Skip to content
Merged
Show file tree
Hide file tree
Changes from 5 commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
ba3e133
feat: begin migrating PIV operations to libcanokey
dangfan Sep 15, 2026
6620bfc
feat: route all applet protocol operations through libcanokey
dangfan Sep 16, 2026
7085eb7
fix: authenticate pass slot reads on gated firmware
dangfan Sep 16, 2026
ed320c7
fix: authenticate the gated algorithm-extension read on firmware 3.0.x
dangfan Sep 16, 2026
4ca1cc5
feat: adopt upstream CTAP2 client and consolidate card clients
dangfan Sep 16, 2026
69ef2b1
refactor: adopt upstream firmware authentication-gate modeling
dangfan Sep 16, 2026
66271c7
chore: unify wasm-bindgen family at 0.2.128 and refresh dependencies
dangfan Sep 16, 2026
e7f77fa
refactor: adopt libcanokey 41a3ea60 and rewrite the integration doc
dangfan Sep 16, 2026
fd4ebdc
chore: drop the dead resetApdu enum field
dangfan Sep 16, 2026
5e32c7d
fix: dart2js-safe 64-bit decodes and skip redundant Admin SELECTs
dangfan Sep 16, 2026
0b23585
feat: show build commit and build time in the About dialog
dangfan Sep 16, 2026
f7ea0cf
feat: skip the duplicate serial read in probes
dangfan Sep 16, 2026
77a9c97
fix: address review follow-ups
dangfan Sep 16, 2026
b4ec54d
feat: polish the build info in the About dialog
dangfan Sep 16, 2026
1a8cf0e
docs: note the remaining wire redundancies needing upstream support
dangfan Sep 16, 2026
0e3fc3d
fix: use the PR head commit for BUILD_COMMIT
dangfan Sep 16, 2026
c03ea2e
feat: bundle app fonts and subset Noto Sans SC for CJK
dangfan Sep 16, 2026
02f26b7
build: regenerate CJK font subsets as part of the build
dangfan Sep 16, 2026
eb86774
ci: set up an isolated Python for the font subsetting step
dangfan Sep 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 0 additions & 14 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,20 +49,6 @@ jobs:
cargo install wasm-pack --version "$WASM_PACK_VERSION" --locked
flutter_rust_bridge_codegen build-web --release \
--wasm-pack-rustup-toolchain "$RUST_NIGHTLY"
- name: Restore FIDO2 Web backend
id: fido2_web_cache
uses: actions/cache@v5
with:
path: web/fido2
key: fido2-web-v1-${{ runner.os }}-${{ runner.arch }}-${{ env.RUST_NIGHTLY }}-${{ steps.wasm_pack.outputs.version }}-${{ hashFiles('pubspec.lock') }}
- name: Build FIDO2 Web backend
if: steps.fido2_web_cache.outputs.cache-hit != 'true'
env:
RUSTUP_TOOLCHAIN: ${{ env.RUST_NIGHTLY }}
run: |
dart run fido2:setup --web --output=build/fido2
mkdir -p web/fido2
cp build/fido2/web/fido2_crypto* web/fido2/
- run: flutter build web --verbose
- uses: actions/upload-artifact@v7
with:
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/usbip.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ jobs:
rust-src-dir: rust
cache-key: usbip-backend

- name: Build FIDO2 backend
- name: Build native backend
if: steps.backend_cache.outputs.cache-hit != 'true'
run: |
cargo build --manifest-path rust/Cargo.toml --release --locked
Expand All @@ -78,10 +78,10 @@ jobs:

- run: flutter pub get

- name: Test FIDO2 backend and client integration
- name: Test native backends and client integration
env:
FIDO2_CRYPTO_LIBRARY: ${{ github.workspace }}/build/usbip-backend/librust_lib_canokey_console.so
run: flutter test --no-pub test/helper/utils/fido2_backend_test.dart
FRB_DART_LOAD_EXTERNAL_LIBRARY_NATIVE_LIB_DIR: ${{ github.workspace }}/build/usbip-backend
run: flutter test --no-pub --tags native

- name: Share native backend with firmware jobs
uses: actions/upload-artifact@v7
Expand Down
1 change: 0 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,6 @@ build
*.iml
.flutter-plugins*
dist/
web/fido2/
app-store-screenshots/
android/fastlane/report.xml
ios/fastlane/report.xml
36 changes: 25 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,28 @@ Visit our web application at [CanoKey Console Web](https://console.canokeys.org)

3. Run the application:
```bash
flutter_rust_bridge_codegen build-web --release # for web only, remove --release for debug Rust build (very slow when decoding qrcode!)
dart run fido2:setup --web --output=build/fido2 # for web only
mkdir -p web/fido2 && cp build/fido2/web/fido2_crypto* web/fido2/ # for web only
flutter_rust_bridge_codegen build-web --release --wasm-pack-rustup-toolchain nightly-2026-09-04 # for web only
flutter run
```

For Chrome development, run `flutter run -d chrome --cross-origin-isolation`
to enable the headers required for shared WASM memory.

If `wasm-pack` cannot download its helper and fails while compiling
`wasm-bindgen-cli` with WASM linker flags on the host, install the matching
helper separately with `cargo +stable install wasm-bindgen-cli --version 0.2.100 --locked`
and ensure its `bin` directory is on `PATH` before rebuilding.

After changing Rust code or regenerating Flutter Rust Bridge bindings, rebuild
the web bundle with the `build-web` command above, then stop and relaunch the
Flutter app. Hot restart does not recompile Rust. A content-hash mismatch means
the loaded WASM bundle and generated Dart bindings are out of sync.

If hot restart reports `Identifier 'wasm_bindgen' has already been declared`,
fully reload the browser page or stop and relaunch the app. The bridge's web
loader inserts its script again on hot restart, while the previous script's
global declaration remains in the page.

## Diagnostic Logs

Open **Settings > View Logs** to inspect this session's local logs without a
Expand All @@ -81,24 +97,22 @@ If you change any Rust dependencies (`Cargo.lock`), please run:
cd rust && cargo bundle-licenses -f json | jq '.third_party_libraries | del(.[].licenses)' > THIRD_PARTY_LICENSES.json
```

The fido2 Dart package and native Rust revision are pinned together at 2.0.0.
Its native C ABI is linked into the existing console Rust library. The
wasm-bindgen dependency family is pinned to versions compatible with fido2 2.0.0.
Web uses the separate JS/WASM loader distributed with the Dart package.
PIV selection, version and algorithm-configuration reads now use a pinned
libcanokey Rust dependency through Flutter Rust Bridge. See the
[migration boundary and next steps](docs/libcanokey-migration.md) for the
implemented scope, session requirements and validation commands.

Before running backend or USB/IP tests locally, build the native backend:

```bash
cargo build --manifest-path rust/Cargo.toml --release --locked
flutter test test/helper/utils/fido2_backend_test.dart
flutter test --tags native
```

### Web

```bash
flutter_rust_bridge_codegen build-web --release
dart run fido2:setup --web --output=build/fido2
mkdir -p web/fido2 && cp build/fido2/web/fido2_crypto* web/fido2/
flutter_rust_bridge_codegen build-web --release --wasm-pack-rustup-toolchain nightly-2026-09-04
flutter build web
```

Expand Down
Loading