<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="/feed.xml" rel="self" type="application/atom+xml" /><link href="/" rel="alternate" type="text/html" /><updated>2026-08-07T19:16:28+00:00</updated><id>/feed.xml</id><title type="html">CalyxOS</title><subtitle>CalyxOS</subtitle><entry><title type="html">August 2026 Security update</title><link href="/news/2026/08/07/august-security-update/" rel="alternate" type="text/html" title="August 2026 Security update" /><published>2026-08-07T00:00:00+00:00</published><updated>2026-08-07T00:00:00+00:00</updated><id>/news/2026/08/07/august-security-update</id><content type="html" xml:base="/news/2026/08/07/august-security-update/"><![CDATA[<ul>
  <li>CalyxOS 7.2.4.20 - Android 16 - available for all supported devices</li>
  <li>August security update</li>
</ul>

<h3 id="rollout">Rollout</h3>

<table>
  <thead>
    <tr>
      <th>Release channel</th>
      <th>Date</th>
      <th>Notes</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Security express</td>
      <td>7 August, Friday</td>
      <td> </td>
    </tr>
    <tr>
      <td>Beta</td>
      <td>10 August, Monday</td>
      <td> </td>
    </tr>
    <tr>
      <td>Stable</td>
      <td>10 August, Monday</td>
      <td> </td>
    </tr>
  </tbody>
</table>

<h3 id="changelog">Changelog</h3>
<ul>
  <li>Chromium: 151.0.7922.71</li>
  <li>microG: v0.3.16.252432</li>
  <li>Calendar (Etar): v1.0.56</li>
  <li>Update all included apps</li>
  <li>Update translations</li>
  <li>Fix keyboard dictonary popup theme</li>
  <li>Remove the Disallow 2G toggle on devices that do not support toggling it</li>
  <li>Aperture: Force dark navigation bar in camera view</li>
  <li>Calculator: Fix button text size scaling</li>
  <li>DeskClock: Increase importance of all notifications so that they show on lockscreen</li>
  <li>Etar: Allow any day of the week to be set as the week start day</li>
  <li>Etar: Prevent Etar from overriding external calendar sync settings</li>
  <li>Etar: Use Storage Access Framework to avoid external storage permissions</li>
  <li>microG: Add support for Google Maps timeline</li>
  <li>microG: Fix Play Integrity issues</li>
  <li>microG: FIDO bug fixes and improvements</li>
</ul>

<h3 id="device-specific-changes">Device specific changes</h3>
<ul>
  <li>Fix eSIM installation on Pixel devices when microG is not used</li>
  <li>Update firmware/proprietary files for FP4, FP5, bangkk, fogo, fogos, and otter</li>
  <li>Enable FM Radio support on otter</li>
</ul>

<h2 id="note">Note</h2>

<div class="alert alert-info" style="margin-top: 3rem">
<ul>
  <li>
    <strong>Over-the-air(OTA) Updates:</strong>
    Starting from CalyxOS 7.2.2.0, [[CalyxOS updates =&gt; updates]] resume automatically over the air. No manual install of updates needed. However, if you would like to manually update your CalyxOS device, see our [[OTA installation instructions =&gt; ota-install]].
  </li>
  <li>
    <strong>Security Updates for Pixel devices:</strong>
    The <strong>Pixel 9a, 9 Pro Fold, 9 Pro XL, 9 Pro, 9, 8a, 8 Pro, 8, Fold, Tablet, 7a, 7 Pro, 7, 6a, 6 Pro, and 6 </strong>stock OSes follow a monthly release schedule in direct alignment with the AOSP security bulletin. However, Google has stopped publishing the source code for AOSP QPR1 and QPR3 releases. As a result, CalyxOS is not able to timely include updates of the proprietary components, such as the bootloader, modem, and vendor firmware, for versions based on those specific QPR branches. The CalyxOS releases for the above models only contain the latest fixes to the open-source components, such as the operating system and the Linux kernel. Proprietary components get updates as soon as the corresponding AOSP source code becomes available.
  </li>
  <li>
    <strong>Security Updates for non-Pixel devices:</strong>
    The <strong>Fairphone 5, 4, Motorola moto g 5G 2024, moto g84 5G, moto g34 / g45 5G, and SHIFTphone 8</strong> stock OSes follow a different security update release schedule, which is usually behind  AOSP updates by a month or two. The CalyxOS releases for these devices only contain the latest fixes to the open-source components. Proprietary components get updates as soon as the stock OS update becomes available.
  </li>
  <li>
    <strong>End-of-life:</strong>
    The <strong>Motorola moto g52, moto g42, moto g32, Pixel 5a (5G), 4a (5G), and 5</strong> are no longer being updated by the manufacturer, the CalyxOS updates for these devices only contain the fixes to the open-source components. Proprietary components no longer get updated.
  </li>
</ul>
</div>]]></content><author><name></name></author><summary type="html"><![CDATA[CalyxOS 7.2.4.20 - Android 16 - available for all supported devices August security update]]></summary></entry><entry><title type="html">CalyxOS is back – download release 7.2.2.0 with full maintenance support</title><link href="/news/2026/07/01/calyxos-official-release-is-back/" rel="alternate" type="text/html" title="CalyxOS is back – download release 7.2.2.0 with full maintenance support" /><published>2026-07-01T00:00:00+00:00</published><updated>2026-07-01T00:00:00+00:00</updated><id>/news/2026/07/01/calyxos-official-release-is-back</id><content type="html" xml:base="/news/2026/07/01/calyxos-official-release-is-back/"><![CDATA[<ul>
  <li>CalyxOS 7.2.2.0 is up online. This release will receive all future updates.</li>
  <li>If you haven’t previously installed 7.2.1.0 (test build) and want to start or continue using CalyxOS, you need to flash your phone and install 7.2.2.0.</li>
  <li>With CalyxOS releases back to normal, we will continue with other backlog issues. Join the Matrix channel for our progress and user support.</li>
</ul>

<p>Dear CalyxOS community members, we are excited to share the release of CalyxOS 7.2.2.0. This means CalyxOS is officially back from the hiatus! It has been an enduring journey for our team to resume CalyxOS releases, and we deeply appreciate all the support and solidarity we received from you along this journey, especially the latest voluntary testing you did with us. Below we are sharing some important notes for anyone planning to install or reinstall CalyxOS, along with our next steps as we work through a large backlog of issues.</p>

<h3 id="pro-tips-for-installing-calyxos-7220">Pro tips for installing CalyxOS 7.2.2.0</h3>

<p>If you are currently using an old CalyxOS release (6.10.10/20 or older) or any other Android OS, you will need to do a clean install of this latest CalyxOS release on your phone. Once you are done, all future updates will be automatically sent and installed over the air (OTA).</p>

<p>To get started, visit our <a href="https://calyxos.org/install/">installation page</a>, select the device model you want, and follow the different installation options to get the relevant guide and downloadable files you need.</p>

<p>Tools that can aid your installation:</p>
<ul>
  <li><strong><a href="https://calyxos.org/docs/guide/apps/seedvault/">Seedvault</a></strong>: can be used to backup and restore your data from other custom ROMs, including CalyxOS 6.10.10/20 and older releases.</li>
  <li><strong>CalyxOS Web Installer</strong>: each device-specific installation page offers multiple options to install CalyxOS. We recommend that you choose the Web Installer if it is available for your device. This is our web-based, step-by-step installation wizard to ease your installation process. Right now, the Web Installer only works for Pixel and Motorola devices. We hope to make it available for other supported devices in the future.</li>
  <li><strong>Device flasher</strong>: this works for all devices on Windows and Linux. If you cannot use the Web Installer, you can download the command line device flasher tool matching your desktop operating system. Simply choose the Windows or Linux options on the device-specific installation page.</li>
</ul>

<p>Please be aware, each installation method has different requirements. To avoid issues that could result in failed flashing or a bricked device, carefully read our notes on top of the installation page.</p>

<p>If you have previously installed CalyxOS 7.2.1.0 (test build), you will get 7.2.2.0 as an OTA update. No further action required to receive future updates.</p>

<h3 id="what-to-know-about-calyxos-7220">What to know about CalyxOS 7.2.2.0</h3>

<p>With this release, we are pleased to announce that CalyxOS has started supporting the SHIFTphone 8. You can find the full list of supported devices in our <a href="https://calyxos.org/docs/guide/device-support/">user documentation</a>.</p>

<p>As mentioned in the <a href="https://calyxos.org/news/2026/05/04/calyxos-progress-update-4/">test build release</a>, we have updated the <a href="https://calyxos.org/docs/guide/apps/">bundled apps</a> in the Setup Wizard and made a few temporary feature changes. We welcome any feedback about your experience. Here is <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items?sort=created_date&amp;state=opened&amp;label_name%5B%5D=Type%3A%3Abug&amp;label_name%5B%5D=android%3A%3A16&amp;first_page_size=100">a list of open issues</a> in case you run into the same problem.</p>

<h3 id="our-work-so-far">Our work so far</h3>

<p>CalyxOS 7.2.2.0 is signed by us using <a href="https://calyxos.org/news/2026/02/10/calyxos-hsm-signing/">a new HSM-based, open-source signing solution</a> we designed to enhance the security of the entire signing process, ensure redundancy, and remove single points of failure. You can verify CalyxOS 7.2.2.0 and future builds following <a href="https://calyxos.org/install/verify/">these instructions</a>. For anyone who is interested, the security audit report of the HSM provisioning ceremony script can be found <a href="https://github.com/trailofbits/publications/blob/master/reviews/2026-01-calyx-hsm-provisioning-ceremony-scripts-securityreview.pdf">here</a>.</p>

<p>In addition, we also went through significant infrastructure improvements. In particular, we have set up a cleaner server structure to streamline each release. In response to Google’s less frequent AOSP source code releases, our team developed scripts to reduce the overhead in applying monthly patches and updates. Please keep in mind, additional manual steps are still needed to compensate for AOSP changes, such as requesting and storing kernel sources with each update. Currently, our lead engineer is continuing the maintenance of the base device trees for both LineageOS and CalyxOS to bridge the gap created by the absence of Google Pixel device trees.</p>

<h3 id="what-next">What next</h3>

<p>Starting from CalyxOS 7.2.2.0, we plan to resume security and feature updates to the best of our ability. We are also working toward increasing transparency around the CalyxOS development road map through public information sharing and documentation. Our <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items">GitLab issue tracker</a> remains the main channel to keep track of our progress and the best place where you help us keep track of issues, either bugs or feature requests.</p>

<p>As many of you may have been expecting, Android 17 has launched earlier this month. Our team is in the early stages of porting it to our supported devices. We will soon share a timeline for releasing CalyxOS 8 with Android 17.</p>

<p>Another update will be for our <strong>Matrix community channels</strong>. All of our current Matrix rooms are on older versions, resulting in bugs and security concerns. In light of these issues, we will be upgrading our Matrix rooms to <a href="https://spec.matrix.org/v1.16/rooms/v12/">version 12</a> about a week from now. We will also create a new Matrix Space to ease future upgrades. Current room members will receive notifications about this upgrade and migration. We apologize for any inconvenience and hope this one week notice gives everyone time to prepare.</p>

<p>Last but not least, we want to share some updates on our team: Aayush, our core developer working on Aurora Store, will be leaving for another opportunity. Aayush’s contributions to CalyxOS and Aurora Store have been invaluable, and we are sure he will continue to shine in his next journey. At the same time, we welcome Habib, who will be in Nat’s place to support our infrastructure needs and improvements moving forward. We are very grateful for Nat’s contributions and hard work during his time building new CalyxOS server infrastructure. He has laid a solid foundation for CalyxOS releases, which we are sure Habib will build on.</p>

<h3 id="help-us-improve">Help us improve</h3>

<p>We can’t be more grateful for the enthusiasm you brought with all the voluntary testing on 7.2.1.0. Most of the conversations from our community happen on our <a href="https://calyxos.org/community/#main-channels">Matrix channels</a> and our main issue tracker on <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items">GitLab</a>. We also have a subreddit and other social media accounts, listed on our <a href="https://calyxos.org/community/">community page</a>. We look forward to meeting you there!</p>]]></content><author><name></name></author><summary type="html"><![CDATA[CalyxOS 7.2.2.0 is up online. This release will receive all future updates. If you haven’t previously installed 7.2.1.0 (test build) and want to start or continue using CalyxOS, you need to flash your phone and install 7.2.2.0. With CalyxOS releases back to normal, we will continue with other backlog issues. Join the Matrix channel for our progress and user support.]]></summary></entry><entry><title type="html">CalyxOS progress report - our test build with Android 16 is here</title><link href="/news/2026/05/04/calyxos-progress-update-4/" rel="alternate" type="text/html" title="CalyxOS progress report - our test build with Android 16 is here" /><published>2026-05-04T00:00:00+00:00</published><updated>2026-05-04T00:00:00+00:00</updated><id>/news/2026/05/04/calyxos-progress-update-4</id><content type="html" xml:base="/news/2026/05/04/calyxos-progress-update-4/"><![CDATA[<ul>
  <li>CalyxOS Android 16 test build (7.2.1.0) is released for community testing</li>
  <li>Read the known issues, notes, and recommendations about this release carefully</li>
  <li>Join our Matrix CalyxOS Testers room to help us test CalyxOS to prepare for the official release</li>
</ul>

<p>Dear CalyxOS community, we are (almost) back. We are excited to share that test builds of CalyxOS are available to our community testers. Below are some details on this release and planned next steps.</p>

<p>These test builds are specifically for people who want to give us early feedback and help us do thorough testing. You might encounter bugs and we recommend that you do not use this test build for your primary device. We plan to follow this test release with an official release that contains fixes and improvements very soon if we find no major blocking issues during this round of testing.</p>

<h3 id="about-the-calyxos-test-build-7210">About the CalyxOS test build (7.2.1.0)</h3>

<p>Signed with the new signing solution earlier discussed in <a href="https://calyxos.org/news/2026/02/10/calyxos-hsm-signing/">our talk at FOSDEM</a>, 7.2.1.0 is ported to Android 16 QPR2.</p>

<p>We have created test builds for the following devices:</p>
<ul>
  <li>Pixels
    <ul>
      <li>9, 9 Pro, 9 Pro Fold, 9 Pro XL, 9a</li>
      <li>8, 8 Pro, Pixel Fold, Pixel Tablet, 8a</li>
      <li>7, 7 Pro, 7a</li>
      <li>6, 6 Pro, 6a</li>
      <li>5, 5a (5G)</li>
      <li>4a (5G)</li>
    </ul>
  </li>
  <li>Fairphone 4, 5</li>
  <li>Motorola
    <ul>
      <li>moto g 5g (2024), moto g84, moto g34/45</li>
      <li>moto g52, moto g42, moto g32</li>
    </ul>
  </li>
</ul>

<p>A note on kernel patches: Pixel 6 and newer Pixel devices are fully patched. All other devices are missing certain Qualcomm patches, which we are actively working to pick up alongside other upstream patches and the <a href="https://source.android.com/docs/security/bulletin/2026/2026-05-01">May Android Security Bulletin (ASB)</a>. We wanted to get this out as quickly as possible and official releases will include more complete patchsets as usual.</p>

<h3 id="changes-to-our-bundled-apps">Changes to our bundled apps</h3>

<p>CalyxOS ships with a set of free-and-open-source apps that can be installed in the Setup Wizard or afterwards without network access. In 7.2.1.0, the bundled apps included in CalyxOS are:</p>

<ul>
  <li>F-Droid Basic 2.0 alpha (v 2.0-alpha8): this newly revamped version will replace the old F-Droid Basic app</li>
  <li>Aurora Store (v 4.7.5)</li>
  <li>Breezy Weather (v 6.1.3_freenet)</li>
  <li>GCam Photos Preview (v 1.1)</li>
  <li>Signal (v 8.7.3)</li>
  <li>OnionShare (v 0.2.3-beta)</li>
  <li>Tor Browser for Android (v 15.0.10 (140.10.0esr))</li>
  <li>Tor VPN Beta (v 1.6.0Beta-arm64-v8a): this new Tor VPN project will replace the Orbot app</li>
  <li>Riseup VPN (v 1.5.3)</li>
  <li>OONI Probe (v 6.0.1)</li>
  <li>CoMaps (v 2026.04.07-8-FDroid): this app will replace Organic Maps</li>
  <li>Scrambled Exif (v 1.7.14)</li>
  <li>Thunderbird (v 18.0)</li>
  <li>DAVx5 (v 4.5.10-ose)</li>
</ul>

<p>CalyxVPN is temporarily excluded from this list as the organization rebuilds the capacity and infrastructure to maintain and develop this app.</p>

<h3 id="temporary-feature-changes">Temporary feature changes</h3>

<p>Android 16 was a major port for CalyxOS with significant changes from Android 15. We are still undergoing full testing of features, device functionality, and app compatibility. Moving forward, it is our intention to ensure that every feature we ship works as expected, especially those critical safety features.</p>

<p>To that end, we decided to omit the <em>Panic button</em> feature in this release until we revist the much needed technical and user experience updates it requires.</p>

<p>Additionally, we are shipping <em>CalyxOS Chromium</em> with less features, which you can read more about below.</p>

<p>We are continually updating the list of known issues as more testing is completed. You can find this list in <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items?sort=created_date&amp;state=opened&amp;label_name%5B%5D=Type%3A%3Abug&amp;label_name%5B%5D=android%3A%3A16&amp;first_page_size=100">our GitLab repo</a>.</p>

<h3 id="our-note-on-calyxos-chromium">Our note on CalyxOS Chromium</h3>

<p>In this latest test release, Chromium ships on the major stable version, 147.0147.0.7727.101, with a subset of its previous <a href="https://gitlab.com/CalyxOS/platform_external_calyx_chromium/-/blob/main/build/01-cromite_patches_list.txt">Cromite</a> and <a href="https://gitlab.com/CalyxOS/platform_external_calyx_chromium/-/blob/main/build/02-calyx_patches_list.txt">Calyx</a> patches. To select these patches, we  focused on the essentials:</p>
<ul>
  <li>deGoogling the browser</li>
  <li>telemetry point removal</li>
  <li>WebRTC disabling</li>
</ul>

<p>Notably, we have excluded some features we previously shipped (e.g. adblocker) to make it easier and faster to port to the latest Chromium version and ship Android 16. As we continue to release CalyxOS builds, we will incorporate more features and patches based on community feedback and team capacity.</p>

<h3 id="new-branding">New branding</h3>

<p>Beginning in late 2024, there has been an organization-wide effort to clarify our mission and rebuild our brand to fairly reflect our identity and values in an uplifting visual language. This includes the rebranding of CalyxOS, our vision for a privacy-respecting, security-oriented Android OS.</p>

<p>In this latest release of CalyxOS, you will have a sneak peek of its new visual identity. Based the latest <a href="https://m3.material.io/">Material You</a> design system, we created a fresh look for CalyxOS with custom designed elements from logo boot animation to iconography. We invite you to join this journey in improving the visual language and user interface for CalyxOS by sending us your feedback.</p>

<h3 id="how-to-test-and-give-feedback">How to test and give feedback</h3>

<p>This release of CalyxOS is intended for our community testers. When you try to install and run this build, you might encounter bugs, unexpected crashes, or odd behavior. It is not prepared for your primary daily device at this time.</p>

<p>If you are still interested in helping us test CalyxOS, yay! Please join the <a href="https://app.element.io/#/room/#calyxos-testers:matrix.org">CalyxOS Matrix Tester’s room</a>. You can find full instructions for testers in the pinned message, including links to our device flasher and CalyxOS builds, installation instructions, and a list of known issues. To send us your feedback, please message us directly in this channel or create a new issue in <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items?sort=created_date&amp;state=opened&amp;first_page_size=20">our GitLab repo</a>.</p>]]></content><author><name></name></author><summary type="html"><![CDATA[CalyxOS Android 16 test build (7.2.1.0) is released for community testing Read the known issues, notes, and recommendations about this release carefully Join our Matrix CalyxOS Testers room to help us test CalyxOS to prepare for the official release]]></summary></entry><entry><title type="html">CalyxOS progress report - a detailed breakdown</title><link href="/news/2026/04/01/calyxos-progress-update-3/" rel="alternate" type="text/html" title="CalyxOS progress report - a detailed breakdown" /><published>2026-04-01T00:00:00+00:00</published><updated>2026-04-01T00:00:00+00:00</updated><id>/news/2026/04/01/calyxos-progress-update-3</id><content type="html" xml:base="/news/2026/04/01/calyxos-progress-update-3/"><![CDATA[<ul>
  <li>Responses to popular questions from our community, such as “What exactly happened with the signing process” and “What is still needed for CalyxOS to be back”</li>
  <li>Further breakdown of the impact of AOSP changes going forward</li>
  <li>What you can do to help us bridge development gaps</li>
</ul>

<p>This update tries to clarify some of the ongoing confusions in the discourses across our community channels. We will continue our effort to address future questions in our regular posts and direct responses from our team members. If you have suggestions on how we can improve this effort, please feel free to reach out on <a href="https://calyxos.org/community/#main-channels">Matrix</a> or <a href="https://calyxos.org/community/#reddit">Reddit</a>.</p>

<h3 id="on-calyxos-signing-process">On CalyxOS signing process</h3>

<p>Following the completion of the <em>provisioning ceremony</em> in February, we have generated the needed release and component signing keys. More tests are still needed to ensure the keys will work as expected. So far, we have successfully signed some components (e.g. GCamPhotosPreview). We will be moving to signing the entire build when we have them ready.</p>

<p>For those interested in downloading and testing GCamPhotosPreview with the new CalyxOS signing keys, you can download the APK file <a href="https://gitlab.com/CalyxOS/calyx-fdroid-repo-apks/-/tree/main/GCamPhotosPreview">here</a>.</p>

<h3 id="on-calyxos-release-server">On CalyxOS release server</h3>

<p>As reported in <a href="https://calyxos.org/news/2026/02/24/calyxos-progress-update-2/">our last progress update</a>, we have set up a new release server and Gerrit server for CalyxOS. There is ongoing work to make sure the new release server is up and running with regular backups and maintenance. From now on, CalyxOS installations will only be pinging the new domain, <strong>https://release.calyxos.org</strong>, to check for updates. We recommend <strong>always running the most up-to-date version available</strong> to ensure the CalyxOS on your device is getting updates without interference. The old domain of the past release server, https://release.calyxinstitute.org, will no longer be updated and eventually phase out as an archival site for old images.</p>

<p>The old release server has been offline and due to the <a href="https://www.npr.org/2026/03/29/nx-s1-5765454/tsa-paychecks-ice-airports-tom-homan">ongoing travel risks across the United States</a>, the dev team hasn’t been able to travel to the physical data center yet. While we are working on manual disk recovery, data on this server remains unreachable. If you have copies of past CalyxOS builds and would like to help us rebuild our release archive, please visit our dedicated GitLab issue: <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items/3466">Release files recovery</a>. You can check which factory images and files are still missing and upload the missing files. We are grateful for your contribution.</p>

<h3 id="on-calyxos-code-review">On CalyxOS code review</h3>

<p>While planning to migrate our old Gerrit server to a new, faster one, the old server went offline. It took a few weeks before the IT team could recover files as a result of the shortage in IT staffing. This set the CalyxOS development back for a few weeks. But we have managed to set the new server up with fully recovered data and measures to prevent similar incidents from happening in the future.</p>

<p>The new Gerrit server is up on the same domain, <a href="https://review.calyxos.org/">https://review.calyxos.org/</a>. You can always review our work on Android 16 QPR2 in real time there.</p>

<p>In this round of server upgrade, we had to sort through years of bulk data, including historical builds, change records, large binary files, and so forth on multiple platforms and locations. Migrating such size of data while creating new server structure has been intensely time-consuming despite our intention to bring back CalyxOS as soon as possible.</p>

<p>We wish we could move faster to bring CalyxOS back, but for a small team like us, cleaning up our development infrastructure for a fresh start while catching up with the fast-changing AOSP updating cycle could end up with many unexpected slowdowns. One thing we can be certain for sure, the team is committed to bringing CalyxOS back with a more efficient development environment. That is why we are working to make a test build with Android 16 available as soon as possible.</p>

<h3 id="on-android-16-qpr2-and-the-impact-of-aosp-release-changes">On Android 16 QPR2 and the impact of AOSP release changes</h3>

<p>Back in January, Google made an unexpected announcement that AOSP source code would <a href="https://web.archive.org/web/20260106233758/https://source.android.com/">only be published in Q2 and Q4 instead of quarterly</a>. This came after a series of significant changes in the previous year: <a href="https://web.archive.org/web/20250327185406/https://source.android.com/docs/whatsnew/site-updates#aosp-changes">moving the entire AOSP development to behind closed doors</a>, <a href="https://calyxos.org/news/2025/06/11/android-16-plans/">terminating public sharing of device-specific source code for Pixels</a>, and <a href="https://web.archive.org/web/20250913121908/https://www.androidauthority.com/android-risk-based-security-updates-3597466/">reducing the frequency of the security patch release from quarterly to monthly</a>. Effectively, QPR1 and QPR3 releases after January 2026 will be exclusive to Pixel devices on the stock OS and thus not accessible publicly. This change in release cadence means the proprietary blobs will always be newer than the available AOSP sources, which will often create conflicts. As a result, our ability to timely integrate any security updates from QPR1 and QPR3 Stock Pixel OS updates will be severely limited.</p>

<p>Not just CalyxOS, all AOSP-based OS development teams have been forced to spend an immense amount of extra time and resources to track and sync code changes before they can release any new builds. Restricting early or even timely access to source code is a major departure from the guiding principles of free and open-source software. Not only do these changes make it more difficult for custom ROM builders, they also harm the freedom to choose what to install on your devices or who you want to share your personal data with.</p>

<p>Since June 2025, CalyxOS and LineageOS have been working on tooling that allows easier and faster updates of Pixel devices in a combined effort as the two projects share developers and resources. A lot of these tools are also beneficial for new device bringup. As always, our work is publicly available for community use and review:</p>
<ul>
  <li><a href="https://review.lineageos.org/q/project:LineageOS/android_tools_extract-utils+status:merged">proprietary files extract improvements</a></li>
  <li><a href="https://review.lineageos.org/q/project:LineageOS/scripts+status:merged+(message:rro+OR+message:dev)">scripts to extract SEPolicy and RRO overlays from stock OS</a></li>
</ul>

<p>We have also been maintaining the base device trees together with LineageOS after the Pixel device tree source code was made publicly unavailable. You can find our latest updates on device support maintenance and Android 16 QPR2 bringup on <a href="https://review.lineageos.org/q/owner:mkbestas@lineageos.org+status:merged">LineageOS code review</a>.</p>

<p>The majority of CalyxOS features have been ported to Android 16 QPR2. However, we have encountered a few broken changes that we are actively working to fix or reimplement. Depending on the complexity of the issue and the time needed to resolve it, some features may be temporarily unavailable in the first testing releases. Taking the CalyxOS Chromium browser for example, to ensure we can ship updates of the latest stable versions of Chromium in time, some features of CalyxOS Chromium may be excluded until we have more capacity in our team.</p>

<h3 id="what-you-can-do-to-help">What you can do to help</h3>

<p>As mentioned above, here are a few things you can help us with to prevent further delay of the next CalyxOS release:</p>
<ol>
  <li>Test GCamPhotosPreview with the new CalyxOS signing keys. The APK file is available for download <a href="https://gitlab.com/CalyxOS/calyx-fdroid-repo-apks/-/tree/main/GCamPhotosPreview">here</a>.</li>
  <li>Join our testers channel on Matrix. We would love to get the community’s help in early beta testing on our upcoming release of CalyxOS. Shortly we will be reaching out directly in the <a href="https://app.element.io/#/room/#calyxos-testers:matrix.org">tester’s channel</a> with details on how to do so. Feel free to join this channel and share your thoughts so that we can polish the testing process.</li>
  <li>Help us improve our communications. Please share your ideas on <a href="https://calyxos.org/community/#main-channels">our Matrix channel</a> or <a href="https://calyxos.org/community/#reddit">subreddit</a>.</li>
  <li>Upload old CalyxOS release files if you have any. You can check out our <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items/3466">Gitlab issue #3466</a> for details required and steps on how to get started.</li>
</ol>]]></content><author><name></name></author><summary type="html"><![CDATA[Responses to popular questions from our community, such as “What exactly happened with the signing process” and “What is still needed for CalyxOS to be back” Further breakdown of the impact of AOSP changes going forward What you can do to help us bridge development gaps]]></summary></entry><entry><title type="html">CalyxOS progress report - final steps to set CalyxOS back on track</title><link href="/news/2026/02/24/calyxos-progress-update-2/" rel="alternate" type="text/html" title="CalyxOS progress report - final steps to set CalyxOS back on track" /><published>2026-02-24T00:00:00+00:00</published><updated>2026-02-24T00:00:00+00:00</updated><id>/news/2026/02/24/calyxos-progress-update-2</id><content type="html" xml:base="/news/2026/02/24/calyxos-progress-update-2/"><![CDATA[<ul>
  <li>We have completed the setup of the new HSM-based signing process</li>
  <li>Current work focuses on a new release server and Gerrit instance</li>
  <li>A new dedicated sysadmin has joined the team</li>
</ul>

<p>Welcome to our first CalyxOS progress report of 2026. January was a busy month for the team: finalizing provisioning ceremony operations and scripts, establishing the new signing infrastructure with our newly onboarded CalyxOS sysadmin, and attending <a href="https://fosdem.org/2026/">FOSDEM2026</a>. We are grateful for the questions, concerns, and suggestions shared with us from our community, and sincerely apologize for any delayed response and update.</p>

<h3 id="calyxos-new-hsm-based-signing-infrastructure">CalyxOS’ new HSM-based signing infrastructure</h3>

<p>Throughout January, the CalyxOS team has been focusing on the implementation of the new signing infrastructure to facilitate and streamline our future development. With the completion of the provisioning ceremony, we are now equipped with the new signing toolkit built by us and <a href="https://github.com/trailofbits/publications?tab=readme-ov-file#cryptography-reviews">audited by Trail of Bits</a>. This new signing infrastructure achieved two major goals:</p>
<ul>
  <li>It resolved the potential bottlenecks and security risks that come with relying on a single person, machine, or HSM to sign every release.</li>
  <li>It reduced the chance of compromise of the signing keys by preventing exporting them in plaintext.</li>
</ul>

<p>You can read our <a href="https://calyxos.org/news/2026/02/10/calyxos-hsm-signing/">deep dive into the whole process</a> or watch <a href="https://fosdem.org/2026/schedule/event/AV8MA9-open-source-hsm-based-aosp-signing/">our talk at FOSDEM2026</a>.</p>

<h3 id="setting-up-new-release-server-and-gerrit-code-review">Setting up new release server and Gerrit Code Review</h3>

<p>We are now at the final step to resume CalyxOS: stabilizing the release cycle for our 25+ supported devices with the upgraded development infrastructure. To give an example, our release server upgrade has been in the backlog for more than 18 months. After a thorough inspection over the past few months, we came to the conclusion that our Gerrit and release servers should be set up with easier, regular backups to protect the project from server-side incidents. We are now migrating the CalyxOS release server to the organization’s Vultr instance along with the web server that is hosting the CalyxOS website. As a result, at the moment you might encounter downtime or missing objects if you are syncing CalyxOS sources. You can find more information about the organization’s larger infrastructure revamp <a href="https://calyx.org/news/2025/update-on-member-portal-and-data">here</a>.</p>

<h3 id="dedicated-expanded-systems-administrator-support">Dedicated, expanded Systems Administrator support</h3>

<p>More good news: we are pleased to have Nat Meysenburg supporting the CalyxOS system admininstration work. Nat joined our team at the beginning of 2026 and has been playing an instrumental role in our infrastructure modernization from server management redesign to code documentation. With Nat as our new member, we are steadily rebuilding the team capacity with a much more refined workflow.</p>]]></content><author><name></name></author><summary type="html"><![CDATA[We have completed the setup of the new HSM-based signing process Current work focuses on a new release server and Gerrit instance A new dedicated sysadmin has joined the team]]></summary></entry><entry><title type="html">Lessons from CalyxOS signing process redesign</title><link href="/news/2026/02/10/calyxos-hsm-signing/" rel="alternate" type="text/html" title="Lessons from CalyxOS signing process redesign" /><published>2026-02-10T00:00:00+00:00</published><updated>2026-02-10T00:00:00+00:00</updated><id>/news/2026/02/10/calyxos-hsm-signing</id><content type="html" xml:base="/news/2026/02/10/calyxos-hsm-signing/"><![CDATA[<ul>
  <li>This post is based on the <a href="https://fosdem.org/2026/schedule/event/AV8MA9-open-source-hsm-based-aosp-signing/">talk</a> our team gave at FOSDEM 2026.</li>
  <li>It provides a deep dive into our HSM-based signing redesign.</li>
  <li>Video recording of this talk is available <a href="https://video.fosdem.org/2026/ub4132/AV8MA9-open-source-hsm-based-aosp-signing.av1.webm">here</a>.</li>
</ul>

<p><img src="/assets/images/fosdem2026-hsm.png" alt="Image by JeroenHeijmans drawn at FOSDEM" width="90%" /></p>

<p>Image created by <a href="https://mastodon.social/@jeroenheijmans/115991012006835253">Jeroen Heijmans</a></p>

<h3 id="why-are-we-using-a-hsm">Why are we using a HSM?</h3>

<p>Code signing is commonly used to cryptographically verify the origin of software. A typical Android build consists of many individually signed pieces, which requires a significant amount of signing keys. Among these keys, the most important is used for <a href="https://source.android.com/docs/security/features/verifiedboot">verified boot</a>, which establishes a full chain of trust for all parts of the operating system.</p>

<p>Each key comes in two parts: the certificate and the private key. Developers use the private keys to make the cryptographic signatures, which need to be stored somewhere. This is typically a file on a storage medium. However, if anyone gets a copy of that file they can make valid signatures indefinitely and there is no way to stop them. It is impossible to verify where there are any copies of the key file, where they exist, or who has access to them. That is quite a risk. It also makes giving more than one person access to the keys quite challenging and thus is bad for your <a href="https://en.wikipedia.org/wiki/Bus_factor">bus factor</a>.</p>

<p>To improve the security, you can store keys in special hardware security modules (HSMs) instead of files on a computer. These modules use tamper-resistant storage hardware that makes it extremely hard to extract private keys without authentication. Even though it may be possible for powerful actors, such as nation-state intelligence, to extract key material if they gain physical access to the module, a HSM is still much more secure than storing keys as files on a computer.</p>

<p>A common use-case for HSMs is to simplify and automatize signing of build artifacts in a <a href="https://en.wikipedia.org/wiki/Continuous_integration">continuous integration</a> environment (CI). An attacker that compromises the CI machine could make malicious signatures. If you stored your signing key in a file that is extractable in plaintext, you have no choice but to generate new signing keys. But with a HSM, if you detect the breach, you can stop the attacker by preventing their access to the HSM.</p>

<p>Note that for now, CalyxOS has no plans to automate signing in this way. We will start with manual signing on a dedicated and secured machine where the HSM is only connected when needed.</p>

<h3 id="defining-criteria-for-secure-signing-operations">Defining criteria for secure signing operations</h3>

<p>By now, it is evident why new keys were needed; generating fresh keys gave us a clean slate with no unknown copies floating around, and allowed us to fully control the redesign and safety of our new signing solution. Next, we defined the criteria for the hardware backing our HSM solutions; you can find the criteria in <a href="https://calyxos.org/news/2025/11/10/calyxos-progress/">our November 2025 community update</a>. This set of criteria helped us reach our goals in three categories: <strong>security</strong>, <strong>operational practicality</strong>, and <strong>transparency</strong>. Many solutions, while meeting our security requirements, were not immediately available, financially affordable, auditable, or aligned to our organizational mission to promote and advance open-source tech.</p>

<p>Our process of evaluating options for the secure signing operation involved many discussions and trade-offs until we could make technical decisions. We looked into cloud-based HSMs, such as the Amazon Cloud HSM, enterprise-grade appliances, such as Thales Luna HSMs and Entrust nShield, and more affordable options, such as Nitrokey NetHSM. Also considered were smaller hardware dongles, such as the YubiHSM 2 and the Nitrokey HSM 2.</p>

<p>We decided to start with a simpler, HSM based, intermediate solution with a quick startup path that would let us soon start signing releases with new keys. That being said, we built in a migration path to a better or final signing solution.</p>

<p>In the end, we decided to start with the YubiHSM 2.</p>

<h3 id="key-wrapping-a-secure-way-to-manage-keys-with-limited-storage-space">Key wrapping: A secure way to manage keys with limited storage space</h3>

<p>It is worth noting that YubiHSM 2 has very limited storage space. It cannot fit all the signing keys required to sign our builds since we use a unique key for each device and different components. This issue is not unique to CalyxOS, it also applies to other projects that need lots of keys,
e.g. <a href="https://f-droid.org/">F-Droid</a>.</p>

<p>Thankfully, there is a solution for this problem called key wrapping. Keys that don’t fit on the HSM can be stored outside, encrypted. When you need to use them, you can import them into the HSM and decrypt them inside. The key that encrypts and decrypts the signing key set, called the <em>wrap key</em>, is always stored securely inside the HSM. This way, signing keys are never available in plaintext outside of the HSM.</p>

<h3 id="key-backup-why-and-how">Key backup: Why and how?</h3>

<p>When using HSMs, there is always a possibility they might break, fail, or get stolen, necessitating a plan to securely backup the keys. The actual signing keys are only available outside of the HSM in encrypted form, so you can back them up in the same way as you back up other files. Still, for the signing keys to be useful, we also need the <em>wrap key</em>, which is only available inside the HSM. Of course, a plaintext backup of the wrap key needs to be avoided, because it re-introduces all the same problems the HSM was supposed to solve.</p>

<p>The best option we found was <a href="https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing">Shamir’s Secret Sharing (SSS)</a>. This sharing algorithm was first developed in 1979. With this technique, we split the wrap key up into several parts, also known as shards. The wrap key could only get reconstructed when a pre-defined number of shards were present. We opted for five shards with a threshold of three shards required to recover the wrap key. Instead of relying on one person to securely back up private keys, we rely on a group of three out of five people to keep each of their shards safe and only ever combine these in a special ceremony.</p>

<h3 id="key-provisioning-ceremony">Key provisioning ceremony</h3>

<p>Somehow, the key material needs to get into the HSM. This could be for restoring a wrap key backup as stated above or when generating the initial key material. Unfortunately, the YubiHSM 2 doesn’t have SSS implemented in its firmware and even the <a href="https://github.com/Yubico/yubihsm-setup/blob/68bf3c7aa2d5c7e3efb05af471fafb551fa84e11/src/main.rs#L481">official setup utility</a> briefly holds the wrap key in memory, splits it into shards, and imports it back into the HSM. So for both cases, we need a secure ceremony that tries to ensure that key material can not leak in any way.</p>

<p>As you can see in <a href="https://calyxos.org/news/2025/12/17/calyxos-progress-update/">our last community update</a>, we spent quite some time in designing, testing, reviewing, and preparing for the key provisioning ceremony. And the whole key ceremony package was audited by <a href="https://www.trailofbits.com/">Trail of Bits</a>. You can find their <a href="https://github.com/trailofbits/publications?tab=readme-ov-file#cryptography-reviews">audit report</a>.</p>

<p>The ceremony taught a few practical lessons. To prevent a targeted attack from compromising the machine used in the provisioning ceremony, we bought a compatible device from a randomly selected store immediately beforehand. To establish a trusted and secure environment, we used an epheremal live OS with a good security track record: <a href="https://tails.net/">TailsOS</a>. Using TailsOS on a random out-of-the-box machine came with its own constraints; we needed to use a DVD as our initial data medium for ceremony scripts and TailsOS files. Prior to creating the bootable TailsOS flash drive, we also needed to verify the integrity of the live medium on Windows, the out-of-the-box operating system. Our specific solution was to create a reproducible <code class="language-plaintext highlighter-rouge">.iso</code> file and burn that onto a DVD. Then, in Windows, we used powershell commands, which were also used in the <a href="https://github.com/juicebox-systems/ceremony">Juicebox HSM Key Ceremony</a>, to compute the SHA256 hash of the entire drive. The operator confirmed the hash by reading it aloud in front of all ceremony participants for everyone to verify the hash of our <code class="language-plaintext highlighter-rouge">.iso</code> file:</p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4b1f31960c64fe0bf5bb7087f8d06923cce611a795f510f028fe3811b4c25847
</code></pre></div></div>

<p>If you are interested, you can reproduce this hash on your own computer following <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items/3447#note_3009846831">our instructions</a>.</p>

<p>After verifying the DVD and the files stored on it, we created a live Tails drive with a flash drive we (also) bought randomly. To ensure security, we made sure to keep the ceremony computer offline throughout the entire procedure, from the initial Windows Setup Wizard to the running of the ceremony scripts on TailsOS.</p>

<p>The next step was rather quick and smooth as we booted into the Tails drive to run the audited scripts from the DVD to set up two HSMs, one for operation and the other for backup. We did a physical factory reset for both the YubiHSM 2 devices and turned on auditing (you can find more about this in the following paragraphs). The script then created three authentication keys: one for the signing operator, one for the admin, and one for the auditor.</p>

<p>The wrap key was then created in the HSM, split into shards, and imported into both HSMs. The shards and the authentication keys were encrypted to pre-defined public keys using <a href="https://github.com/FiloSottile/age">age</a>.</p>

<h3 id="android-signing-with-pkcs11">Android signing with PKCS#11</h3>

<p>All tools involved in Android signing support PKCS#11, an <a href="https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=pkcs11">OASIS standard</a>, C interface to let software communicate with a HSM and also referred to as Cryptoki. It is a common choice when replacing signing keys in files with an HSM. However, we couldn’t find out-of-the-box PKCS#11 solutions for signing Android builds. As far as we know, we were the first Android ROM building a complete PKCS#11 Android signing solution and documenting it. It was possible that bigger OEMs had been taking this route to sign their builds with HSMs. Or at least we hope so.</p>

<p>Android’s entire signing process is quite complex. It is not only about signing lots of apps, but apps inside partitions that get unpacked, repacked after all contents have been signed, and finally signed themselves.</p>

<p>There are three different tools used throughout the signing process: apksigner, signapk and OpenSSL. All of them need to get hooked up to use our HSM but each is used in their unique ways and troubleshooting tool-specific bugs takes time.</p>

<p>For example, apksigner was using a PKCS#11 module, but it <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items/3434">didn’t close sessions</a>, which caused a denial of service because of the limited number of open sessions allowed and the long timeout. To add to this, we found signapk quite <a href="https://gitlab.com/CalyxOS/calyxos/-/work_items/3417">buggy</a> and not usable with strictly PKCS#11-compliant solutions. So we had to switch to using apksigner instead. It remained unclear to us why Google would use two different tools here when one could simply do the job.</p>

<p>Other changes we made included performance improvements. For instance, apksigner would load the entire key store at each start. If the keys were on the HSM, this would take a long time. Since we used apksigner a lot, we added a batch mode to it.</p>

<p>We also disabled <a href="https://source.android.com/docs/security/features/apksigning#schemes">V1 signatures</a> for our apps. V1 signatures require a lot of HSM operations (one for each file in the APK). Plus, it is not needed in recent Android versions.</p>

<p>The next steps for us include continuing the code cleanup, revising the changes with better, more sustainable logic, and further improving signing performance by using a signing cache (so that signing the same component will use the same HSM and key only once).</p>

<p>All of our source code for the above is free and open-sourced. We invite all custom ROM development teams who are curious about signing with HSMs to contact us and collaborate. You can find links to them at the bottom of this post.</p>

<h3 id="auditing">Auditing</h3>

<p>Keeping the signing keys safe with a multiparty backup approach was important but we wanted to go further. Being auditable at all times was another important goal for us to improve our signing design; specifically addressing the issue where whoever performed the actual signing with the HSM would still hold significant power. While they could not extract the signing keys themselves, they could sign arbitrary things with those keys, such as a malicious app. With a valid signature, an imposter app can replace the real app installed on a victims’ device.</p>

<p>With this in mind, we aimed to audit all signing operations, which led us to the discovery of more limitations of the YubiHSM 2. Similar to the limited key storage, the space for saving the audit log is equally limited. If you don’t want to lose logs you need to regularly fetch logs from the HSM. Since we enabled a force-log mode, a full log would cause a denial of service. This was where some of our own toolings came in; we intercepted every signing command and ensured that logs would get flushed to a file on disk. The audit logs were then pushed to an append-only git repository where CI would automatically verify the hash chain of signing log.</p>

<p>Even with these logs, there were still room for improvement: the audit log on the HSM wasn’t cryptographically signed and we needed extra steps to verify the log in the git repo against the one in the signing artifacts. Since the log contained sparse information, we would need to manually retain all signed artifacts to properly investigate a potential incident. Despite the improvements we are planning, this has got us a head start in reviving CalyxOS.</p>

<hr />

<p>This project came to fruition with the support of many open-source tools. We would like to thank the tool developers, our security auditors, and everyone who has contributed to this work along our journey. The talk was presented by <a href="https://gitlab.com/aysha12">aysha</a> and <a href="https://gitlab.com/grote">Torsten Grote</a> on the CalyxOS team with a special thanks to <a href="https://gitlab.com/t-m-w">t-m-w</a>.</p>

<p>If you are curious about our work and want more details, you can check out our <a href="https://gitlab.com/CalyxOS/vendor_calyx/-/blob/225f0dda34109fc85fa69f647b7e72753adbe8d8/scripts/pkcs11/DOCUMENTATION.md">PKCS#11 documentation</a> and <a href="https://gitlab.com/CalyxOS/vendor_calyx/-/blob/6d4d024ae/scripts/hsm_provisioning/README.md">provisioning documentation</a> on this topic. All of our signing-related scripts can be found <a href="https://gitlab.com/CalyxOS/vendor_calyx/-/tree/4a07f419fb9f86417d24dadb0f5314e033983005/scripts">here</a>.</p>

<p>Here’s a list of patches we had to make to AOSP:</p>
<ul>
  <li><a href="https://gitlab.com/CalyxOS/platform_build/-/commit/6962d7ab4cd91dd53265ab6deacc3f628fbb80e4">Add PKCS#11 signing support</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_build/-/commit/1c810cfcab496a1bf213f96f329f997bc4f7c3b4">Add argument to keep temporary files</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_build/-/commit/0cd789aeb7aa217014576221989d04968526283e">Don’t add quotes around signing_args</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_build/-/commit/af5a3b003a7ced41108100d3eaa1f2d552eba4fb">Use apksigner for most APK and APEX signing</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_build/-/commit/0d37c304584b103131f85c1d971a1d821fbfa2fa">Add option to use a signing command interceptor</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_system_apex/-/commit/afd136efc87e7d99ff4e0b7e42e18591ab0b94d9">Add support for a signing command interceptor</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_tools_apksig/-/commit/5275610e05b5010c9f8bc07d0b65b99dbf130942">Add alignment override option like signapk</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_tools_apksig/-/commit/12a329fefe23b4abe5879a5078311e9fb00b48b9">Log out of SunPKCS11 on exit</a></li>
  <li><a href="https://gitlab.com/CalyxOS/platform_tools_apksig/-/commit/391b20b75c737afe7d2ed1400d95641468cfedbb">Add batch mode to reuse loaded keystore</a></li>
</ul>

<p>If you have more questions, feel free to <a href="https://calyxos.org/community/">get in touch with us</a>.</p>]]></content><author><name></name></author><summary type="html"><![CDATA[This post is based on the talk our team gave at FOSDEM 2026. It provides a deep dive into our HSM-based signing redesign. Video recording of this talk is available here.]]></summary></entry><entry><title type="html">CalyxOS progress report - ceremony preparation, QPR ports, and FOSDEM</title><link href="/news/2025/12/17/calyxos-progress-update/" rel="alternate" type="text/html" title="CalyxOS progress report - ceremony preparation, QPR ports, and FOSDEM" /><published>2025-12-17T00:00:00+00:00</published><updated>2025-12-17T00:00:00+00:00</updated><id>/news/2025/12/17/calyxos-progress-update</id><content type="html" xml:base="/news/2025/12/17/calyxos-progress-update/"><![CDATA[<ul>
  <li>Our final open HSM-based key provisioning plan is undergoing auditing before the key ceremony</li>
  <li>CalyxOS devices, including extended support, are being ported to Android 16 QPR1 while QPR2 support plan is being developed</li>
  <li>We are improving community support with the new Community Coordinator</li>
  <li>Catch up with us at FOSDEM in Brussels on January 31 2026!</li>
</ul>

<p>Following <a href="https://calyxos.org/news/2025/11/10/calyxos-progress/">last month’s update</a>, the CalyxOS team is entering the final stage for the new signing plan and policy. In addition, we are working on bringing CalyxOS supported devices up to Android 16 QPR2 and building the team capacity with new hires. Here is a detailed rundown of our work:</p>

<h3 id="signing-finalization-and-audit">Signing finalization and audit</h3>

<p>Our team has reached a final draft for the new HSM-based signing process. This includes a detailed plan for the initial key ceremony, provisioning scripts, and the verification methodology of each element in the process. Based on the <a href="https://calyxos.org/news/2025/11/10/calyxos-progress/">criteria we laid out before</a> and our requirements for signing CalyxOS builds and apps at the frequency of every one to three months, our goal for this new signing design is ensure that all key material will have a secure backup so that no single person can hold access to our signing keys. The main key we will be generating during a provisioning ceremony will be split into shards using Shamir’s Secret Sharing. Each shard is only ever stored encrypted and kept safe by a designated team member. Together with security auditors we selected a <a href="https://github.com/hashicorp/vault/tree/main/shamir">library</a> for this job and wrote our own simple Go executable with it, which could create reproducible builds and was already audited.</p>

<p>All the provisioning tools, key ceremony operational plan, and auditing mechanism are being packaged for a final security audit.</p>

<p>Once this package for key signing provisioning passes the audit from our security consultant, we will perform the key ceremony and deploy the new signing mechanism for CalyxOS. We anticipate this to happen in the next few weeks and will keep you updated on audit progress.</p>

<h3 id="android-16-qpr1-and-qpr2">Android 16 QPR1 and QPR2</h3>

<p>We are pleased to share that we have booted Android 16 QPR1 on all modern devices on <a href="https://calyxos.org/docs/guide/device-support/">our supported device list</a> and are testing full CalyxOS functionality while also porting it to the rest of the our supported devices. What’s more, we have started analysis of the <a href="https://android-developers.googleblog.com/2025/12/android-16-qpr2-is-released.html">newly published QPR2</a> and are building out our QPR2 sync plan and timeline for all supported devices.</p>

<p>In the meantime, we are setting out to migrate our CalyxOS Gerrit Code Review instance to a new and faster server as part of the Calyx Institute’s data infrastructure overhaul. The success of the Gerrit migration will stabilize and facilitate our QPR2 bringup.</p>

<h3 id="building-capacity-for-the-calyxos-team-continued">Building capacity for the CalyxOS team, continued</h3>

<p>Last month, Lucas, a long-time CalyxOS contributor, joined the team as the Community Coordinator. You might have been familiar with Lucas on our various community channels, including Matrix room and CalyxOS subreddit. We will keep improving our community communications with the tremendous help from Lucas. To start, we will try to make sure we respond to all questions and concerns. If you have any comments or suggestions, please do not hesitate to ping us on our channels.</p>

<p>The position of CalyxOS Android Board Support Packages (BSP) Engineer has been closed and we have entered the interview stage. We will soon have a few more openings on our <a href="https://job-boards.greenhouse.io/calyxinstitute">job board</a>. Stay tuned!</p>

<h3 id="meet-the-calyxos-team-at-fosdem-2026">Meet the CalyxOS team at FOSDEM 2026</h3>

<p>If you plan to attend <a href="https://fosdem.org/2026/">FOSDEM 2026</a> and are interested in knowing more about our effort in HSM signing upgrade, we will present our methodologies and lessons at the <a href="https://fosdem.org/2026/schedule/track/foss-on-mobile/">FOSS on Mobile devroom</a>. Looking forward to seeing you there!</p>]]></content><author><name></name></author><summary type="html"><![CDATA[Our final open HSM-based key provisioning plan is undergoing auditing before the key ceremony CalyxOS devices, including extended support, are being ported to Android 16 QPR1 while QPR2 support plan is being developed We are improving community support with the new Community Coordinator Catch up with us at FOSDEM in Brussels on January 31 2026!]]></summary></entry><entry><title type="html">CalyxOS progress report — signing, team capacity, and more</title><link href="/news/2025/11/10/calyxos-progress/" rel="alternate" type="text/html" title="CalyxOS progress report — signing, team capacity, and more" /><published>2025-11-10T00:00:00+00:00</published><updated>2025-11-10T00:00:00+00:00</updated><id>/news/2025/11/10/calyxos-progress</id><content type="html" xml:base="/news/2025/11/10/calyxos-progress/"><![CDATA[<ul>
  <li>CalyxOS is working seamlessly with our security consultants to finalize the HSM signing solution.</li>
  <li>The Calyx engineering is fixing our data infrastructure.</li>
  <li>Three new roles are open for CalyxOS.</li>
</ul>

<p>As <a href="https://calyxos.org/news/2025/09/30/how-to-reach-the-calyxos-team/">promised</a>, today the CalyxOS team is sharing an update on our progress to improve the project and increase transparency.</p>

<p>Throughout the past few weeks, the team has been focusing on improving the security of our critical infrastructure and tackling long lasting challenges. In addition, we are revising our communication strategy toward a combination between providing thorough updates and building capacity for direct engagement in our community channels. Understandably, the decrease of the team voice and public actions have raised questions and concerns around the capacity of the project. We would like to respond to concerns people have raised by confirming that CalyxOS hasn’t been compromised and the organization is directing significant resources to get it back on track. We deeply appreciate all the people who have been sharing their concerns with us. And we will try our best to address their questions in this report.</p>

<h2 id="redesigning-the-calyxos-signing-process">Redesigning the CalyxOS signing process</h2>

<p>We are finalizing the design of a Hardware Security Module (HSM) signing solution for CalyxOS. A HSM is a dedicated physical hardware device that generates and stores cryptographic keys in a tamper-resistant environment; the keys never leave the HSM, which puts a guardrail against key extraction and compromise. We decided to move to a HSM because signing keys are a critical part of the chain of trust: they are what verifies to your device that an update actually comes from CalyxOS and hasn’t been tampered with.</p>

<p>Our criteria for the CalyxOS signing solution were that it should be: <strong>available</strong>, <strong>affordable</strong>, <strong>secure</strong>, <strong>expandable</strong>, <strong>auditable</strong>, <strong>redundant</strong>, <strong>easy to access</strong>, and <strong>aligned to the mission of the Calyx Institute</strong>. These requirements were what led us to choose the HSM solution among available options. Specifically, we selected the YubiHSM2 based on our current urgent development requirements and resources as an interim solution while we evaluate and build out a long-term solution. To keep our solutions consistent with a seamless transition in the future, we are ensuring that our keys are transferable both operationally and technically, and that CalyxOS users will not need to reflash their devices beyond the initial installation.</p>

<p>Our work has also included integrating AOSP’s documented <a href="https://source.android.com/docs/core/ota/sign_builds">signing process</a> with PKCS #11, the public-key cryptography standard for communicating with HSMs and cryptographic devices. To make that happen, we are building an interface layer between the two that does not yet exist in the standard AOSP tools or within the FOSS community.</p>

<p>Right now, we are finalizing the detailed provisioning plan for the signing process under the guidance and testing from our independent, third-party security consultants.</p>

<p>Once the new signing infrastructure and procedure is in place, documentation and code will be shared as a FOSS project as part of our commitment to open source, transparency, and community collaboration.</p>

<h2 id="adapting-to-the-new-norm-of-aosp-releases">Adapting to the new norm of AOSP releases</h2>

<p>Google has made serious changes to AOSP development in the last few months; monthly security patches are often empty and public git tags for developers, which make it easy to identify patches, are no longer available. As the changes unfold gradually, the challenge of keeping a regular and timely development cycle with all these AOSP changes remains significant as the custom ROM community has spoken about extensively.</p>

<p>Despite these challenges, we have made the decision to — in our best effort — further extend our device support for moto g32, g42, g52, Pixel 5, 4a 5G, and Pixel 5a 5G when CalyxOS resumes update releases. That means people with these devices can install the Android 16 version of CalyxOS when it becomes available. We are still gauging whether we can ship QPR1 to these extended release devices, pending the release of the QPR1 source; QPR2 is even less certain as we assess the work involved. Once we have builds ready with a thorough evaluation of the case, we will publish a confirmed new EOL date for devices for which we provide extended support.</p>

<p>In the interim, we have also reached out to our peer custom ROM developers and several device manufacturers to align strategies to sustainably access and publish OS security patches. We hope that this collective effort of the global FOSS community will stop the trend of closing source for AOSP and other open-source projects.</p>

<h2 id="building-capacity-for-the-calyxos-team">Building capacity for the CalyxOS team</h2>

<p>In reality, Calyx has been a small team running a lot of projects, not least of all CalyxOS. We are stretched thin right now and our priority has been getting CalyxOS back up and running ASAP. As we are drafting this report, we are also working diligently to expand development capacity and optimize team structure. We have brought Lucas—a long-time CalyxOS community facilitator—to the team as our new Calyx Community Coordinator, a role that has never existed in the organization before. In addition, we are in active recruitment for the <a href="https://job-boards.greenhouse.io/calyxinstitute/jobs/4934856007">CalyxOS Android Board Support Packages (BSP) Engineer</a> position and a new Android Platform Software Developer. Keep an eye on our <a href="https://job-boards.greenhouse.io/calyxinstitute">job board</a> and please help spread the word!</p>]]></content><author><name></name></author><summary type="html"><![CDATA[CalyxOS is working seamlessly with our security consultants to finalize the HSM signing solution. The Calyx engineering is fixing our data infrastructure. Three new roles are open for CalyxOS.]]></summary></entry><entry><title type="html">An update on how to reach the CalyxOS team</title><link href="/news/2025/09/30/how-to-reach-the-calyxos-team/" rel="alternate" type="text/html" title="An update on how to reach the CalyxOS team" /><published>2025-09-30T00:00:00+00:00</published><updated>2025-09-30T00:00:00+00:00</updated><id>/news/2025/09/30/how-to-reach-the-calyxos-team</id><content type="html" xml:base="/news/2025/09/30/how-to-reach-the-calyxos-team/"><![CDATA[<ul>
  <li>An update on how CalyxOS will provide support on each community channel</li>
  <li>Team support will withdraw from the Telegram channel</li>
</ul>

<p>Dear CalyxOS community members,</p>

<p>We would like to share an update on how to reach the CalyxOS team given the recent traffic insights and our internal temporary shortage of staffing. As we work hard to get the project back on track, including its community channels, we are increasingly concerned with the rapidly growing spam messages in the Telegram channel. Historically, this community channel, like every other CalyxOS community channel, has been fully administrated and moderated by volunteers and the moderator bot that was set up to bridge between the CalyxOS Matrix and Telegram channels. And the CalyxOS team tried our best to make sure they are governed under the CalyxOS <a href="https://calyxos.org/community/code-of-conduct/">Code of Conduct</a> and <a href="https://calyxos.org/community/pledge/">Community Pledge</a>.</p>

<p>As we are transitioning the project, we also aim to refine our community support to make the best use of small team’s capacity at the moment. To further clarify, here is a rundown of how you can seek help or support from the CalyxOS team on our community channels:</p>
<ul>
  <li>To seek a quick answer to a technical question, the best way is to reach us in our <a href="https://app.element.io/#/room/#CalyxOS:matrix.org">Matrix room</a>. You can tag @calyx_institute:matrix.org to ensure a response.</li>
  <li>To report bug or send feature / functionality request, please start a new issue on the <a href="https://gitlab.com/CalyxOS/calyxos/-/issues">Calyx GitLab</a>. Regular triage and review will restart in mid-October.</li>
  <li>To follow the latest CalyxOS updates, you can check the <a href="https://x.com/CalyxOS">CalyxOS X</a> and <a href="https://fosstodon.org/@calyxos">Mastodon</a> accounts.</li>
  <li>We will also continue to sync all CalyxOS updates to the <a href="https://www.reddit.com/r/CalyxOS/">CalyxOS subreddit</a> and answer questions when we have the time.</li>
</ul>

<p>Going forward, we will withdraw our support from the Telegram channel to make sure our main channel is fully supported. However, the Telegram channel will continue to run as a entirely community-led space, however, our team is unable to moderate nor delegate moderator privilege in those groups at this time. We thank all the admins and superusers on Telegram who have been voluntarily facilitating a democratic space for CalyxOS with our deepest gratitude.</p>

<p>Please stay tuned for our next community periodical progress report which will be coming within the next week!</p>]]></content><author><name></name></author><summary type="html"><![CDATA[An update on how CalyxOS will provide support on each community channel Team support will withdraw from the Telegram channel]]></summary></entry><entry><title type="html">Last OTA update before the new CalyxOS release</title><link href="/news/2025/08/27/last-ota-update-before-new-calyxos-release/" rel="alternate" type="text/html" title="Last OTA update before the new CalyxOS release" /><published>2025-08-27T00:00:00+00:00</published><updated>2025-08-27T00:00:00+00:00</updated><id>/news/2025/08/27/last-ota-update-before-new-calyxos-release</id><content type="html" xml:base="/news/2025/08/27/last-ota-update-before-new-calyxos-release/"><![CDATA[<ul>
  <li>This is the last over-the-air (OTA) update to all current and supported CalyxOS devices, before CalyxOS resumes development from its current hiatus.</li>
  <li>The OTA update warns people of the risk of running the current, unmaintained version of CalyxOS.</li>
  <li>It also includes a patch to enable Moto and Fairphone users to install CalyxOS while the project is on pause in response to emerging public requests.</li>
</ul>

<h3 id="whats-included">What’s included</h3>

<p>As mentioned in our letter to the <a href="/news/2025/08/01/a-letter-to-our-community/">CalyxOS community</a>, this project has been on a hiatus for the last two months. However, we are concerned with the many existing CalyxOS users who may have not been made aware of this important change. To reach as many active CalyxOS users as we can, our team decided collectively to push one last OTA update to inform all people currently running CalyxOS about the hiatus and its impact.</p>

<p>Therefore, rather than a typical monthly update, this OTA update alerts people through a system notification that their current version of CalyxOS will no longer receive updates from our team and a link to our community letter. Once the project comes out of the hiatus, you will be alerted with an additional notification, and reinstalling CalyxOS will be required to receive updates going forward.</p>

<p>In addition, Moto and Fairphone devices will receive a patch to fix <a href="/install/antirollback-update-pending/">the issue related to the anti-rollback protection (ARB) feature</a> we discovered earlier. We hope this can provide a temporary solution to people who are seeking to run CalyxOS on these devices before they can establish a long-term plan. Note that since there will be no more updates to the existing version of CalyxOS installed on your device, future releases from the manufacturer to increment the ARB index are likely to cause the same issue mentioned above.</p>

<p>We understand that some people will continue running CalyxOS until our next release, so alongside this notification, we have included the latest open source security updates for Android 15 (although this is not a full CalyxOS security update).  This OTA update, however, is not related to our Android 16 port or the AOSP QPR1 update. We are closely monitoring the AOSP QPR1 release and working hard on bringing up Android 16 with all feature updates and security patches along with our current need to overhaul the project.</p>

<h3 id="rollout">Rollout</h3>

<table>
  <thead>
    <tr>
      <th>Release channel</th>
      <th>Date</th>
      <th>Notes</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Security express</td>
      <td>2 September, Tuesday</td>
      <td> </td>
    </tr>
    <tr>
      <td>Beta</td>
      <td>2 September, Tuesday</td>
      <td> </td>
    </tr>
    <tr>
      <td>Stable</td>
      <td>3 September, Wednesday</td>
      <td> </td>
    </tr>
  </tbody>
</table>

<h3 id="changelog">Changelog</h3>
<ul>
  <li>CalyxOS 6.10.10 / 6.10.20</li>
  <li>Android 15</li>
  <li>August 2025 Security update (2025-08-01) with platform patches only.</li>
  <li>Critical notice that maintenance of all current installations have been paused.</li>
</ul>]]></content><author><name></name></author><summary type="html"><![CDATA[This is the last over-the-air (OTA) update to all current and supported CalyxOS devices, before CalyxOS resumes development from its current hiatus. The OTA update warns people of the risk of running the current, unmaintained version of CalyxOS. It also includes a patch to enable Moto and Fairphone users to install CalyxOS while the project is on pause in response to emerging public requests.]]></summary></entry></feed>