Skip to content

fix: keep genuine-check verify dialog interactive on iOS retry - #12951

Merged
originalix merged 3 commits into
hotfix/v6.5.2from
fix/genuine-check-dialog-ios-freeze
Aug 20, 2026
Merged

fix: keep genuine-check verify dialog interactive on iOS retry#12951
originalix merged 3 commits into
hotfix/v6.5.2from
fix/genuine-check-dialog-ios-freeze

Conversation

@originalix

Copy link
Copy Markdown
Collaborator

Problem

On iOS, in the onboarding "Check and Update" page, when the genuine check (firmware verify) fails and the user retries a few times, the whole page ends up dimmed and unresponsive — the error dialog stays visible but its Retry button no longer receives taps. 100% reproducible on a Pro 2 whose firmware verification currently fails (Failure_DataError, Decode failed: 800(4033)).

Root cause

Same class of bug as the earlier bootloader-dialog fixes (#12656 line of work): on native iOS every Dialog.show renders into the single FullWindowOverlay portal, where stacking follows render order only (zIndex is not honored across portal siblings).

In verifyHardware, the shouldAuthenticateFirmware branch closed the hardware checking dialog with a fire-and-forget void closeHardwareUiStateDialog(...) and immediately mounted the firmware-verify dialog via the global Dialog.show. The new Sheet mounts inside the old Sheet's 300 ms exit window, and each retry round repeats the race in both directions (checking dialog reopening while the previous verify dialog is still exiting). After a few rounds a stale backdrop is stranded above the interactive dialog and swallows every tap.

Fix (mirrors the established bootloader-dialog pattern)

  • useDeviceConnect.verifyHardware: on iOS, serialize the handoff with hardwareUiStateDialogLifecycle.closeAndWait(...) so the checking dialog fully leaves the global overlay before the verify dialog mounts (same rule as the bootloader branch a few lines above).
  • useFirmwareVerifyDialog: accept an optional dialogHost (default Dialog, other callers unchanged). CheckAndUpdate passes its existing page-owned in-page dialog host (BootloaderDialogHostBridge), so the verify dialog renders into the page's own portal and can never interleave with the checking Sheet in the render-order-only global overlay. During verification itself no global checking dialog appears (firmwareAuthenticate runs with hideCheckingDeviceLoading: true), so nothing covers the in-page dialog.

Side effect: the verify dialog now inherits the onboarding force-dark theme instead of popping light, consistent with the bootloader dialog.

Verification

  • Hardware-triggered scenario, not reproducible in the simulator; the in-page host mechanism is already proven by the shipped bootloader dialog on the same page.
  • QA on a failing-verify Pro 2: on "Check and Update", fail the genuine check and retry (both the dialog Retry and the in-page Retry) 5–10 rounds — the app must stay responsive and the dialog buttons tappable; regression-check the bootloader-mode dialog flow on the same page.

@sidmorizon

Copy link
Copy Markdown
Contributor

@codex review

@sidmorizon

Copy link
Copy Markdown
Contributor

@codex security review

@sidmorizon

Copy link
Copy Markdown
Contributor

@cursoragent review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@cursor

cursor Bot commented Aug 20, 2026

Copy link
Copy Markdown

I reviewed PR #12951 and posted the comments on the PR.

The fix matches the shipped bootloader-dialog pattern: iOS waits for the hardware checking sheet to leave the global overlay, and Check and Update mounts the verify dialog in the page-owned portal so it cannot stack with that sheet. Other useFirmwareVerifyDialog callers stay on global Dialog.

One residual QA risk: in-dialog Retry only re-runs verify(). hideCheckingDeviceLoading skips the checking sheet, but deviceVerify() can still flash the global “confirm on device” UI. A leftover FullWindowOverlay backdrop would sit above the in-page dialog. Please fail genuine check on a Pro 2 and tap dialog Retry 5–10 times without dismissing. Nits (shared host type, v1 path unchanged) are non-blocking. No security issues. Verdict: approve after that Pro 2 retry check.

Open in Web Open in Cursor 

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: b13261cf8c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@cursor

cursor Bot commented Aug 20, 2026

Copy link
Copy Markdown

Review

The change is the right class of fix and it mirrors the shipped bootloader-dialog pattern on this page. Two files, both on the Check and Update genuine-check path.

What looks correct

  • iOS close is serialized. verifyHardware no longer fire-and-forgets closeHardwareUiStateDialog before Dialog.show. On iOS it uses hardwareUiStateDialogLifecycle.closeAndWait(...), same rule as the bootloader branch a few lines above. That is the actual fix for the FullWindowOverlay leftover-backdrop freeze.
  • Verify dialog leaves the global overlay on this page. dialogHost defaults to Dialog, so Device Management / v1 ConnectYourDevice are unchanged. CheckAndUpdate passes the existing BootloaderDialogHostBridge (useInPageDialog), so the verify sheet mounts in the page portal and cannot become a sibling of HardwareUiStateContainer’s singleton in FULL_WINDOW_OVERLAY_PORTAL.
  • In-page Retry cannot overlap an exiting verify sheet. runGenuineCheck stays in-progress while the dialog is open, so the page Retry button is disabled. onClose only runs after Dialog.show’s 300 ms portal teardown, then the promise rejects and the row becomes Error. The next verifyHardware therefore starts after the previous page-portal dialog is gone.
  • In-dialog Retry does not remount the sheet. Error → Retry only calls verify() again. Combined with firmwareAuthenticate({ hideCheckingDeviceLoading: true }), that path does not reopen the checking dialog.

Residual risk (QA, not a blocking code defect)

hideCheckingDeviceLoading only skips the checking sheet. deviceVerify() can still drive REQUEST_BUTTON (“confirm on device”) through HardwareUiStateContainer, which lives in the global FullWindowOverlay — above the in-page verify dialog.

Each dialog Retry can therefore open/close that singleton without closeAndWait. If Failure_DataError, Decode failed: 800(4033) still flashes the confirm sheet, a stuck global backdrop would cover the in-page dialog and look like the original freeze.

Please keep this in the Pro 2 QA script: fail genuine check, tap dialog Retry 5–10 times without dismissing, and confirm the Retry button stays tappable after the device confirm UI (if any) goes away. The page Retry / bootloader-mode cases already listed in the PR body are the right regressions.

Nits (non-blocking)

  • IFirmwareVerifyDialogHost is the same shape as IBootloaderModeDialogHost. A shared Pick<typeof Dialog, 'show'> type would avoid a second name, but this is consistent with the bootloader hook.
  • getBootloaderDialogHost is now also the genuine-check host. Fine for this hotfix; a later rename to getInPageDialogHost would match usage.
  • If bootloaderDialogHostRef.current is still null, dialogHost falls back to global Dialog and the old race returns. Unlikely after first paint (bridge is rendered at the top of the page), but worth knowing if the first verify ever runs before commit.
  • v1 ConnectYourDevice still fire-and-forgets the close + global Dialog.show. Out of scope here.

Security

No change to verification, hashing, skip rules, or hardware auth. This is dialog-lifecycle / portal targeting only. The existing dev-skip path is untouched.

Verdict: approve for merge after the Pro 2 retry QA above. I would not block on the nits.

Comment thread packages/kit/src/views/Onboardingv2/hooks/useDeviceConnect.tsx Outdated
Comment thread packages/kit/src/views/Onboardingv2/hooks/useDeviceConnect.tsx
@originalix
originalix merged commit 5425c92 into hotfix/v6.5.2 Aug 20, 2026
11 of 13 checks passed
@originalix
originalix deleted the fix/genuine-check-dialog-ios-freeze branch August 20, 2026 14:52
originalix added a commit that referenced this pull request Aug 22, 2026
* feat(hardware): add complete OneKey Pro 2 integration (#11814)

* feat(shared): add Pro 2 device foundations

Define canonical protocol V2 device state, connection and routing helpers, firmware config sources, portfolio payload/archive utilities, and Pro 2 media helpers shared across runtimes.

* feat(hardware): integrate Pro 2 background services

Persist canonical device state across main/background runtimes and add Pro 2 USB/BLE onboarding, hidden-wallet sessions, settings, firmware, portfolio sync, NFT transfer, network capability, and WalletConnect handling.

* feat(hardware): add Pro 2 wallet user flows

Expose Pro 2 onboarding, connection state, passphrase and hidden-wallet handling, device settings, brightness, wallpaper, firmware progress, portfolio display, NFT actions, and developer controls in the wallet UI.

* feat(cli): adapt hardware commands for Pro 2

Use the unified hardware SDK queue and device discovery/session data in CLI login and signing flows, with focused regression coverage.

* docs(hardware): document Pro 2 session and portfolio flows

Describe passphrase-wallet session semantics and the implemented portfolio packaging, synchronization, and upload pipeline.

* fix: address Pro 2 review findings

* fix: address remaining Pro 2 review findings

* fix: stabilize Pro 2 device management

* fix: avoid eager hardware SDK import

* fix: sync Pro 2 label validation feedback

* fix: avoid duplicate pin during hardware onboarding

* fix: address Pro 2 review feedback

* fix: prepare Pro 2 prerelease verification

* fix: preserve legacy hardware compatibility

* fix: use SDK Pro2 update targets

* fix: harden hardware device data handling

* fix: preserve hardware settings and safe logs

* fix: tighten Pro2 integration boundaries

* fix: harden Pro2 hardware security flows

* fix: address Pro2 review feedback

* fix: stabilize Pro2 onboarding and hardware sessions

* fix: stabilize hardware account creation

* fix: stabilize Pro2 hardware communication

* perf: lazy load hardware JPEG decoder

* fix: restore Pro2 hidden wallet entry

* fix: handle Pro2 Attach PIN onboarding

* fix: finalize Pro2 production support

* chore: exclude unrelated hotfix changes

* chore: upgrade hardware SDK to alpha.53

* fix: preserve Pro2 onboarding on hotfix

* fix: address Pro2 review feedback

* feat: improve Pro2 device and firmware update flows

* chore: update hardware sdk to 1.2.0-alpha.56

* fix: address Pro2 portfolio and lint review feedback

* fix: preserve hardware device compatibility

* fix: use local database schema version 20

* fix: close final Pro 2 compatibility gaps

* fix: bound firmware recheck wait

* feat(hardware): support Neo Protocol V2 devices (#12766)

* chore: update hardware SDK to alpha.69 (#12780)

* feat: harden firmware upgrade pipeline (#12656)

* feat: harden firmware upgrade pipeline

Stack the firmware-only changes on the hotfix IP Table prerequisite.

* chore: update hardware sdk prerelease

* fix: restore trusted firmware catalog

* fix: remove bundled firmware catalog

* fix: keep hardware available without firmware manifest

* fix: decouple firmware probe from IP routing

* chore: bump range downloader alpha

* fix: sync verified firmware artifact receipts

* chore: update hardware SDK to alpha.72

* chore: update hardware SDK to alpha.73

* chore: update hardware SDK to alpha.74

* chore: update SNI connect to alpha.9

* chore: update hardware SDK to alpha.76

* fix: harden firmware transport boundaries

* chore: update hardware SDK to alpha.77

* fix: serialize iOS hardware dialog transitions

* fix: serialize iOS bootloader dialog handoff

* fix: keep bootloader dialog interactive on iOS

* fix: load Protocol V2 resource archives (#12788)

* fix: clarify Pro2 firmware update workflow guard

* refactor: migrate desktop and webembed to rspack v2 (#12427)

* refactor: migrate desktop and webembed to rspack v2

* fix: unblock rspack migration checks

* fix: add jiti loader to desktop rspack workflows

* fix: strengthen web-embed compatibility checks

* fix: restore desktop rspack defaults

* fix: match spaced script end tags

* fix: harden web-embed script extraction

* fix: harden web-embed production finalization

* fix: finalize desktop production assets

* fix: align node engine with rspack

* fix: align web embed sentry release

* fix: align rspack production config with x

* fix: correct Pro2 portfolio currency conversion

* docs: translate firmware workflow comments

* fix: address Pro2 firmware workflow review feedback

* fix: keep switched firmware wallets manageable

* fix: support manifest-driven Pro2 resources

* fix: align Pro2 and Neo firmware update titles

* fix: sync locale translations

* fix: load protocol v2 resource archives

* fix: enable remote resource archive updates

* fix: address firmware update review feedback

* chore: align hardware sdk alpha versions

* fix: show protocol v2 update versions

* fix: mark resource archive download state

* fix: show protocol v2 component versions

* fix: harden protocol v2 firmware updates

* chore: remove unrelated locale changes

* chore: align locale with hotfix base

* fix: honor protocol v2 forced update targets

* fix: handle protocol v2 resource update overrides

* chore: update hardware sdk to 1.2.0-alpha.84

* refactor: route firmware artifacts through unified downloader

* fix: validate protocol v2 plan targets exactly

* fix: bind firmware host to prepared plan

* fix: allow current firmware artifact host

* fix: compare Protocol V2 resources by default

* chore: update hardware sdk to 1.2.0-alpha.86

* chore: update hardware sdk to 1.2.0-alpha.87

* fix: allow pre-release firmware artifact hosts in developer mode (#12800)

* fix: validate Protocol V2 firmware plans early

* chore: fix firmware artifact lint wording

* fix: consume prepared plans without duplicate inputs

* style: format prepared plan assertion

* fix: address protocol v2 firmware review

* chore: fix firmware UI test import order

* fix: support serial-less protocol v2 updates

* chore: update hardware sdk to 1.2.0-alpha.92

* chore: update hardware sdk to alpha.98

* chore: update hardware sdk to alpha.99

---------

Co-authored-by: huhuanming <huanming@onekey.so>
Co-authored-by: Leon <lixiao.dev@gmail.com>

* fix: pro2 bug fix (#12804)

* chore: update hardware sdk to alpha.100

* fix: align Pro2 device behavior

* fix: upgrade hardware SDK to 1.2.0-alpha.101 (#12808)

* Feat/hw fixes on hotfix652 OK-57549 OK-58650 OK-58579 (#12795)

* feat: offer a firmware update action on the generic hardware error toast

The UnknownHardwareError fallback toast tells users to keep hardware and app
up to date but gave them nothing to act on.

- UnknownHardwareError was the only hardware error class without its own
  `code`, so it fell back to the generic -99999 shared by every OneKey error
  and could not be matched. Give it ECustomOneKeyHardwareError.
  UnknownHardwareError (4033).
- Route that code to a new in-app firmware update action. The existing
  NeedFirmwareUpgradeFromWeb button stays on the web tool, which is what that
  error means.
- The SDK error payload never carries the device it came from, so stamp the
  connectId in withHardwareProcessing's catch and keep the raw payload on
  UnknownHardwareError (message resolution unchanged). Errors raised outside
  the wrapper still work: the ChangeLog page resolves the device itself.
- Add two ErrorToast gallery entries to trigger the toast manually.

* fix: move the device details danger zone below the routine settings

The danger zone sat between Security and Advanced, so a destructive wipe
action was surrounded by everyday settings and easy to hit by mistake. It is
now the last user-facing section, above only the Trezor debug block. Display
conditions are unchanged: still gated on device settings being shown and
still hidden for third-party vendors.

* chore: drop the yalc hardware SDK debug script

Local SDK work goes through the watcher in the SDK repo (dev:core to compile,
debug:watcher to copy dist into this repo's node_modules). This script drove the
older yalc flow, its package.json entry is long gone, and the publish:yalc side
it documents no longer exists either.

* feat: recognize the BLE pairing-cancelled code as a user cancel, not a connect failure

* fix: send a failed Trezor setup back to the device scan instead of retrying a dead address

* fix: keep the translated hardware error copy on the update toast

Passing `message` set normalizeErrorProps' `msg` up front, so its `!msg` i18n
branch never ran and the toast title fell back to the raw device string —
dropping the wallet_action_failed guidance the update button exists to act on.
Only `payload` is needed for the button to reach connectId.

Jest cannot catch this: the i18n branch is behind `!platformEnv.isJest`.

* feat: bridge the BLE release channel through the desktop preload

The keep-alive transport frees a link on a logical NOBLE_BLE_RELEASE signal;
without the preload bridge the idle countdown never starts and every operation
holds the device on the 10-minute busy backstop. keepSession rides the same
call so a mid-flow release keeps the long backstop. The SDK side ships in
1.2.0-alpha.101, already bumped on the base branch.

* fix: address the automated review on the firmware toast action and BLE channel list

Route CheckFirmwareUpdateButton through openChangeLogModal so the extension
popup/side-panel move to an expanded tab and device reachability is checked,
instead of pushing the modal into an ephemeral surface via rootNavigationRef.

Add NOBLE_BLE_RELEASE to the desktop cleanup list. alpha.75 self-clears its
handlers, so this is keeping the host list honest rather than a live fix.

* fix: handle onboarding device scan errors (#12830)

* fix: avoid legacy inputs in prepared firmware V3 (#12828)

* fix: avoid legacy inputs in prepared firmware V3

* test: align firmware self-test with prepared V3 inputs

---------

Co-authored-by: wabiwabo <68363074+wabicai@users.noreply.github.com>

* fix: harden Pro2/Neo recovery, BLE, and resource uploads (#12809)

* fix: refresh Pro2 and Neo state after firmware cancel

* fix: skip stale Pro2 portfolio sync OK-59765

* fix: consume normalized TON signing message

* style: translate firmware state comments to English

* fix: preserve binary payloads across offscreen bridge

* fix: satisfy offscreen lint rules

* fix: secure portfolio retries and BLE wallet creation

* fix: allow hidden-only devices in device management

* refactor: align BLE wallet creation with x branch

* fix: redact TON mismatch logs and cover device removal

* fix: route protocol v2 resource uploads through sdk

* chore: upgrade hardware sdk to alpha.104

* fix: persist selected hardware transport

* fix: resume post-update firmware recheck

* fix: add Pro2 and Neo bootloader minimum versions

* fix: harden firmware recheck and wallpaper uploads

* fix: use sdk auto shutdown options

* fix: defer wallet deprecation after device reset

* fix: handle onboarding device scan errors

* fix: allow sdk-managed protocol v2 firmware updates

* fix: reduce silent portfolio BLE sync

* fix: isolate stale device scan failures

* fix: prevent stale portfolio resume uploads

* fix: harden device scan error handling

* fix: preserve reset session on restarted scans

* fix: bind portfolio sync to connected device

* fix: defer Pro2 identity checks in bootloader

* chore: upgrade hardware sdk to 1.2.0-alpha.106

* fix: translate hardware comments to English

* fix: prevent stale portfolio identity cache reuse

* fix: NFT collect fixes (OK-59979 OK-59980) (#12836)

* fix: restore SDK NFT size lookup in getDeviceNftConfig

* fix: localize Pro2 NFT storage limit error message

* chore: sync translations from Lokalise

* chore: translate NFT storage limit message for all locales

* chore: upgrade sdk (#12838)

* fix: align firmware update device details (#12829)

* fix: close device setting select after change (#12841)

* fix: align prerelease firmware integrity validation (#12843)

* fix: restore Extension firmware update flow (#12851)

* fix: restore Extension firmware update route

* chore: upgrade hardware SDK to alpha.113

* chore: upgrade hardware SDK to alpha.116

* fix: avoid desktop sync IPC for time cache (#12853)

* fix: remove Pro 2 from USB connect device label (#12855)

* chore: upgrade hardware sdk to alpha.118 (#12856)

* chore: upgrade hardware sdk to alpha.119 (#12865)

* fix: skip ble pairing dialog for live ble session OK-60091 (#12861)

* fix: skip ble pairing dialog for live ble session OK-60091

* fix: silent ble bind probe uses silentMode and bounded timeout

* fix: gate silent ble bind behind recent live traffic evidence

* fix: read probe identity from both deviceId and device_id fields

* fix: invalidate live connectId evidence on device disconnect

* chore: add hardware lease and silent ble bind diagnostic logs

* fix: pin known protocol in silent ble bind probe

* test: align firmware detect assertions with ownerName param

* chore: remove hardware diagnostic logs from hotfix

* chore: restore firmware detect test assertions

---------

Co-authored-by: wabiwabo <68363074+wabicai@users.noreply.github.com>

* fix: correct Pro2 settings and label sync(OK-60188, OK-59745, OK-60258) (#12869)

* fix: correct Pro2 settings display

* fix: show Pro2 Bluetooth name

* fix: sync Pro2 device label with wallet name OK-60258

* test: cover Pro2 serial fallback OK-59745

* fix: separate alphabetic portfolio currency symbols OK-59745

* fix: persist Pro2 label through wallet sync OK-60258

* fix: align segmented slider marks OK-60188

* fix: persist Pro2 label after wallet creation OK-60258

* fix: align Pro2 brightness segment values OK-60188

* fix: correct SegmentSlider test import order

* fix: restore firmware-switch device management behavior (OK-60205) (#12877)

* fix: restore firmware-switch device management behavior (OK-60205)

* chore: upgrade hardware sdk to alpha.123 (OK-60205)

* fix: sync portfolio on idle desktop BLE links (#12845)

* fix: sync portfolio on idle desktop BLE links

* chore: upgrade hardware sdk to alpha.115

* chore: upgrade hardware sdk to alpha.117

* chore: upgrade hardware sdk to alpha.118

* fix: preserve desktop usb portfolio sync

* fix: address desktop portfolio review feedback

* fix: scope desktop portfolio transport guard

* fix: preserve hardware transport and portfolio lease

* fix: narrow background transport pinning

* fix: sync V1 device-side settings changes after device operations (OK-60121) (#12879)

* fix: sync V1 device-side settings changes after device operations (OK-60121)

* chore: gate hardware debug file logging behind showDeviceDebugLogs

* chore: route hardware logs through defaultLogger with dev production-parity switch

* chore: add persist-all-logs switch to dev settings

* fix: resolve Copy Log Path via desktopApi on desktop

* fix: address review feedback on log masking, read-back scope and timeout

* fix: harden v1 settings sync per second review round

---------

Co-authored-by: wabiwabo <68363074+wabicai@users.noreply.github.com>

* fix: support Pro2 and Neo BLE flows (#12871)

* fix: add Neo to hardware onboarding

* fix: handle bluetooth usb conflicts

* chore: upgrade hardware sdk to alpha.124

* chore: upgrade hardware sdk to alpha.125

* fix: preserve Pro QR wallet entry

* chore: upgrade hardware sdk to alpha.126

* fix: sync hardware connection status after reset(OK-60117) (#12892)

* fix: sync hardware connection status after reset OK-60117

* fix: clear and rebroadcast hardware connection identities on SDK reset OK-60117

* fix: remove redundant parens flagged by CI lint

* fix: use SDK dimensions for Pro2 images (#12894)

* chore: upgrade hardware SDK to alpha.129 (#12896)

* fix: sync Pro2 settings and send BLE cancel immediately (#12899)

* Fix/trezor ble row heal on hotfix652 OK-60092 (#12900)

* fix: mark ledger btc change outputs with bip32 derivation

Change outputs need bip32/tapBip32 derivation info so the device nets
them out of the confirmed amount instead of displaying them as a
separate recipient; recipient outputs are left untouched.

* chore: drop unused uuid hoisting override from mobile package.json

* fix: derive Ledger BTC Taproot tapInternalKey from xpub, not the address script

Change outputs and inputs on Taproot (BIP86) Ledger accounts previously
computed tapInternalKey by slicing bytes out of the destination address's
own (already-tweaked) output script, which bitcoinjs-lib rejects when
building PSBT outputs ("Script or address mismatch") and silently mis-fed
to the device for inputs. Derive the pre-tweak pubkey from the account's
xpub instead, matching the pattern already used in KeyringHardwareBtcBase
and this file's signPsbt method.

Also fixes a related landmine: xpubSegwit on Taproot accounts holds a
BIP380 descriptor string (tr([fp/path]xpub/<0;1>/*)), not a base58 xpub,
so the existing xpubSegwit-preferring fallback can't be reused for local
key derivation. Taproot branches now read xpub directly.

* Revert "chore: drop unused uuid hoisting override from mobile package.json"

This reverts commit 0818f25.

* fix: type PSBT input/output data precisely instead of any

Addresses PR review: replace inputData/outputData 'any' with the exact
parameter types of Psbt.addInput/addOutput (extracted via Parameters<>,
since bitcoinjs-lib doesn't export PsbtInputExtended/PsbtOutputExtended
by name), so field typos or shape mistakes on the BIP32/Taproot
derivation fields are caught at compile time instead of at Ledger
signing time.

* fix: align hardware errors, wallet state, and Pro2 workflows (#12905)

* fix: handle onboarding hardware errors across runtimes

* fix: handle reset hardware wallet state

* fix: surface hardware errors across workflows

* fix: align Pro2 QR and settings support

* fix: align portfolio token count

* fix: format portfolio token count

* fix: preserve hardware identity across native RPC

* fix: prevent transient empty portfolio sync

* fix: harden Pro2 firmware update flow

* fix: align hardware connection detection with x

* fix: exclude QR wallets from portfolio sync

* fix: keep Pro2 passphrase settings editable

* fix: complete cross-platform firmware update flow

* fix: preserve hardware connection state across runtimes

* chore: update hardware sdk to 1.2.0-alpha.141

* chore: update hardware sdk to 1.2.0-alpha.142

* fix: scope firmware USB preflight to selected device

* fix: order firmware utility imports

* fix: resolve third-party hardware wallet avatars per device model OK-60448 (#12912)

* fix: resolve third-party hardware wallet avatars per device model

Ledger and Trezor wallets all shared one generic placeholder image
regardless of physical model. Add a resolver that maps the device's
persisted vendorModel (SDK code) / vendorModelName to a per-model
avatar key, fix refillWalletInfo (which ran on every wallet read) to
stop forcing avatars back to the generic vendor key, and wire the
resolver through onboarding scan lists, BLE binding, and the Tray.

* chore: trim overlong comments in avatar resolver

* fix: keep neutral vendor fallback avatars for unrecognized devices

The ledger/trezor fallback keys pointed at the new Nano X / Safe 7
artwork, so an unrecognized or metadata-less device would render as
that specific model instead of a neutral placeholder. Restore the
original generic placeholder art for the two fallback keys and add a
regression test asserting they stay byte-distinct from any
specific-model asset.

* fix: seed canonical device state before hidden wallet passphrase session (OK-59992) (#12908)

* fix: seed canonical device state before hidden wallet passphrase session (OK-59992)

* fix: prefer persisted post-unlock device state in hidden wallet creation

* fix: guard post-unlock device state refresh against empty connect id and third-party vendors

* test: cover manifest-free Pro2 RESC archives (#12924)

* test: cover manifest-free RESC archives

* chore: update hardware sdk to 1.2.0-alpha.143

* chore: update hardware sdk to 1.2.0-alpha.144

* fix: correct Ledger Nano Gen5/Flex asset swap and legacy Trezor One code (#12926)

LedgerNanoGen5.png and LedgerFlex.png had their artwork swapped in the
original asset pack; corrected. Also add the legacy 'internal_model'-less
Trezor One firmware model code ('1', reported by pre-internal_model
firmware instead of 'T1B1') to the resolver, verified against a real
device settingsRaw.

* fix: let SDK own hardware Cancel and bump SDK 148 (#12917)

* fix: guide users to repair invalid BLE bonds

* fix: surface USB-priority errors during device verification

* fix: handle BLE USB-priority errors

* fix: align hardware portfolio count with home visible tokens

* fix: make Pro2 firmware dev setting switches toggle reliably

* fix: hide firmware update exit errors after device reconnect

Map updateTasksClear/exitUpdateWorkflow to a device-disconnected
message, and only exit the workflow after the last update page
actually leaves so remounts do not abort an in-progress install.

* fix: send hardware Cancel only for Pro2/Neo

Skip the device Cancel command when Bluetooth pairing or link setup fails, and never emit it on Classic/Mini/Pro1.

* fix: toast when passphrase toggle already matches device

* fix: resolve firmware update TypeScript lint errors

* chore: upgrade hardware SDK to alpha.146

* fix: skip silent portfolio sync while the device is locked

Only transfer when unlocked on USB and BLE. Firmware DeviceLocked
refusals stop the current attempt and do not retry automatically.

* fix: keep firmware cancel, resume locked portfolio, and bump SDK 147

* fix: let SDK own hardware Cancel and bump to alpha.148

* chore: upgrade hardware SDK to alpha.149

* chore: upgrade hardware SDK to alpha.150

* fix: address hardware review comments and iOS Pro2 switches

* fix: restore desktop usb routing OK-60693 (#12940)

* fix: cache the Earn banner list and keep rich text inline when clampe… (#12938)

* fix: cache the Earn banner list and keep rich text inline when clamped (OK-60299)

Signed-off-by: ezailWang <jelly@onekey.so>

* fix: harden the Earn banner request against staleness, failure and disk cost

Signed-off-by: ezailWang <jelly@onekey.so>

---------

Signed-off-by: ezailWang <jelly@onekey.so>

* fix: detect hardware disconnect on desktop USB and BLE (OK-60486) (#12942)

* fix: detect hardware disconnect on desktop USB and BLE (OK-60486)

The wallet-list connected dot reads the union of navigator.usb enumeration and
a background identity-key map. The map is only ever evicted per-device from the
DEVICE.DISCONNECT handler, and on desktop that event never fired, so once any
interaction had populated it the dot stayed lit until an SDK reset.

The missing event is fixed in hardware SDK 1.2.0-alpha.155; bump to it and pass
the new disconnect reason through the preload bridge.

Also guard refreshDevices with a request sequence: the usb disconnect event and
HardwareConnectionStateUpdate can fetch concurrently, and the slower response
could re-light a device that had already gone.

Log the eviction path, which was previously silent — a disconnect that never
arrived and one that left no trace looked identical in collected logs.

* chore: align hardware SDK version in the cli app

The root manifest was bumped to 1.2.0-alpha.155 but apps/cli was left on
alpha.150, which trips the repo's cross-manifest version-consistency check.

* fix: mask the connect id in the disconnect log and align reason comments

serviceHardwareUtils.hardwareLog reaches a @LogToLocal sink, so the raw
connectId would have shipped in exported logs; mask it like the other device
identifiers do.

The reason comments claimed to separate a real drop from a keep-alive
reclaim, which the transport deliberately does not do — every link drop is
reported. Describe what the field is actually for.

* fix: validate Electron update package before install (OK-59014, OK-58098, OK-53765, OK-45636) (#12700)

* fix: validate electron update package availability

* fix: harden electron update package recovery

* docs: explain native update confirmation boundary

* fix: rehydrate macOS updater before install

* fix: reuse cached macOS update package

* fix: handle macOS updater preparation

* fix: address app update recovery review

* fix: harden desktop update recovery

* fix: isolate app update recovery retries

* fix: prevent updater state rebind during install

* fix: rehydrate persisted desktop update packages

* fix: preserve prepared desktop update on check error

* fix: align Pro2/Neo firmware verify, homescreen and BLE name compatibility (#12933)

* fix: canonicalize Pro2 BLE names and bump SDK to alpha.152

Current Pro2 advertisements use "Pro 2 XXXX". Keep matching older
"Pro2 XXXX" names when repairing bleConnectId, and show the spaced
form in device display names.

* style: format Pro2 BLE name helper imports

* fix: enable normal firmware verify for pro2 neo

* fix(v2 firmware verify): align data/dataHex payload format

* fix(v2 firmware verify): restore wallet challenge format

* fix(verify): hash protocol v2 challenge for firmware verify

* fix(verify): use Pro-style challenge bytes for Pro2 and Neo

Keep wallet data as instanceId_timestamp_random and send the UTF-8
bytes to the device, matching Pro. Firmware must accept the variable-length
message instead of a 32-byte digest.

* fix: use native pro2 and neo device types for homescreen api

* fix: use native pro2 and neo labels and firmware detail types

* chore: upgrade hardware SDK to alpha.157

* fix: repair Pro 2 wallet names, labels, and homescreen fallback

Treat compact and spaced BLE names as the same wallet-name pollution,
keep the shared OneKey Pro onboarding copy, and fall back to Pro
homescreens when native Pro 2 or Neo resources are empty.

* fix: request native pro2 and neo homescreens without a Pro fallback

Dashboard should serve Protocol V2 wallpaper types directly.

* fix: keep unpublished Pro 2 and Neo USB copy as OneKey Pro

Connect-your-device still interpolates getDeviceLabel into the USB
prompt, and those products are not public yet.

* chore: upgrade hardware SDK to alpha.159

* fix: map BlePeerRemovedPairingInformation to DeviceBondError

* chore: upgrade hardware SDK to alpha.160

* fix: format bluetooth error test

* chore: upgrade hardware SDK to alpha.162

---------

Co-authored-by: Leon <lixiao.dev@gmail.com>

* fix: support iOS Fabric WebView navigation (#12947)

* fix: prevent iOS address list liquid glass blur (#12948)

* fix: prevent iOS address list liquid glass blur

* fix: harden iOS scroll edge effect binding

---------

Co-authored-by: huhuanming <huanming@onekey.so>

* fix: align Pro2 firmware and portfolio behavior (#12950)

* fix: surface firmware USB priority error

* fix: exclude zero-value tokens from portfolio other count

* chore: bump hardware sdk to 1.2.0-alpha.168

* chore: bump hardware sdk to 1.2.0-alpha.170

* chore: bump hardware sdk to 1.2.0-alpha.171

* chore: bump hardware sdk to 1.2.0-alpha.172

* fix: keep genuine-check verify dialog interactive on iOS retry (#12951)

* fix: keep genuine-check verify dialog interactive on iOS retry

* fix: gate verify dialog in-page host to iOS

---------

Co-authored-by: huhuanming <huanming@onekey.so>

* fix: keep Android browser content above toolbar(OK-60781) (#12955)

* fix: keep Android browser content above toolbar

* fix: keep Android browser dashboard interactive

* chore: upgrade hardware SDK to 1.2.0-alpha.176 (#12954)

* fix: show Protocol V2 custom wallpapers (#12956)

* fix: support Protocol V2 wallpapers

* fix: generate Protocol V2 wallpaper data on client

* refactor: clarify wallpaper upload routing

* fix: align Protocol V2 wallpaper resource type

* fix: reconcile hotfix/v6.5.2 sync residuals with x

* fix: resolve sync PR lint and unit test failures

* ci: raise startup budgets for 6.5.2 hardware SDK weight

* ci: allow eager HardwarePortfolioSync simpleDb entity in bundle architecture check

* fix: make hardwarePortfolioSync simpleDb getter lazy and add missing native-bundle:bg script

---------

Signed-off-by: ezailWang <jelly@onekey.so>
Co-authored-by: wabiwabo <68363074+wabicai@users.noreply.github.com>
Co-authored-by: huhuanming <huanming@onekey.so>
Co-authored-by: ByteZhang <ByteZhang@protonmail.com>
Co-authored-by: JellyWang <38491708+ezailWang@users.noreply.github.com>
Co-authored-by: limichange <limichange@hotmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants