View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001786 | K18X001.00 SKB SWAN | SW | public | 2023-08-03 17:25 | 2023-11-17 10:00 |
| Reporter | (ALTech) Sangmin Choi | Assigned To | (ALTech) Sangmin Choi | Due Date | 2023-11-03 10:42 |
| Priority | normal | Severity | s4-minor | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Summary | 0001786: The account of AppleTV+ can't be saved. | ||||
| Description | The account of AppleTV+ can't be saved. You can reproduce this issue with following steps. 1. Open the AppleTV+ application # am start -a android.intent.action.MAIN -n com.apple.atve.androidtv.appletv/.MainActivity 2. Login the account 3. Terminate the AppleTV+ application # kill -9 $(pidof com.apple.atve.androidtv.appletv) 4. Open the AppleTV+ application again # am start -a android.intent.action.MAIN -n com.apple.atve.androidtv.appletv/.MainActivity 5. You can see the login screen and this issue the issue. The account should be saved. Other devices have no issue.(Eagle and AI2 Intek) Could you please check it? | ||||
| Tags | No tags attached. | ||||
| Attach Tags | |||||
| User List |
(ALTech) Wooshin Kang , |
|---|
|
|
|
|
|
Hello, Jacky, Could you please assign an engineer for this ticket? Thank you. Sangmin Choi. |
|
|
Hi Sangmin, I've tried to reproduce it. it's random. Sometimes, I can see the issue, but sometimes I can't. If I can not see the issue, after rebooting device, I can see it. I also checked it on Apple community, It looks like a known issue. https://discussions.apple.com/thread/254574167 https://discussions.apple.com/thread/254806896 Thanks, Jason |
|
|
Hello, Jason, Could you please share the video you tested? Thank you. Sangmin Choi. |
|
|
Hi Sangmin, For pass case, Please refer to apple_pass.mp4. (Please ignore my broken monitor) As you can see, the login status is kept after killing process. (I tried 2 times) but when I reboot the device, the account is logout. Thanks, Jason |
|
|
Hello, Jason, You're working without SKB account login. Now I have checked the login account was kept without SKB account login. But, this issue reproduced every time with SKB account login.(there is live broadcasting) And, also the AppleTV+ account didn't maintain when the STB rebooted. I think it's not a known issue. There are following error messages in logcat. 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err javax.crypto.IllegalBlockSizeException 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err at android.security.keystore.AndroidKeyStoreCipherSpiBase.engineDoFinal(AndroidKeyStoreCipherSpiBase.java:519) 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err at javax.crypto.Cipher.doFinal(Cipher.java:2055) 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err at com.apple.atve.generic.LunaRSA.decrypt(LunaRSA.java:163) 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err at com.apple.atve.generic.UserData.loadKeyFromFile(UserData.java:187) 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err at com.apple.atve.generic.UserData.<init>(UserData.java:81) 08-03 18:23:24.326 com.apple.atve.androidtv.appletv 6626 6678 W System.err at com.apple.atve.generic.LunaWatchNextChannelWorker.<init>(LunaWatchNextChannelWorker.java:43) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at java.lang.reflect.Constructor.newInstance0(Native Method) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at java.lang.reflect.Constructor.newInstance(Constructor.java:343) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at androidx.work.WorkerFactory.createWorkerWithDefaultFallback(WorkerFactory.java:96) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at androidx.work.impl.WorkerWrapper.runWorker(WorkerWrapper.java:245) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at androidx.work.impl.WorkerWrapper.run(WorkerWrapper.java:137) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at androidx.work.impl.utils.SerialExecutor$Task.run(SerialExecutor.java:91) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1167) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:641) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at java.lang.Thread.run(Thread.java:919) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err Caused by: android.security.KeyStoreException: -1 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at android.security.KeyStore.getKeyStoreException(KeyStore.java:1303) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at android.security.keystore.KeyStoreCryptoOperationChunkedStreamer.doFinal(KeyStoreCryptoOperationChunkedStreamer.java:224) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err at android.security.keystore.AndroidKeyStoreCipherSpiBase.engineDoFinal(AndroidKeyStoreCipherSpiBase.java:506) 08-03 18:23:24.327 com.apple.atve.androidtv.appletv 6626 6678 W System.err ... 14 more 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err java.lang.NullPointerException: Attempt to invoke virtual method 'void javax.crypto.Cipher.init(int, java.security.Key, java.security.spec.AlgorithmParameterSpec)' on a null object reference 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at com.apple.atve.generic.LunaAES.decrypt(LunaAES.java:116) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at com.apple.atve.generic.UserData.decryptFile(UserData.java:125) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at com.apple.atve.generic.UserData.update(UserData.java:158) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at com.apple.atve.generic.LunaWatchNextChannelWorker.doWork(LunaWatchNextChannelWorker.java:84) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at androidx.work.Worker$1.run(Worker.java:86) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1167) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:641) 08-03 18:23:24.332 com.apple.atve.androidtv.appletv 6626 6893 W System.err at java.lang.Thread.run(Thread.java:919) Is there anything to check with this messages? Thank you. Sangmin Choi. |
|
|
Hi Sangmin, Is this a special AppleTV+ apk that apple release to SKB. I guess this app is not standard app. When I remove Digicap HomeUI, and prebuilt Android TV standard Launcher. After I launcher AppleTV from standard Launcher. I can NOT see login screen. I reboot the device again, I still can NOT see login screen. My 1st suspicion is I guess this special app that apple release to SKB and the account management is managed by HomeUI for some reasons (maybe Apple has a deal with SKB) My 2nd suspicion is as follows, if we launch AppleTV+ from TVSettings or Android Standard Launcher. the AppleTV+ will be opened normally. if we launch AppleTV+ from HomeUI app list, the AppleTV+ will be opened in another way. (HomeUI will start different Activity) Could you check it? Thanks, Jason |
|
|
Hi Sangmin, I've created the following ticket https://synacsm.atlassian.net/servicedesk/customer/portal/173/CSMSKBSBLT-225 Thanks, Jason |
|
|
Hello, Jason, Thank you. I will also check if there is anything I can check. Best regards, Sangmin Choi. |
|
|
Hello, Jason, This issue was reported by SKB QA. https://jira.skbroadband.com/browse/BPM-22652 And, Apple has released test apk for this issue. Followings are the original comment from apple. ==================================================================================== After device reboot I checked if the `key` file is there or not using Android Studio. It exists. However, when we try to read that key.bin we are encountering issues. Question for SKB : why the key is corrupted on a device reboot. This seems to be happening only on the Soundbar. I wrote a sample application that shows the problem after the reboot. Please look for AndroidKeyStoreTest.java code for the code that is problematic on the Soundbar. We use AndroidKeyStore to generate public private keypair and use the public key to encrypt our own symmetric encryption key and store it on the file system. On a device reboot we try to decrypt our symmetric private key using the private key stored in Android Key Store. This second operation seems to fail after the device reboot. ==================================================================================== I already pushed Synaptics through CSMSKBSBLT-225 ticket. Thank you. Sangmin Choi. |
|
|
Hello, Jason, This issue was reported by SKB QA. https://jira.skbroadband.com/browse/BPM-22652 And, Apple has released test apk for this issue. Followings are the original comment from apple. ==================================================================================== After device reboot I checked if the `key` file is there or not using Android Studio. It exists. However, when we try to read that key.bin we are encountering issues. Question for SKB : why the key is corrupted on a device reboot. This seems to be happening only on the Soundbar. I wrote a sample application that shows the problem after the reboot. Please look for AndroidKeyStoreTest.java code for the code that is problematic on the Soundbar. We use AndroidKeyStore to generate public private keypair and use the public key to encrypt our own symmetric encryption key and store it on the file system. On a device reboot we try to decrypt our symmetric private key using the private key stored in Android Key Store. This second operation seems to fail after the device reboot. ==================================================================================== I already pushed Synaptics through CSMSKBSBLT-225 ticket. Thank you. Sangmin Choi. |
|
|
Hello, Jason, About the Apple TV login issue, Synaptics can't reproduce it with their CI firmware. https://synacsm.atlassian.net/servicedesk/customer/portal/173/CSMSKBSBLT-225 And, I mentioned before, there is no issue in AI2 Intek. Swan is the only device which has this issue in VS550 devices. So, please communicate with Synaptics to fix this issue. Synaptics may not work without any question or analysis from us, because reference image has no issue. Thank you. Sangmin Choi. |
|
|
Hi Sangmin, I asked Synatpics to review our log. Because we never modify Keymaster flow by ourselves. As far as I know the flow of keymaster frameworks/base/keystore -> same as the eagle. vendor/synaptics/vsxxx/keymaster -> We never modify it. Maybe it's different from AI2. (I don't know how to check it, because it's Synaptics implementation) syna-release/ta_enc/ There is a modification from Synaptics before (For fixing TVTS failures) libgencrypto.ta/bg5ct/A0/libgencrypto.ta. This may related to keymaster. but we don't have source code of ta file. Please also help us push Synaptics to review the log so that we can check every part that related to Keymaster. Thanks, Jason |
|
|
Hello, Jason, I got the comment and application from Apple yesterday. Could you please check it? ==================================================================================== 10-17 10:35:16.745 6626 6649 W System.err: javax.crypto.IllegalBlockSizeException 10-17 10:35:16.745 6626 6649 W System.err: at android.security.keystore.AndroidKeyStoreCipherSpiBase.engineDoFinal(AndroidKeyStoreCipherSpiBase.java:519) 10-17 10:35:16.745 6626 6649 W System.err: at javax.crypto.Cipher.doFinal(Cipher.java:2055) 10-17 10:35:16.745 6626 6649 W System.err: at com.apple.atve.generic.LunaRSA.decrypt(LunaRSA.java:163) 10-17 10:35:16.746 6626 6649 W System.err: at com.apple.atve.generic.UserData.loadKeyFromFile(UserData.java:187) 10-17 10:35:16.746 6626 6649 W System.err: at com.apple.atve.generic.UserData.<init>(UserData.java:81) 10-17 10:35:16.746 6626 6649 W System.err: at com.apple.atve.generic.LunaWatchNextChannelWorker.<init>(LunaWatchNextChannelWorker.java:43) 10-17 10:35:16.746 6626 6649 W System.err: at java.lang.reflect.Constructor.newInstance0(Native Method) 10-17 10:35:16.746 6626 6649 W System.err: at java.lang.reflect.Constructor.newInstance(Constructor.java:343) 10-17 10:35:16.746 6626 6649 W System.err: at androidx.work.WorkerFactory.createWorkerWithDefaultFallback(WorkerFactory.java:96) 10-17 10:35:16.746 6626 6649 W System.err: at androidx.work.impl.WorkerWrapper.runWorker(WorkerWrapper.java:245) 10-17 10:35:16.746 6626 6649 W System.err: at androidx.work.impl.WorkerWrapper.run(WorkerWrapper.java:137) 10-17 10:35:16.746 6626 6649 W System.err: at androidx.work.impl.utils.SerialExecutor$Task.run(SerialExecutor.java:91) 10-17 10:35:16.746 6626 6649 W System.err: at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1167) 10-17 10:35:16.746 6626 6649 W System.err: at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:641) 10-17 10:35:16.746 6626 6649 W System.err: at java.lang.Thread.run(Thread.java:919) 10-17 10:35:16.747 6626 6649 W System.err: Caused by: android.security.KeyStoreException: Unknown error 10-17 10:35:16.747 6626 6649 W System.err: at android.security.KeyStore.getKeyStoreException(KeyStore.java:1303) 10-17 10:35:16.747 6626 6649 W System.err: at android.security.keystore.KeyStoreCryptoOperationChunkedStreamer.doFinal(KeyStoreCryptoOperationChunkedStreamer.java:224) 10-17 10:35:16.747 6626 6649 W System.err: at android.security.keystore.AndroidKeyStoreCipherSpiBase.engineDoFinal(AndroidKeyStoreCipherSpiBase.java:506) The Issue is with the AndroidKeyStore that we use to generate a public private key pair and use the resulting keys for encrypting and decrypting our own private key. After the app is killed or the device is rebooted we have observed that the first public private key pair generated by AndroidKeyStore is not working well. I tried to capture this scenario in the Sample Application and hope that should help debug this issue. Please review this with your partner. Please find attached a SampleApplication from our Engineering Team that highlights the problem seen on the Devices related to this issue. Some key things. 1. Please have a look at the class AndroidKeyStoreTest.java file. 2. Tests written in that file work just fine when invoked from MainActivity on Google Chromecast. However, Same tests fail on SKB device. We are guessing the firmware has some issue with Bouncy Castle implementation of the crypto algorithms for various use cases in the application. ==================================================================================== Thank you. Sangmin Choi. |
|
|
Hello, Jason, Do you know how to enable the log in syna-release/ampsdk/drm/client/genericcrypto_client/src/DRM_Crypto_Agent.c ? There is an error the function exist in DRM_Crypto_Agent.c, but I can't see the log message even though I uncomment the DEBUG define. #define DEBUG #ifdef DEBUG #define log DRMCLT_ERROR #define LOG_FUNCTION_ENTRY DRMCLT_ERROR("%s: Entered\n", __FUNCTION__); #define LOG_FUNCTION_EXIT(ret) DRMCLT_ERROR("%s: Leaving with %d\n", __FUNCTION__, ret); #else #define log(...) #define LOG_FUNCTION_ENTRY #define LOG_FUNCTION_EXIT(ret) #endif Thank you. Sangmin Choi. |
|
|
Hi Sangmin, I have one question, Is there anything suspicious in the drm folder? I've reviewed our code, I don't see anyone ever modifying Keymaster. I've checked many parts as follows, external/bouncycastle -> same as the eagle10 system/keymaster/ -> same as the eagle10 system/security/keystore -> same as the eagle10 hardware/interfaces/keymaster -> same as the eagle10 frameworks/base/keystore -> same as the eagle10 The following 3 parts are what I suspect but I don't know how to check. vendor/synaptics/common/keymaster -> keymaster HAL, implementation by Synaptics -> I can not understand the Synaptics's implementation, I don't know how to verify. Maybe we can compare AI2 (ATV10) normal log syna-release/ta_enc/ -> trust application that handle keymaster, it's binary file, we don't have source code. syna-release/linux_4_9_q/arch/arm64/configs -> Maybe we missed to enable some kernel configurations, but I have no idea to confirm it. That's why I asked Synpatis to check the logs first, because some parts are their implementation and some parts we don't have source code. I also checked a very old version and that version already had issues. I think there was already a problem when we received the SDK from Synaptics. If you have any idea (update), please let me know. Thanks, Jason |
|
|
Hello, Jason, I'm tracking the error and it looks Syanptics DRM module related with RSA has problem. I updated the Synaptics Jira, please check it. Thank you. Sangmin Choi. |
|
|
Hello, Jason, Could you please share the result of CtsKeystoreTestCases ? Thank you. Sangmin Choi. |
|
|
Hi Sangmin, I tested CtsKeystoreTestCases this morning, the result is good. Thanks, Jason |
|
|
Thank you, Jason :) |
|
|
Hello, Jason, I used following modifications to figure out the point which returns the error. 1. syna-release/drm diff --git a/drm_common/src/drm_logger.c b/drm_common/src/drm_logger.c index 280d8a4..045fdc3 100755 --- a/drm_common/src/drm_logger.c +++ b/drm_common/src/drm_logger.c @@ -54,7 +54,7 @@ extern UINT32 DRM_GetCurrentTimeMS(); -UINT32 gDebugLogLevel = DRM_LOG_ERROR; +UINT32 gDebugLogLevel = DRM_LOG_LEVEL_MAX; static char *lead_color[] = { "\033[31;1m", // Fatal: red diff --git a/keymaster/src/ca_apis.c b/keymaster/src/ca_apis.c index 9045806..3166a44 100755 --- a/keymaster/src/ca_apis.c +++ b/keymaster/src/ca_apis.c @@ -628,9 +628,12 @@ HRESULT TZ_DRM_RsaOperation(UINT32 uPurpose, UINT32 uPadding, UINT32 uDigest, operation.params[3].value.b = (UINT32)phySign; operation.started = 1; + DRMLOGE("[%s,%d] lRes : %d\n", __FUNCTION__, __LINE__, lRes); lRes = TEEC_InvokeCommand(&teeSession, TZ_ALGO_RSA_OPERATION, &operation, NULL); + DRMLOGE("[%s,%d] lRes : %d\n", __FUNCTION__, __LINE__, lRes); + return lRes; } 2. vendor/synaptics/common diff --git a/keymaster/4.0/hal/include/syna_km_util.h b/keymaster/4.0/hal/include/syna_km_util.h index 0d8e6fb..06fba10 100755 --- a/keymaster/4.0/hal/include/syna_km_util.h +++ b/keymaster/4.0/hal/include/syna_km_util.h @@ -23,7 +23,7 @@ #define LOG_TAG "SYNAKeyMaster" #include <log/log.h> -//#define ENABLE_LOG +#define ENABLE_LOG #ifdef ENABLE_LOG #define dbg_log ALOGD You can see the error messages with SYNAKeyMaster and MODULE_GENERIC TAGs. Synaptics is preparing the debug library for tee. When you get the library, please check why SWAN has this issue only. Thank you. Sangmin Choi. |
|
|
Hello, Jason, SKB and Apple are pushing me about resolving this issue. I think you should put a resource for this issue. If you still have any resource problem, please let me know. I also must report it to Wooshin about current situation. Thank you. Sangmin Choi. |
|
|
Hi Sangmin, We have limited resource, but current situation is you saw the error in trusty application (*.ta) file. (we don't have source code to analyze it, so we can not help you to debug it) I just asked Synpatics China FAE to push their RD again. Thanks, Jason |
|
|
Hello, Jason, I also want to check this issue on your side. I think you updated this ticket based on just my comments. I'm afraid that if there is anything I didn't catch. Anyway, please keep pushing your contact point to resolve this issue. Thank you. Sangmin Choi. |
|
|
Hello, Jason, I set the due date for this ticket. If you have any problem with this schedule, please let me know. Thank you. Sangmin Choi. |
|
|
Hi Sangmin, I've spent the whole day checking this issue and I think I'm at the same progress as you so far. lRes = TEEC_InvokeCommand(&teeSession, TZ_ALGO_RSA_OPERATION, &operation, NULL); the return value lRes is -1 in this function. I also consult River about this case. He said we can not debug it anymore. because we don't know the implementation of trusty application. I also checked if there are any missing AMP's config, I tried to add the following configuration. but I still can see the issue. xts@xts-deskmini:~/Projects/swan/syna-release/configs/product$ git diff . diff --git a/product/bg5ct_a0_android_q_launched_stb_v4/bg5ct_a0_android_q_launched_stb_v4_defconfig b/product/bg5ct_a0_android_q_launched_stb_v4/bg5ct_a0_android_q_launched_stb_v4_defconfig index a8e3cff..ca1de45 100644 --- a/product/bg5ct_a0_android_q_launched_stb_v4/bg5ct_a0_android_q_launched_stb_v4_defconfig +++ b/product/bg5ct_a0_android_q_launched_stb_v4/bg5ct_a0_android_q_launched_stb_v4_defconfig @@ -221,7 +221,7 @@ CONFIG_DYNAMIC_FFMPEG=y CONFIG_ENABLE_ISR_AFFINITY=y # CONFIG_AMP_RELEASE_BUILD is not set CONFIG_ENABLE_DRM=y -# CONFIG_AMP_DRM_DEBUG_ENABLE is not set +CONFIG_AMP_DRM_DEBUG_ENABLE=y CONFIG_AMP_DRM_ENG_BCM=y CONFIG_AMP_DRM_STATIC_CURL=y # CONFIG_AMP_IP_DRM_CIP is not set @@ -232,10 +232,10 @@ CONFIG_AMP_IP_DRM_GENERIC_CRYPTO=y # CONFIG_AMP_IP_DRM_HDCP2X is not set # CONFIG_AMP_IP_DRM_NAGRA is not set # CONFIG_AMP_IP_DRM_CISCOVSSS is not set -# CONFIG_AMP_IP_DRM_OPENCRYPTO is not set +CONFIG_AMP_IP_DRM_OPENCRYPTO=y # CONFIG_AMP_IP_DRM_PVR is not set # CONFIG_AMP_IP_DRM_VMX_ULTRA is not set -# CONFIG_AMP_IP_DRM_KEY is not set +CONFIG_AMP_IP_DRM_KEY=y Now I have one more idea to check this issue. Could you pull libkeymaster.so or libgencrypto.ta from AI2 (ATV10) device, and remount/push to AI2MAX. (The AI2 on our side is ATV9) I just want to confirm if the failures is related to these parts. I'll push Synaptics China FAE twice a day to speed up the correction of this problem. Thanks, Jason |
|
|
Hi Sangmin, I discussed this ticket with Synaptics China FAE these 2 nights, He knew that SKB escalated the issue. so He will help us push their RD. I also asked him if his RD thinks the key is corrupted, please let me know how to check/dump it at every stage and speed up debugging. Thanks, Jason |
|
|
Hello, Jason, Thank you for update. |
|
|
Hi Sanmin, We just had a meeting with Synaptics engineers. He wants to know how AppleTV determines that there is corrupted with the key.bin. Is the location of key.bin /data/data/com.apple.atve.androidtv.appletv/files/key.bin I did some tests to check key.bin 1. Boot device (we haven't launched AppleTV yet) -> key.bin has not been generated yet 2. 1st launch AppleTV (we haven't logined Apple account) -> key.bin has been generated. the checksum of key.bin is 4c43df05b038db837160afe178fd14ef 3. login AppleTV account the checksum of key.bin is still 4c43df05b038db837160afe178fd14ef 4. Reboot device 4. Check checksum again before launch AppleTv. the checksum of key.bin is still 4c43df05b038db837160afe178fd14ef 5. launch AppleTv again. (Login status disappeared) the checksum of key.bin change to bcada886dbe63f7be2550569466be676 Could you provide these information to Apple Engineer. And ask how AppleTV determines that there is corrupted with the key.bin. Synaptics engineer wants to know how AppleTV determines that there is corrupted with the key.bin Thanks, Jason |
|
|
Hello, Jason, Synaptics released the patch and I checked it works. I attached the patch from Synaptics. But, there is one more issue. The root cause of this issue is that the private key was generated incorrectly. Apple TV+ application generates the private key at the first boot time even if the Apple TV+ application doesn't start. So, all swan devices have incorrect private key already. If we apply the patch from Synaptics, the private key will be generated correctly, but exist private key will not be updated. Apple TV+ application will not try to generate the private key again. So, we should initialize the private key of Apple TV+ if the generated key has problem. Could you please check above and let me know your opinion? Thank you. Sangmin Choi. 135759_c39a9af8.patch (12,451 bytes)
commit c39a9af8cea1642e81d8b3892f59b0e7f3046f0d
Author: Hong Song <Hong.Song@synaptics.com>
Date: Mon Apr 19 14:11:20 2021 +0800
keymaster - MMCEI-9460 - CL#135759 - merged
Change-Id: If3094fc70a7e21bcfa0bf2c08a241633ee4cbe5a
diff --git a/keymaster/4.0/hal/include/syna_cryptokey.h b/keymaster/4.0/hal/include/syna_cryptokey.h
index 1bba939..29f0651 100755
--- a/keymaster/4.0/hal/include/syna_cryptokey.h
+++ b/keymaster/4.0/hal/include/syna_cryptokey.h
@@ -278,6 +278,8 @@ public:
return 0;
}
+
+
protected:
keymaster_error_t CreateKey(keymaster_key_origin_t key_origin,
const keymaster_key_param_set_t* params,
@@ -286,10 +288,12 @@ protected:
keymaster_key_blob_t* key_blob,
keymaster_key_characteristics_t** characteristics);
+
inline const uint8_t* GetKey() const {
return iKey;
}
+
inline int GetKeySizeFromCurve (keymaster_ec_curve_t Curve){
int SzBits = 0;
@@ -345,6 +349,10 @@ protected:
inline keymaster_error_t SetKeySize(size_t key_size_bits) {
keymaster_error_t lRes = SupportedKeySize(key_size_bits);
+
+ LOG_FUNCTION_ENTRY;
+
+
if (lRes == KM_ERROR_OK) {
if(iAlgo == KM_ALGORITHM_TRIPLE_DES) {
/*
@@ -370,6 +378,9 @@ protected:
iKeySize += 1;
}
}
+
+ dbg_log("keysize:%d\n", iKeySize);
+ LOG_FUNCTION_EXIT(lRes);
return lRes;
}
diff --git a/keymaster/4.0/hal/syna_asymcryptokey.cpp b/keymaster/4.0/hal/syna_asymcryptokey.cpp
index acd5f68..f02b925 100755
--- a/keymaster/4.0/hal/syna_asymcryptokey.cpp
+++ b/keymaster/4.0/hal/syna_asymcryptokey.cpp
@@ -347,6 +347,7 @@ keymaster_error_t RsaKey::SetImportKeySize(size_t /*key_size_bits*/)
size_t RsaKey::GetKeyBufferSize() const
{
//N(iKeySize) + PubExpo(4 bytes) + (P, Q, DP, DQ, QInv) of size iKeySize/2 each
+ dbg_log("GetKeyBufferSize for RSA:%d\n", iKeySize + sizeof(uint32_t) + 5 * (iKeySize >> 1));
return (iKeySize + sizeof(uint32_t) + 5 * (iKeySize >> 1));
}
diff --git a/keymaster/4.0/hal/syna_cryptokey.cpp b/keymaster/4.0/hal/syna_cryptokey.cpp
index 7939ee6..f70fa34 100755
--- a/keymaster/4.0/hal/syna_cryptokey.cpp
+++ b/keymaster/4.0/hal/syna_cryptokey.cpp
@@ -142,15 +142,21 @@ keymaster_error_t CryptoKey::CreateKey(keymaster_key_origin_t key_origin,
keymaster_key_characteristics_t** characteristics)
{
keymaster_error_t lRes = KM_ERROR_OK;
+
+ LOG_FUNCTION_ENTRY;
+
lRes = ValidateKeyParam(*params);
if (lRes == KM_ERROR_OK) {
- lRes = SetupKeyBuffer();
+
+ if(key_origin != KM_ORIGIN_SETUP) lRes = SetupKeyBuffer();
+
if (lRes == KM_ERROR_OK) {
if (key_origin == KM_ORIGIN_GENERATED) {
if (lRes == KM_ERROR_OK)
lRes = GenerateSecureKey();
} else if (key_origin == KM_ORIGIN_SETUP) {
/*nothing to do*/
+ dbg_log("KM_ORIGIN_SETUP\n");
} else if (key_origin == KM_ORIGIN_IMPORTED) {
lRes = ImportSecureKey(key_format, key_data);
if (lRes == KM_ERROR_OK) {
@@ -175,6 +181,9 @@ keymaster_error_t CryptoKey::CreateKey(keymaster_key_origin_t key_origin,
if (key_origin == KM_ORIGIN_GENERATED)
lRes = KM_ERROR_INVALID_ARGUMENT;
}
+
+ LOG_FUNCTION_EXIT(lRes);
+
return lRes;
}
@@ -233,6 +242,8 @@ uint32_t CryptoKey::CalcSizeofKeyblob (
uint32_t key_blob_size = KEY_CHKSUM_SIZE+KEY_HANDLE_SIZE+sizeof(keymaster_key_origin_t)+sizeof(params->length);
keymaster_key_param_t *pParam = NULL;
+ LOG_FUNCTION_ENTRY;
+
if(params->length > 0) {
pParam = params->params;
for (index = 0; index < params->length; index++) {
@@ -269,7 +280,10 @@ uint32_t CryptoKey::CalcSizeofKeyblob (
key_blob_size += sizeof(uint32_t); /*iKeySize*/
key_blob_size += sizeof(uint32_t); /*iKeySizeInBits*/
- key_blob_size += iKeySize; /*iKey*/
+ key_blob_size += GetKeyBufferSize(); //iKeySize; /*iKey*/
+
+ LOG_FUNCTION_EXIT(0);
+
return key_blob_size;
}
@@ -288,6 +302,8 @@ keymaster_error_t CryptoKey::StoreParamsToKeyblob (
keymaster_key_param_t *pParam = NULL;
+ LOG_FUNCTION_ENTRY;
+
if(!key_blob || !params) {
return KM_ERROR_INVALID_ARGUMENT;
}
@@ -370,8 +386,9 @@ keymaster_error_t CryptoKey::StoreParamsToKeyblob (
memcpy((void *)(key_blob->key_material+offset), &iKeySizeInBits, sizeof(iKeySizeInBits));
offset += sizeof(iKeySizeInBits);
/*store iKey*/
- memcpy((void *)(key_blob->key_material+offset), iKey, iKeySize);
- offset += iKeySize;
+
+ memcpy((void *)(key_blob->key_material+offset), iKey, GetKeyBufferSize());
+ offset += GetKeyBufferSize();
}
lRes = iImpl->EncryptKeyData((key_blob->key_material_size - (KEY_HANDLE_SIZE + KEY_CHKSUM_SIZE)),
@@ -406,6 +423,7 @@ keymaster_error_t CryptoKey::StoreParamsToKeyblob (
memcpy((void *)(key_blob->key_material), &sum, KEY_CHKSUM_SIZE);
}
+ LOG_FUNCTION_EXIT(lRes);
return lRes;
}
@@ -421,7 +439,11 @@ keymaster_error_t CryptoKey::RetrieveParamsFromKeyblob (
uint32_t offset = 0;
uint32_t index = 0;
- if(!key_blob && !key_origin && !params && !key_format && !key_data) {
+
+ LOG_FUNCTION_ENTRY;
+
+
+ if(!key_blob || !key_origin || !params || !key_format || !key_data) {
return KM_ERROR_INVALID_ARGUMENT;
}
@@ -499,19 +521,31 @@ keymaster_error_t CryptoKey::RetrieveParamsFromKeyblob (
* Let's check if it reach the end of key_blob.
* if not, we should be able to Retrieve iKey/iKeySize/iKeySizeInBits
*/
+
if((offset+8) <= key_blob->key_material_size) {
memcpy(&iKeySize,key_blob->key_material+offset, sizeof(iKeySize));
offset += sizeof(iKeySize);
memcpy(&iKeySizeInBits,key_blob->key_material+offset, sizeof(iKeySizeInBits));
offset += sizeof(iKeySizeInBits);
}
- if((offset+iKeySize) <= key_blob->key_material_size) {
- iKey = (UINT8 *)malloc(iKeySize);
- memcpy(iKey, key_blob->key_material+offset, iKeySize);
- offset += iKeySize;
+
+
+ SetupKeyBuffer();
+ size_t uKeyBufSize = GetKeyBufferSize();
+
+ if((offset+uKeyBufSize) <= key_blob->key_material_size) {
+
+ // iKey = (UINT8 *)malloc(uKeyBufSize);
+ memcpy(iKey, key_blob->key_material+offset, uKeyBufSize);
+ offset += uKeyBufSize;
+ dbg_log("uKeyBufSize:%d\n", uKeyBufSize);
+ }else{
+
+ dbg_log("cannot copy to key in %s, %d, %d, %d, %d\n", __FUNCTION__, offset, iKeySize, uKeyBufSize, key_blob->key_material_size);
}
}
+ LOG_FUNCTION_EXIT(lRes);
return lRes;
}
@@ -560,21 +594,31 @@ keymaster_error_t CryptoKey::SetupKey(
keymaster_key_format_t key_format;
internal_keymaster_blob_t key_data;
+ LOG_FUNCTION_ENTRY;
+
memset(¶ms, 0x0, sizeof(internal_keymaster_key_param_set_t));
memset(&key_data, 0x0, sizeof(internal_keymaster_blob_t));
lRes = RetrieveParamsFromKeyblob((const keymaster_key_blob_t *)key_blob, &key_origin,
¶ms, &key_format, &key_data);
+ dbg_log("key_origin:%d\n", key_origin);
+
//KM_TAG_KEY_SIZE will default to the size of the key provided
- SetImportKeySize(key_data.data_length << 3);
+
if(key_origin == KM_ORIGIN_GENERATED) {
key_origin = (keymaster_key_origin_t)KM_ORIGIN_SETUP;
+ }else if(key_origin == KM_ORIGIN_IMPORTED){
+ SetImportKeySize(key_data.data_length << 3);
}
+
lRes = CreateKey(key_origin, (keymaster_key_param_set_t *)¶ms,
key_format, (keymaster_blob_t *)&key_data, key_blob, characteristics);
+
lRes = RecycleParamsMemory(¶ms, &key_data);
+ LOG_FUNCTION_EXIT(lRes);
+
return lRes;
}
@@ -854,14 +898,14 @@ keymaster_error_t CryptoKey::ValidateKeyParam(const keymaster_key_param_set_t& p
SetKeyActivationTime(params[index].date_time);
break;
case KM_TAG_ORIGINATION_EXPIRE_DATETIME:
- ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_ORIGINATION_EXPIRE_DATETIME\n", index);
+ ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_ORIGINATION_EXPIRE_DATETIME, %llu\n", index, params[index].date_time);
SetKeyOriginationExpireTime(params[index].date_time);
break;
case KM_TAG_CREATION_DATETIME:
ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_CREATION_DATETIME\n", index);
break;
case KM_TAG_USAGE_EXPIRE_DATETIME:
- ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_USAGE_EXPIRE_DATETIME\n", index);
+ ALOGD("ValidateKeyParam() params[%d].tag = KM_TAG_USAGE_EXPIRE_DATETIME, %llu\n", index, params[index].date_time);
SetKeyUsageExpireTime(params[index].date_time);
break;
case KM_TAG_MIN_SECONDS_BETWEEN_OPS:
@@ -922,9 +966,11 @@ keymaster_error_t CryptoKey::SetupKeyBuffer()
keymaster_error_t lRes = KM_ERROR_UNSUPPORTED_KEY_SIZE;
size_t uKeyBufSize = 0;
//A valid Key-size must be set by now
+ LOG_FUNCTION_ENTRY;
if (iKeySize > 0) {
lRes = KM_ERROR_OK;
if (iKey) {
+ dbg_log("delete key content\n");
delete iKey;
iKey = NULL;
}
@@ -934,6 +980,7 @@ keymaster_error_t CryptoKey::SetupKeyBuffer()
lRes = KM_ERROR_MEMORY_ALLOCATION_FAILED;
}
}
+ LOG_FUNCTION_EXIT(lRes);
return lRes;
}
diff --git a/keymaster/4.0/hal/syna_km_context.cpp b/keymaster/4.0/hal/syna_km_context.cpp
index d8b34d2..b8d4e52 100755
--- a/keymaster/4.0/hal/syna_km_context.cpp
+++ b/keymaster/4.0/hal/syna_km_context.cpp
@@ -763,17 +763,23 @@ keymaster_error_t SynaKMContext::Begin(keymaster_purpose_t purpose,
LOG_FUNCTION_ENTRY
//Find the crypto key that corresponds to key blob
+ LogHex("keyblob:", key->key_material, 16);
+
CryptoKey* pCryptoKey = iKeyList->Find(key);
if (!pCryptoKey) {
+ dbg_log("no key is found, set up key\n");
lRes = SetupKey((keymaster_key_blob_t*)key, &pCharacteristics);
}
pCryptoKey = iKeyList->Find(key);
if (pCryptoKey) {
keymaster_algorithm_t algo = pCryptoKey->GetAlgorithm();
+
CryptoOperation* pOp = CryptoOperation::CreateCryptoOperation(algo, purpose, &lRes);
+ dbg_log("CreateCryptoOperation return lRes = %d\n", lRes);
if (pOp) {
lRes = pOp->Init(pCryptoKey, in_params, out_params, operation_handle);
+ dbg_log("Init return lRes = %d\n", lRes);
if (lRes == KM_ERROR_OK) {
iOperationList->Add(pOp);
} else {
diff --git a/keymaster/4.0/hal/syna_km_util.cpp b/keymaster/4.0/hal/syna_km_util.cpp
index 07ac069..df59239 100755
--- a/keymaster/4.0/hal/syna_km_util.cpp
+++ b/keymaster/4.0/hal/syna_km_util.cpp
@@ -476,8 +476,11 @@ keymaster_error_t IsValidDigest(keymaster_algorithm_t algo, keymaster_digest_t d
//Check whether the given time has lapsed current time
bool VerifyTimeLapsed(uint64_t timestamp, uint32_t timeout)
{
- time_t givenTime = (timestamp + timeout) / 1000;
- return difftime(time(NULL), givenTime) > 0;
+ uint64_t givenTime = (timestamp + (uint64_t) timeout) / 1000;
+ uint64_t cur_time = (uint64_t) time(NULL);
+ dbg_log("timestamp[%llu], timeout:%u\n", timestamp, timeout);
+ dbg_log("giventime[%llu], curtime[%llu]\n", givenTime, cur_time);
+ return (cur_time > givenTime);
}
//HMAC Signature verification
diff --git a/keymaster/4.0/hal/syna_rsaoperation.cpp b/keymaster/4.0/hal/syna_rsaoperation.cpp
index 94e39a2..e83cf94 100755
--- a/keymaster/4.0/hal/syna_rsaoperation.cpp
+++ b/keymaster/4.0/hal/syna_rsaoperation.cpp
@@ -166,7 +166,13 @@ keymaster_error_t RsaOperation::InitOperation(const uint8_t* pKey, size_t uKeySi
{
keymaster_error_t lRes = KM_ERROR_OK;
uint64_t uPubExpo = iKey->GetPubExponent();
+
+ LOG_FUNCTION_ENTRY;
+
lRes = iImpl->InitRsaOperation(iPurpose, iPadding, iDigest, uPubExpo, pKey, uKeySize, &iHandle);
+
+ LOG_FUNCTION_EXIT(lRes);
+
return lRes;
}
|
|
|
Hi Sangmin, Please check the following fw /release_by_fxn/tmp/mantis1786 127|BFX-UA300:/ # getprop ro.vendor.vasott.version v540r1786-20231115 Thanks, Jason |
|
|
Hello, Jason, Thank you. I will test it. Anyway, could you please explain about initializing the private key procedure? Best Regards, Sangmin Choi. |
|
|
Hi Sangmin, the default value of property (persist.sys.update_apple_certificate) of new FW is 0 When update to this FW, we will check the following conditions sys.boot_completed=1 and persist.sys.update_apple_certificate=0 If both conditions are true, we will run the script to do "pm clear appletv's pagename" then set persist.sys.update_apple_certificate as 1 Thanks, Jason |
|
|
Hello, Jason, I checked the test firmware and I think it works correctly. I'm checking with SKB and let you know when it needs to push. Please keep the modifications until I get the confirmation from SKB. Thank you. Sangmin Choi. |
|
|
Hello, Jason, Please push all modifications to 541 branches. And, please add "[BPM-22652]" to prefix of commit message. Thank you. Sangmin Choi. |
|
|
Hi Sangmin, Push to UI541 Done 2023-11-17 09:34:59 | jason.tf.ling@fii-.. | 7800320 | vendor/synaptics/common | [BPM-22652] Fix wrong certificate of AppleTV 2023-11-17 09:34:06 | jason.tf.ling@fii-.. | f108fa5 | vendor/foxconn | [BPM-22652] renew AppleTv certificate [2/2] 2023-11-17 09:33:41 | jason.tf.ling@fii-.. | 72d9831 | device/synaptics/sequoia | [BPM-22652] renew AppleTv certificate [1/2] Thanks, Jason |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2023-08-03 17:25 | (ALTech) Sangmin Choi | New Issue | |
| 2023-08-03 17:25 | (ALTech) Sangmin Choi | Status | new => assigned |
| 2023-08-03 17:25 | (ALTech) Sangmin Choi | Assigned To | => (SW) Jacky Chiang |
| 2023-08-03 17:25 | (ALTech) Sangmin Choi | File Added: BFX-UA300_AppleTV_account_issue.txt | |
| 2023-08-03 17:26 | (ALTech) Sangmin Choi | Note Added: 0013817 | |
| 2023-08-03 17:26 | (ALTech) Sangmin Choi | Issue Monitored: (ALTech) Wooshin Kang | |
| 2023-08-03 17:26 | (ALTech) Sangmin Choi | Issue Monitored: (SW) Jason Ling | |
| 2023-08-08 11:38 |
|
Note Added: 0013838 | |
| 2023-08-08 11:38 |
|
Assigned To | (SW) Jacky Chiang => (ALTech) Sangmin Choi |
| 2023-08-08 11:47 |
|
Note Edited: 0013838 | |
| 2023-08-08 12:33 | (ALTech) Sangmin Choi | Note Added: 0013840 | |
| 2023-08-08 12:33 | (ALTech) Sangmin Choi | Assigned To | (ALTech) Sangmin Choi => (SW) Jason Ling |
| 2023-08-08 14:07 |
|
Note Added: 0013841 | |
| 2023-08-08 14:07 |
|
File Added: apple_pass.mp4 | |
| 2023-08-08 15:30 | (ALTech) Sangmin Choi | Note Added: 0013844 | |
| 2023-08-09 11:15 |
|
Note Added: 0013853 | |
| 2023-08-09 11:17 |
|
Assigned To | (SW) Jason Ling => (ALTech) Sangmin Choi |
| 2023-08-14 12:09 |
|
Note Added: 0013877 | |
| 2023-08-16 07:33 | (ALTech) Sangmin Choi | Note Added: 0013881 | |
| 2023-10-10 14:45 | (ALTech) Sangmin Choi | Note Added: 0014256 | |
| 2023-10-10 14:46 | (ALTech) Sangmin Choi | Note Added: 0014257 | |
| 2023-10-10 14:46 | (ALTech) Sangmin Choi | File Added: SampleApplication.zip | |
| 2023-10-18 16:18 | (ALTech) Sangmin Choi | Note Added: 0014338 | |
| 2023-10-18 16:54 |
|
Note Added: 0014340 | |
| 2023-10-19 13:19 | (ALTech) Sangmin Choi | Note Added: 0014348 | |
| 2023-10-19 13:19 | (ALTech) Sangmin Choi | File Added: App_Restart_Logs_UponForceQuit.txt | |
| 2023-10-19 13:19 | (ALTech) Sangmin Choi | File Added: SampleApplication_2.zip | |
| 2023-10-20 10:38 | (ALTech) Sangmin Choi | Note Added: 0014356 | |
| 2023-10-20 14:15 |
|
Note Added: 0014360 | |
| 2023-10-20 16:32 | (ALTech) Sangmin Choi | Note Added: 0014364 | |
| 2023-10-23 10:44 | (ALTech) Sangmin Choi | Note Added: 0014373 | |
| 2023-10-23 12:29 |
|
Note Added: 0014374 | |
| 2023-10-23 12:41 | (ALTech) Sangmin Choi | Note Added: 0014375 | |
| 2023-10-24 09:40 | (ALTech) Sangmin Choi | Note Added: 0014388 | |
| 2023-10-24 09:40 | (ALTech) Sangmin Choi | Assigned To | (ALTech) Sangmin Choi => (SW) Jason Ling |
| 2023-10-30 16:46 | (ALTech) Sangmin Choi | Note Added: 0014428 | |
| 2023-10-30 17:12 |
|
Note Added: 0014429 | |
| 2023-10-30 17:28 | (ALTech) Sangmin Choi | Note Added: 0014431 | |
| 2023-10-31 09:42 | (ALTech) Sangmin Choi | Due Date | => 2023-11-03 10:42 |
| 2023-10-31 09:44 | (ALTech) Sangmin Choi | Note Added: 0014433 | |
| 2023-10-31 20:19 |
|
Note Added: 0014440 | |
| 2023-11-03 13:46 |
|
Note Added: 0014464 | |
| 2023-11-03 14:09 | (ALTech) Sangmin Choi | Note Added: 0014465 | |
| 2023-11-06 16:12 |
|
Note Added: 0014481 | |
| 2023-11-13 13:59 | (ALTech) Sangmin Choi | Note Added: 0014514 | |
| 2023-11-13 13:59 | (ALTech) Sangmin Choi | File Added: 135759_c39a9af8.patch | |
| 2023-11-15 10:38 |
|
Note Added: 0014542 | |
| 2023-11-15 10:43 | (ALTech) Sangmin Choi | Note Added: 0014543 | |
| 2023-11-15 10:57 |
|
Assigned To | (SW) Jason Ling => (ALTech) Sangmin Choi |
| 2023-11-15 11:01 |
|
Note Added: 0014544 | |
| 2023-11-15 11:01 |
|
Note Edited: 0014544 | |
| 2023-11-15 17:00 | (ALTech) Sangmin Choi | Note Added: 0014550 | |
| 2023-11-17 07:41 | (ALTech) Sangmin Choi | Note Added: 0014570 | |
| 2023-11-17 09:35 |
|
Status | assigned => resolved |
| 2023-11-17 09:35 |
|
Resolution | open => fixed |
| 2023-11-17 09:35 |
|
Note Added: 0014573 | |
| 2023-11-17 10:00 | (ALTech) Sangmin Choi | Status | resolved => closed |