappers (src/charger.c, -142 LOC).
  • Baseline table-drive: stock_state.conf save/load now loops over descriptor tables (src/sysfs.c).
  • Thermal normalization: single normalize_thermal_temps() inline replaces 8 duplicated mili-degree blocks in main/ipc/charger.
  • Chmod guard dedup: unified write_chmod_guarded() for rate-limit vs sconfig chmod variants (src/cpu.c).
  • Atomic baseline: save_stock_baseline() writes tmp+rename so power loss never leaves half-written stock_state.conf.
  • IPC resilience: status JSON buffer 1024->1152 with bounds check, ipc_sync_status() helper, sigaction() for SIGTERM/SIGINT.
  • WebUI guards: shell.js double-resolve fix (settled flag), removed dead pollCpuGpu/pollRamBat, hypermoon.js _pollInFlight guard.
  • MT6789 lock: customize.sh now requires GED+Mali+FPSGO (was ||), strict parity with daemon validate_hardware_target().
  • HyperMoon fix: overlay cpu_policy now shows hardware ceiling cpuinfo_max_freq (500-2200 MHz) instead of throttled scaling_max_freq (500-2000).

Build & Docs

  • service.sh graceful SIGTERM before SIGKILL so restore_baseline_nodes() runs; uninstall.sh restores full GED/FPSGO/VM set.
  • Version fallbacks in WebUI no longer hard-code v6.8.5 (store.moduleVersion is live truth).

Full Changelog: https://github.com/itswill00/hypercore/blob/main/changelog.md

HyperCore v6.8.5

Choose a tag to compare

@itswill00 itswill00 released this 13 Sep 01:47

Release v6.8.5: Logic Flaw Hardening, Baseline Integrity & Inotify Resilience

HyperCore v6.8.4 — Charger Bypass Hysteresis & Sensor Discovery Hardening

Choose a tag to compare

@itswill00 itswill00 released this 11 Sep 15:26

What's Changed

🐛 Bug Fixes & Architecture Hardening

  • Charger Bypass Hysteresis Preservation: Fixed a bug in enforce_charge_mode() where non-static local variable override_active reset every 2-second daemon tick, preventing clean hysteresis recovery when battery level climbs back above 12% in Bypass mode.
  • Dynamic Thermal Zone Discovery for GPU & Charger: Integrated automatic scanning for MT6789 GPU sensor nodes (gpu1, gpu2, mali) and Charger nodes (charge_therm, charger) into scan_thermal_zones(), replacing non-existent hardcoded thermal zones.
  • State Synchronization & WebUI Telemetry: Added effective_charge_mode and charge_thermal_override to IPC responses and status.json. Synchronized real-time thermalTier and thermal protection warning banners in WebUI.
  • Stock Baseline Rollback in Uninstaller: uninstall.sh now reads and restores untouched hardware baseline parameters from /data/adb/hypercore/stock_state.conf before removing the data directory.
  • Installer & Shell Hardening: Standardized game auto-detection format in customize.sh (${pkg}:GAMING), fixed subshell quoting in build.sh deploy command, and updated all fallback version references to v6.8.4.

HyperCore v6.8.3 — Status JSON & Boot Fixes

Choose a tag to compare

@itswill00 itswill00 released this 10 Sep 07:51

Bug Fixes

  • gpu_temp/chg_temp missing from status.json: WebUI now correctly shows GPU and charger temperatures instead of always falling back to CPU/battery values.
  • Boot status "Stopped" fix (from v6.8.2): Daemon updates module.prop immediately on startup.