Skip to content

Latest commit

 

History

History
139 lines (118 loc) · 7.16 KB

File metadata and controls

139 lines (118 loc) · 7.16 KB

DawnShell progress

한국어 · Documentation · Testing

This file records the current standalone DawnShell implementation only. Obsolete prototype package names, signing values, APK hashes, and migration notes have been removed because they do not describe the current product.

Completed

Android Direct Boot

  • Dedicated package me.aroxu.dawnshell and dedicated app UID.
  • Direct-Boot-aware LOCKED_BOOT_COMPLETED receiver and foreground service.
  • DE provisioning for boot settings, public keys, runtime files, and logs.
  • BFU root, CE isolation, rootfs, and chroot gates.
  • Persistent Debian instance across USER_UNLOCKED.
  • Duplicate boot and stale supervisor-state prevention.

The implementation follows Google's Direct Boot guide and the AOSP FBE guide.

Debian 13

  • Verified Trixie rootfs installation with live logs and atomic publication.
  • systemd, D-Bus, OpenSSH, and the debian account.
  • Public-key-only SSH with direct root login disabled.
  • Local root and debian password management and su root support.
  • Validated start, stop, restart, status, and rootfs removal.

Embedded runtime

  • Source builds for armeabi-v7a, arm64-v8a, and x86_64.
  • Pinned BusyBox, pkgdetails, gpgv dependency closure, and Debian keys.
  • Source URL, version, and SHA-256 records in SOURCES.lock.
  • BusyBox formatted stat -c preflight.
  • Default make -j"$(nproc)" parallel compilation.

Kernel and network

  • Delegated cgroup v2 plus device BPF probe with isolated v1 fallback.
  • Direct Android NIC sharing for Wi-Fi, mobile, and USB Ethernet.
  • Default-off direct and VID:PID-scoped exclusive USB passthrough, with v2 BPF and v1 devices fallback plus normal-stop driver restoration.
  • Tailscale route-mark integration.
  • Safe host-network-only Docker default and explicit risky bridge controls.
  • Android-wide reboot now bridge with isolated systemctl reboot behavior.

UI, documentation, and compliance

  • Material 3 dashboard and dedicated selectable live-log readers.
  • Complete Korean UI resources.
  • Random SSH key generation, file export, and generic local-shell commands.
  • Friendly Korean and English guides, glossary, and official Android links.
  • Local and CI Markdown link, heading-anchor, and language-pair validation.
  • Removal of obsolete product names and migration guidance.
  • MIT application license and preserved third-party source/license obligations.
  • GitHub Actions builds, checks, signed tag releases, corresponding source, license bundles, metadata, and checksums.

Hardware video acceleration

  • Added a default-off MediaCodec option and app-local diagnostic :codec process.
  • Added an on-demand NDK worker path available in both BFU and AFU without coupling its lifecycle to USER_UNLOCKED.
  • Added deterministic B-frame MP4 and HEVC vectors, streaming FFmpeg wrappers, a software CPU baseline, and hardware-encode PSNR/SSIM checks.
  • Added malformed AVC/HEVC, EOS, concurrent private-worker, parent-exit cleanup, and five-workload long-run CPU/RSS/thermal regression paths.
  • Added API 29+ platform classification and conservative API 24–28 fallback.
  • Excluded secure/DRM and silent software fallback while recording AVC/HEVC instance creation in DE JSON and logs.
  • Added a versioned inherited-FD binary protocol, static Debian client, and bionic NDK worker for all three supported ABIs.
  • Added deterministic AVC decode/I420 checksum and hardware encode/FFmpeg self-tests.
  • Added FFmpeg demux/mux wrappers for hardware decode and encode while preserving bounded packet framing and timestamps.
  • Replaced the listener/descriptor-passing prototype with one inherited memfd, two inherited eventfd objects, and no socket fallback.
  • Added H.264/HEVC-to-H.264 Surface transcoding without returning full YUV frames to Debian.
  • Added keyframe requests, worker/session statistics, and malformed-request isolation checks.
  • Added a 720p inherited-transport check, 1080p30 realtime Surface transcode gate, and abrupt-client resource cleanup test path.
  • Recorded earlier AFU app-local MediaCodec probe evidence. This historical probe does not validate the current inherited-FD NDK worker path.
  • Verified the current inherited-FD private NDK worker after unlock by encoding a 10-second, 1920x1080 HEVC stream (300 frames at approximately 8 Mbit/s) on an Android 16 ARM64 device.
  • Rewrote the packet-framing and FFmpeg planning adapter for perl-base, which Debian marks Essential, so provisioning installs no interpreter for the hardware bridge. Installing Python previously added several slow minutes to every Debian setup run.
  • Diagnosed and fixed multi-minute stalls during package configuration. The device kernel carries a close_range(2) backport that walks the whole requested descriptor range, so each closefrom(3) call cost about two minutes of uninterruptible kernel time. A measured seccomp filter now reports ENOSYS for that call, and dpkg-reconfigure openssh-server went from over ten minutes to 3.3 seconds on the affected device.
  • Fixed systemd staying permanently degraded after any package change. /data uses fscrypt version 1, so the encryption key is resolved through the calling process keyring; systemd joins a fresh session keyring at startup and loses it, leaving every service unable to create files (ENOKEY). A measured seccomp filter now reports ENOSYS for KEYCTL_JOIN_SESSION_KEYRING. On the device the manager returned to system_state=running with zero failed units.
  • Verify vendor AVC hardware instance creation on a locked real device.
  • Verify fixed-vector decode, encode, inherited memfd/eventfd transport, and Surface transcode before and after first unlock.
  • Verify 1080p realtime performance, timestamp stability, and resource cleanup on a real device.

Physical-device validation completed

  • Android 16 / ARM64 locked-boot broadcast and DE execution.
  • BFU Debian systemd and SSH.
  • First-unlock continuity.
  • cgroup v1 delegation through Docker cgroup initialization.
  • Shared host networking and Tailscale routes.
  • AFU private NDK worker startup and 1080p HEVC hardware encode through the inherited memfd/eventfd transport.
  • gsmi distinguished an active 1080p MediaCodec encode client from an independently idle 3D GPU on an Android 16 ARM64 device.

Remaining validation

  • Full ARMv7 installation and BFU test.
  • Full x86_64 device or emulator test.
  • Five-cycle regression across additional vendor ROMs.
  • Broader Docker bridge backend coverage.
  • Direct/exclusive USB hot-plug, driver restore, serial, libusb, and storage validation on physical devices.
  • Long-running memory, mount, and cgroup leak observation.
  • Five-cycle BFU hardware codec regression with BFU_REQUIRE_HARDWARE_CODEC=1.

See testing for the current acceptance procedure.