View Issue Details

IDProjectCategoryView StatusLast Update
0002061T99X171.00 SKB EagleSW Issuepublic2026-08-03 10:25
Reporter(ALTech) Younkwang Jung Assigned To(ALTech) JunGyu Kim Due Date2026-06-30 09:39
PrioritynormalSeveritys4-minorReproducibilityalways
Status closedResolutionfixed 
Summary0002061: [Smart3][UI552] BTS warning : recovery signed with VBMeta test key
DescriptionHi Hank

Smart3 15.552.46 BTS result warning was observed.
This warning was not observed on other manufacturer models.

I am worried that this warning will be suddenly changed to an alert in the future.
If it suddenly changes to alert, we cannot get Google approval.
so we need to be prepared for this warning

Please give me your opinion on how to deal with this warning.

Thank you
YK.Jung
TagsNo tags attached.
Attach Tags

Activities

(ALTech) Younkwang Jung

2026-01-09 09:48

developer  

image.png (204,571 bytes)   
image.png (204,571 bytes)   

(SW) Willin Deng

2026-01-09 16:07

developer   ~0017722

Hi Jung

3PL said that it would not become alert in the short term.
If Google requires a rectification within a certain period in the future,consider applying for waiver or replacing the key in stages.

(ALTech) Younkwang Jung

2026-01-13 13:52

developer   ~0017724

Hi Willing

Thank you for update
YK.Jung

(ALTech) JunGyu Kim

2026-06-08 15:58

developer   ~0017797

Hi Willin,

Based on the BTS results released today, it has been confirmed that this issue will be changed to an alert after 2026-08-06.
Since the deadline has not yet passed, there is no urgent need to fix it.

However, this issue must be resolved for future firmware builds.
I would like to inquire if there is a way to resolve this issue.

Thank you.
Kim
Image_20260608161959_345_1.jpg (149,432 bytes)   
Image_20260608161959_345_1.jpg (149,432 bytes)   

(SW) Willin Deng

2026-06-13 17:25

developer   ~0017798

Hi Kim,
The "3PL" feedback indicates that applying for a waiver may not guarantee approval.
It's worth submitting the application, but it's advisable to resolve this issue first.
The typical approach to updating a KEY involves locating its actual position and replacing it with a new KEY.
This is done by using two firmware versions to update the KEY for the user.
The first version is compatible with both the old and new KEYS, while the second version completely replaces the old KEY with the new one,
thereby minimizing the risk of entering RECOVER mode.

BR.
Willin

(ALTech) JunGyu Kim

2026-06-15 07:50

developer   ~0017799

Hi Willin,

1. Could you please provide guidance on how to ensure that both the existing key and the new key are compatible?

2. Since some customers may receive the OTA update very late, using this method might require maintaining compatibility between the two keys for a considerable amount of time.
In this case, it could become an issue if the Warning does not disappear from the BTS.

3. I would like to inquire if I can use the key located at the following path for the new key:
vendor/foxconn/android-certs

Thank you.
Kim

(ALTech) JunGyu Kim

2026-06-22 10:22

developer   ~0017801

Hi Willin,

Could you please check any updates on this issue?

Thank you.
Kim

(ALTech) JunGyu Kim

2026-06-29 10:45

developer   ~0017811

Hi Willin,

I was informed that a waiver is being requested from the 3PL regarding this ticket.
https://btracker-cns.fii-foxconn.com/vaas/view.php?id=2069#c17808

Since it has been discussed internally that we should also proceed with a waiver for Smart3,
I think it would be best to proceed with version 15.561.128, which recently approved Google xTS.

The link to the Google xTS results is as follows.
http://altserver01.duckdns.org/google_xts/self_mr_report/eagle_os12/15.561.128.zip

Please let me know if any requirements.

Thank you.
Kim

(SW) Willin Deng

2026-06-30 16:40

developer   ~0017812

Last edited: 2026-07-02 09:17

Hi Kim,

The waiver has been applied for 15.561.128.The issue url is as follows:
 
https://issuetracker.google.com/529577441

BR.
Willin

(SW) Willin Deng

2026-07-01 15:26

developer   ~0017813

Last edited: 2026-07-02 10:47

Hi Kim,

Google's reply is as follows.See attached file "[SHADOWED b_529641895] [BTS] New Inquiry_ _BFX-AT100___ VBMeta test key_ [529577441] - Issue Tracker.pdf".
 
As per the Partner Security Advisory—2025-05 (CVE-2025-48613 VBMeta Test Key) guidelines, partners must ensure that their VBMeta data structure is signed with their OEM release key and NOT an AOSP test key. Any data structures identified as being signed with AOSP test keys must be re-signed with the OEM release key. Android Security will require these changes for compliance with the 2026-03-05 SPL.

A potential workaround, which has been successfully explored by at least one partner with their SoC vendor, is to modify the Android Bootloader (ABL). The ABL can be updated to report the old, exposed key to KeyMaster/KeyMint while verifying the image with a new production key. This would allow for migration from the vulnerable key without requiring a factory reset.

BR.
Willin
google_reply_msg.png (162,268 bytes)   
google_reply_msg.png (162,268 bytes)   

(SW) Willin Deng

2026-07-02 10:48

developer   ~0017814

the issue info and reply

(ALTech) JunGyu Kim

2026-07-13 11:31

developer   ~0017823

Hi Willin,

Based on the 3PL response you provided, I contacted Amlogic Korea.
As a result of the inquiry, I was informed that the system would boot normally if only the signing key was changed, so I modified it as follows.

diff --git a/products/mbox/g12a/g12a.mk b/products/mbox/g12a/g12a.mk
index db7e643..d1b4a9f 100644
--- a/products/mbox/g12a/g12a.mk
+++ b/products/mbox/g12a/g12a.mk
@@ -97,12 +97,12 @@ ifeq ($(BUILD_WITH_AVB),true)
BOARD_AVB_ENABLE := true
#BOARD_BUILD_DISABLED_VBMETAIMAGE := true
BOARD_AVB_ALGORITHM := SHA256_RSA2048
-BOARD_AVB_KEY_PATH := external/avb/test/data/testkey_rsa2048.pem
+BOARD_AVB_KEY_PATH := vendor/foxconn/android-certs/foxconn_avb_release_key.pem
BOARD_AVB_ROLLBACK_INDEX := 0
BOARD_AVB_MAKE_VBMETA_IMAGE_ARGS += --prop dovi_hash:b00595345b44b13a3df532771168bb1af10c1a67d2c3e30cd6d51227f53dc338

ifneq ($(AB_OTA_UPDATER),true)
-BOARD_AVB_RECOVERY_KEY_PATH := external/avb/test/data/testkey_rsa2048.pem
+BOARD_AVB_RECOVERY_KEY_PATH := vendor/foxconn/android-certs/foxconn_avb_release_key.pem
BOARD_AVB_RECOVERY_ALGORITHM := SHA256_RSA2048
BOARD_AVB_RECOVERY_ROLLBACK_INDEX := $(PLATFORM_SECURITY_PATCH_TIMESTAMP)
BOARD_AVB_RECOVERY_ROLLBACK_INDEX_LOCATION := 2

The foxconn_avb_release_key.pem key was generated by me.

After proceeding with the upgrade, it is booting normally.
I also verified whether the signing key had changed using the command below.

[Before change key]
jgkim@dev2-server05:~/a12_smart3_561$ python3 external/avb/avbtool.py info_image --image out/target/product/BFX-AT100/vbmeta.img | grep Public
Public key (sha1): cdbb77177f731920bbe0a0f94f84d9038ae0617d
jgkim@dev2-server05:~/a12_smart3_561$ python3 external/avb/avbtool.py info_image --image out/target/product/BFX-AT100/recovery.img | grep Public
Public key (sha1): cdbb77177f731920bbe0a0f94f84d9038ae0617d

[After change key]
jgkim@dev2-server05:~/a12_smart3_561$ python3 external/avb/avbtool.py info_image --image out/target/product/BFX-AT100/vbmeta.img | grep Public
Public key (sha1): a840af6ec92ceea822b8f89e8250bae75b7ed5af
jgkim@dev2-server05:~/a12_smart3_561$ python3 external/avb/avbtool.py info_image --image out/target/product/BFX-AT100/recovery.img | grep Public
Public key (sha1): a840af6ec92ceea822b8f89e8250bae75b7ed5af

Could you please upload this BTS FW for check BTS warning or not?
FW : http://altserver01.duckdns.org/release_by_ALT/20260713_Smart3_BTS_Warning/k000c-561r1284_SU-20260713-BFX-AT100/SKB~BFX_AT100~BFX-AT100~12~STTC.220724.001~15.561.1284-20260713~user~release-keys.zip

Thank you.
Kim

(SW) Willin Deng

2026-07-14 08:27

developer   ~0017825

Hi Kim,
fingerprint: SKB/BFX_AT100/BFX-AT100:12/STTC.220724.001/15.561.1284-20260713:user/release-keys
The two warnings of public KEY signature have been removed, but a new warning about "Unregistered APK" has been added.

This issue currently does not have a planned enforcement date,below for the list of unregistered APKs of warnings:
com.skb.screencaster 69163578d0bc98804630cdf519800785b69203c8d1c0c63e77dc61619a300554,
org.chromium.trichromelibrary 32a2fc74d731105859e5a85df16d95f102d85b22099b8064c5d8915c61dad1e0,
com.google.android.webview.debug 32a2fc74d731105859e5a85df16d95f102d85b22099b8064c5d8915c61dad1e0,
com.android.companiondevicemanager f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.android.providers.media.module 81716cd45398f8f03db9d851fe42ec1b8de3bd163aa8111d51649ebc683e9619,
com.android.cts.ctsshim a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc,
com.android.cts.priv.ctsshim a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc,
com.android.providers.tv f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.android.printspooler f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.android.providers.media 81716cd45398f8f03db9d851fe42ec1b8de3bd163aa8111d51649ebc683e9619,
android.autoinstalls.config.skb.bfx_at100 f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.droidlogic.droidtvsettingsoverlay f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.droidlogic.overlay f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.google.android.overlay.gtvsconfig f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.android.networkstack.tethering.inprocess.droidlogic f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.droidlogic.ble f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.google.android.overlay.googlewebview f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0,
com.android.networkstack.tethering.droidlogic f10fe4d1ae8a3d32f1e63d91199730a8a2457c73c8196878ed77143fedbd8eb0

Additionally, have you attempted to upgrade this firmware?
I previously modified this line, and the Public key (sha1) was successfully changed, but after the upgrade, the OTT keeps rebooting at the startup screen.

BR.
Willin

(ALTech) JunGyu Kim

2026-07-23 10:13

developer   ~0017828

Hi Willin,

First, Could you please upload again this BTS FW for check BTS warning or not?
FW : http://altserver01.duckdns.org/release_by_ALT/20260713_Smart3_BTS_Warning/k000c-561r1285_SU-20260723-BFX-AT100/SKB~BFX_AT100~BFX-AT100~12~STTC.220724.001~15.561.1285-20260723~user~release-keys.zip

As you mentioned, I found that some devices does not boot when only the AVB Key is changed.
Therefore, following Amlogic's guide, I replaced the existing hardcoded key in the bootloader with the new key and confirmed that it boots normally.

Additionally, the firmware I sent last time generated the AVB Key based on the releasekey.pk8 key,
But this FW, a new key has been generated newely for the AVB Key.

However, I am not sure of the cause of the "Unregistered APK" issue regarding the specific apps you provided.
The apps you sent are seems PRESIGNED apps, and their signing keys have not been changed.
Is there a registration menu in APFE for these apps?

Thank you.
Kim

(SW) Willin Deng

2026-07-24 09:26

developer   ~0017829

Hi Kim,
all the warning is fixed by the FW (Fingerprint: "SKB~BFX_AT100~BFX-AT100~12~STTC.220724.001~15.561.1285-20260723~user~release-keys.zip").

BR.
Willin
image-2.png (157,710 bytes)   
image-2.png (157,710 bytes)   

(ALTech) JunGyu Kim

2026-08-03 10:25

developer   ~0017846

Hi Willin,

Thank you for support.
We plan to conduct tests in various cases, and we will let you know if any problems.

Kim

Issue History

Date Modified Username Field Change
2026-01-09 09:48 (ALTech) Younkwang Jung New Issue
2026-01-09 09:48 (ALTech) Younkwang Jung Status new => assigned
2026-01-09 09:48 (ALTech) Younkwang Jung Assigned To => Hank Huang (FXN)
2026-01-09 09:48 (ALTech) Younkwang Jung File Added: image.png
2026-01-09 09:48 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Jong-Hwa JUNG
2026-01-09 09:48 (ALTech) Younkwang Jung Issue Monitored: (ALTech) JunGyu Kim
2026-01-09 09:48 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Sangmin Choi
2026-01-09 09:48 (ALTech) Younkwang Jung Issue Monitored: (ALTech) SY Yoon
2026-01-09 09:48 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Wooshin Kang
2026-01-09 09:48 (ALTech) Younkwang Jung Issue Monitored: (PM) Sheila Tu
2026-01-09 09:48 (ALTech) Younkwang Jung Issue End Monitor: (ALTech) Jong-Hwa JUNG
2026-01-09 09:51 (ALTech) Younkwang Jung Issue Monitored: (SW) Willin Deng
2026-01-09 16:07 (SW) Willin Deng Note Added: 0017722
2026-01-09 16:07 (SW) Willin Deng Assigned To Hank Huang (FXN) => (ALTech) Younkwang Jung
2026-01-13 13:52 (ALTech) Younkwang Jung Note Added: 0017724
2026-06-08 15:58 (ALTech) JunGyu Kim Note Added: 0017797
2026-06-08 15:58 (ALTech) JunGyu Kim File Added: Image_20260608161959_345_1.jpg
2026-06-08 15:59 (ALTech) JunGyu Kim Assigned To (ALTech) Younkwang Jung => (SW) Willin Deng
2026-06-09 08:35 (ALTech) Younkwang Jung Due Date => 2026-06-30 09:39
2026-06-13 17:25 (SW) Willin Deng Note Added: 0017798
2026-06-15 07:50 (ALTech) JunGyu Kim Note Added: 0017799
2026-06-22 10:22 (ALTech) JunGyu Kim Note Added: 0017801
2026-06-29 10:45 (ALTech) JunGyu Kim Note Added: 0017811
2026-06-30 16:40 (SW) Willin Deng Note Added: 0017812
2026-07-01 15:26 (SW) Willin Deng Note Added: 0017813
2026-07-01 15:26 (SW) Willin Deng File Added: google_reply_msg.png
2026-07-02 09:17 (SW) Willin Deng Note Edited: 0017812
2026-07-02 09:23 (SW) Willin Deng Note Edited: 0017813
2026-07-02 10:47 (SW) Willin Deng Note Edited: 0017813
2026-07-02 10:48 (SW) Willin Deng Note Added: 0017814
2026-07-02 10:48 (SW) Willin Deng File Added: [SHADOWED b_529641895] [BTS] New Inquiry_ _BFX-AT100___ VBMeta test key_ [529577441] - Issue Tracker.pdf
2026-07-13 11:31 (ALTech) JunGyu Kim Note Added: 0017823
2026-07-14 08:27 (SW) Willin Deng Note Added: 0017825
2026-07-14 08:27 (SW) Willin Deng File Added: Screenshot from 2026-07-14 08-14-02.png
2026-07-14 08:27 (SW) Willin Deng File Added: Screenshot from 2026-07-14 08-13-57.png
2026-07-16 17:25 (SW) Willin Deng Assigned To (SW) Willin Deng => (ALTech) Younkwang Jung
2026-07-23 10:13 (ALTech) JunGyu Kim Note Added: 0017828
2026-07-24 09:26 (SW) Willin Deng Note Added: 0017829
2026-07-24 09:26 (SW) Willin Deng File Added: image-2.png
2026-08-03 10:25 (ALTech) JunGyu Kim Assigned To (ALTech) Younkwang Jung => (ALTech) JunGyu Kim
2026-08-03 10:25 (ALTech) JunGyu Kim Status assigned => closed
2026-08-03 10:25 (ALTech) JunGyu Kim Resolution open => fixed
2026-08-03 10:25 (ALTech) JunGyu Kim Note Added: 0017846