mirror of
https://github.com/bitwarden/android.git
synced 2026-07-21 00:33:17 -05:00
[GH-ISSUE #6898] Biometric unlock setup fails on EMUI 12 (Huawei proprietary HAL) after 2026.4.0 SDK unlock refactor #109420
Closed
opened 2026-06-06 04:28:21 -05:00 by GiteaMirror
·
8 comments
No Branch/Tag Specified
main
environment-update
PM-40631-display-personal-vault-as-my-vault
sdlc/sdk-update
renovate/lock-file-maintenance
PM-40527-send-controls-policy-data-model
cron-sync-privileged-browsers/70-sync
PM-40295-mp-policy-on-unlock
PM-40278-freeze-public-key
PM-40154-keystore-encrypted-shared-prefs
PM-39902-blob-encryption-support
worktree-QA-2177-blockeduri-testtag
PM-32685/test-support
cron-sync-privileged-browsers/69-sync
release/2026.7-rc58
PM-37256/merge-fill-assist-with-traverse
update-billing-api
agalles/create-deploy-workflow-trigger
llm/plan-implement-review-command
allow-user-certs
vvolkgang/fdroid-update
release/2026.6-rc57
agalles/create-github-workflow-trigger
release/2026.6-rc56
release/2026.5-rc55
release/2026.5-rc53
release/2026.5-rc54
PM-37255/consume-fill-assist-rules-data
PM-26896-autofill-fix
release/hotfix-v2026.4.1-bwpm
target-sdk-37
agalles/fdroid-only
BWA-99/show-next-totp
BWA-99/add-preview-next-totp-code-setting
sync-min-sdk
release/2026.4-rc51
related-origin-passkey-creation
release/2026.4-rc50
platform/android-breaking-change-detection
innovation-sprint-2026-send-folder
release/2026.3-rc49
PM-34193-vault-lockout
android-collections
llm/add-resolving-sdk-updates-skill
QA-1523/sanity-test-saucelabs
release/2026.3-rc48
release/2026.2-rc47
pr-6572
release/2026.2-rc46
release/2026.1-rc45
PM-30644/added-logs-for-debug
PM-30644/quicktile-nav-not-showing-migration
minor-gradle-updates
release/2026.1-rc42
release/2026.1-rc44
release/2026.1-rc43
PM-28834/set-landscape-on-horizonos-devices
PM-28468/validate-and-navigate-to-vault-migration
PM-20026/force-ltr-passwords-and-codes
release/2025.12-rc41
cmcg/testCoverage
PM-29014/talkback-support-for-passwords
release/2025.12-rc40
BRE-1305/publish_test
accept-user-certs
autofill-permissions
release/2025.11-rc39
PM-22479/check-all-certificates-validate-asset-links
release/2025.10-rc38
agalles/android-latest
retro-agent
PM-27001/skip-account-selection-only-one-exists-cxp
release/2025.10-rc37
agalles/test-1118
release/2025.10-rc36
PM-20593-token-refresh
QA-1126b/adding-native-sanity-test
release/2025.9-rc35
pm-25933/sdk-update-password
release/2025.9-rc34
release/2025.8-rc33
agalles/20250821-release
debug-release-issues
pm-24249-allow-automated-prs-for-sdk-updates
release/2025.8-rc32
release/WORKFLOW-TEST-2025.8-rc28
agalles/20250807release
release/2025.07-rc25
release/hotfix-v2025.7.0-bwa
pm-23311/export-vault-policy-bypass
release/2025.07-rc24
authenticator-pm-sync-flags-issue
release/hotfix-v2025.6.0-bwpm
release/2025.06-rc21
agalles/automate-android-fastlane-patch
release/2025.05-rc20
release/2025.04-rc19
languages/basque
release/2025.03-rc19
update-readme
qrcode/feature
innovation/archive/pm-19153-archive-items
qrcode/2-ui-fields
qrcode/1-page
hold-on-biometric-prompt-alternative
release-notes-process
release/2025.02-rc16
bwa-monorepo
PM-8223/new-device-verification-ux-improvements
pm-18451/exempt-from-policies
test-bwa
release/2025.01-rc15
release/2025.01-rc14
release/2024.12-rc13
pm-16670/sync-leave-notice
821
PM-16695/backport-lean-more-new-device-verification
release/hotfix-v2024.11.7
release/2024.11-rc1
pm-11304/collection-add-item-button
PM-14241/disabling-logs-app-crash
poc/offline-editing
new-version-calc
pm-11649/expired-link-services
pm-6702/add-feature-flag
pm-6702/email-verification-feature
pm-9933/marketing-copy-update
pm-6702/registration-flows
update-templates
pm-6701/email-verification-selfhost-registration
v2026.6.1-bwa
v2026.6.1-bwpm
v2026.6.0-bwpm
v2026.6.0-bwa
v2026.5.1-bwpm
v2026.5.1-bwa
v2026.5.0-bwpm
v2026.5.0-bwa
v2026.4.2-bwpm
v2026.4.1-bwa
v2026.4.1-bwpm
v2026.4.0-bwa
v2026.4.0-bwpm
v2026.3.1-bwa
v2026.3.1-bwpm
v2026.3.0-bwpm
v2026.3.0-bwa
v2026.2.1-bwpm
v2026.2.1-bwa
v2026.2.0-bwpm
v2026.2.0-bwa
v2026.1.1-bwa
v2026.1.1-bwpm
temp-test
v2026.1.0-bwpm
v2026.1.0-bwa
v2025.12.1-bwa
v2025.12.1-bwpm
v2025.12.0-bwa
v2025.12.0-bwpm
v2025.11.1-bwpm
v2025.11.1-bwa
v2025.11.0-bwpm
v2025.11.0-bwa
v2025.10.1-bwa
v2025.10.1-bwpm
v2025.10.0-bwa
v2025.10.0-bwpm
v2025.9.1-bwa
v2025.9.1-bwpm
v2025.9.0-bwa
v2025.9.0-bwpm
v2025.8.1-bwa
v2025.8.1-bwpm
v2025.8.0-bwa
v2025.8.0-bwpm
v2025.7.2-bwa
v2025.7.2-bwpm
v2025.7.1-bwa
v2025.7.1-bwpm
v2025.7.0-bwa
v2025.7.0-bwpm
v2025.6.1-bwpm
v2025.6.0-bwa
v2025.6.0-bwpm
v2025.1.0-bwa
v2025.5.0-bwa
v2025.5.0-bwpm
v2025.5.999
2025.4.0
v2025.4.0
untagged-4731eaadac73f3dfbbb8
v2025.3.0
v2025.2.0
untagged-815a165c5d70ffe75bc7
v2025.1.2
v2025.1.1
v2025.1.0
v2024.12.0
untagged-5a76b6392a4c8998c63a
v2024.11.7
v2024.11.6
v2024.11.5
v2024.11.4
v2024.11.3
v2024.11.2
v2024.11.1
v2024.11.0
v2024.10.2
v2024.10.1
v2024.10.0
v2024.9.0
v2024.8.1
v2024.8.0
v2024.7.3
v2024.7.2
v2024.7.1
v2024.7.0
v2024.6.1
v2024.6.0
v2024.5.1
v2024.4.1
v2024.4.2
v2024.4.0
v2024.3.3
v2024.3.1
v2024.3.0
v2024.2.1
v2024.2.0
v2024.1.1
v2024.1.0
v2023.12.0
v2023.10.0
v2023.9.2
maui-single-project-android
v2023.9.1
v2023.9.0
v2023.8.0
v2023.7.0
v2023.5.0
v2023.4.0
v2023.3.2
v2023.3.1
v2023.3.0
v2023.2.0
v2023.1.0
v2022.11.0
v2022.10.0
v2022.9.1
v2022.9.0
v2022.8.0
v2022.6.2
v2022.6.1
v2022.6.0
v2022.05.0
v2.18.0
v2.17.0
v2.16.4
v2.16.3
v2.16.2
v2.16.1
v2.15.0
v2.14.2
v2.14.1
v2.14.0
v2.13.0
v2.12.0
v2.11.3
v2.11.2
v2.11.1
v2.11.0
v2.10.0
v2.9.1
v2.9.0
v2.8.2
v2.8.1
v2.8.0
v2.7.2
v2.7.0
v2.6.1
v2.6.0
v2.5.6
v.2.5.5
v2.5.5
v2.5.4
v2.5.3
v2.5.2
v2.5.1
v2.5.0
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.1
v2.3.0
v2.2.8
v2.2.7
v2.2.6
v2.2.2
v2.2.1
v2.2.0
v2.1.2
v2.1.0
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.22.1
v1.22.0
v1.21.0
v1.20.0
v1.19.0
v1.18.1
v1.18.0
v1.17.0
v1.16.0
v1.15.2
v1.15.1
v1.15.0
v1.14.4
v1.14.1
v1.14.0
v1.13.0
v1.12.2
v1.12.1
v1.12.0
v1.11.1
v1.11.0
v1.10.0
v1.9.0
v1.8.1
v1.8.0
v1.7.0
v1.6.5
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.4
v1.4.3
v1.4.0
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/android#109420
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @CrayCJ on GitHub (May 9, 2026).
Original GitHub issue: https://github.com/bitwarden/android/issues/6898
Steps To Reproduce
Workaround that reveals the bug:
Expected Result
On a device with Class 3 hardware biometrics that previously supported biometric unlock in older Bitwarden versions, the option should remain available and the toggle should reflect the actual active state. At minimum, if biometric authentication works (as demonstrated by the workaround), the settings UI should not indicate incompatibility.
Actual Result
Two separate failure modes:
1. Fresh install on 2026.4.0: The biometric unlock option is grayed out and cannot be enabled at all. The new SDK-based unlock service introduced in the 2026.3/2026.4 cycle calls
canAuthenticate(BIOMETRIC_STRONG)via the Bitwarden Rust SDK's Android verifier (bitwarden_uniffi::android_support), which returns a non-success code on this device.2. After workaround (key created on 2025.1.0, then updated to 2026.4.0): Biometric unlock works correctly for vault access, but the settings toggle is grayed out with the incompatibility message. This indicates that the setup/availability check and the actual authentication path are now decoupled: the setup check (
canAuthenticate(BIOMETRIC_STRONG)) fails, while the runtime authentication against the existing Android Keystore key succeeds.Screenshots or Videos
No response
Additional Context
I used Claude AI to troubleshoot this issue which led to the workaround above. I then instructed Claude to write up its findings for this bug report:
Root cause analysis via ADB diagnostics:
The device uses Huawei's proprietary biometric HAL instead of the standard Android BiometricService:
vendor.huawei.hardware.biometrics.fingerprint@2.2-servicevendor.huawei.hardware.biometrics.hwfacerecognize@2.0-serviceRunning
adb shell dumpsysbiometric returns empty output, confirming that no standard Android BiometricService is present. This meanscanAuthenticate(BIOMETRIC_STRONG)queries a service that does not respond as expected, causing the new SDK-based unlock service to treat the device as incompatible.Why it worked before the regression: Prior to the "Refactor unlock service to use Bitwarden SDK" change, Bitwarden used the AndroidX
BiometricManagercompatibility library, which contains device-specific workarounds for known non-standard biometric HAL implementations (including older Huawei/EMUI devices). The new native Rust SDK implementation does not appear to apply these workarounds.Why banking apps work but Bitwarden setup doesn't: Other apps using biometrics (e.g. banking apps) call
BiometricPromptwithout aCryptoObject— simple identity verification. Bitwarden requiresBiometricPromptwith aCryptoObject(hardware-backed Keystore key), which is the BIOMETRIC_STRONG path. The Keystore authentication itself succeeds once the key exists; only the availability check via the new SDK fails.Also noted in ADB logcat during device unlock:
This suggests the Huawei biometric HAL process is denied permission to add auth tokens to the Android Keystore — further evidence of the non-standard integration between Huawei's proprietary biometric stack and the standard Android Keystore/BiometricManager APIs.
Suggested fix directions:
BiometricManageruses, within the SDK's Android verifier.canAuthenticateresult when an existing valid biometric Keystore key is present and functional.Build Version
2026.4.0 (21434)
What server are you connecting to?
Self-host
Self-host Server Version
Vaultwarden Web 2026.4.1 (1.36.0)
EDIT: Issue also recreated with bitwarden.com account: On my device with app version 2026.4.0 (21434), the biometrics option is grayed out, eventhough it has class 3 biometrics available. But the workaround found does not work, as logins with the older app version 2025.1.0 (19622) seem to be rejected by the server ("an error occured, try again"). This suggests that the issue is not connected to the server, but the workaround seems to be.
Environment Details
Device: Huawei Mate 20 Pro (LYA-L29)
OS: EMUI 12.0.0 (Android 10, API 29)
Biometric hardware: Class 3 fingerprint sensor + 3D face unlock (Huawei proprietary HAL)
Bitwarden source: F-Droid
Google Play Services: present
Issue Tracking Info
@bitwarden-bot commented on GitHub (May 9, 2026):
Thank you for your report! We've added this to our internal board for review.
ID: PM-36981
@pamperer562580892423 commented on GitHub (May 10, 2026):
Vaultwarden server version 1.36.0 then, I guess?
@CrayCJ commented on GitHub (May 10, 2026):
Yes, 1.36.0. Sorry, for not clarifying that. I added this info to the bug report above.
@pamperer562580892423 commented on GitHub (May 10, 2026):
I really don't know how accurate the Claude AI analysis is... but can you reproduce this issue whit a BW cloud account?
@rmcdowell-bitwarden commented on GitHub (May 11, 2026):
Hi there,
It is important to note that Vaultwarden is not associated with Bitwarden. Vaultwarden is a re-writing of the Bitwarden server code in Rust, that is not contributed to nor supported by the Bitwarden team or organization. The security audits granted to Bitwarden do not apply to Vaultwarden, and the Bitwarden support team is not able to respond to questions regarding Vaultwarden. Support options for Vaultwarden are found here:
https://github.com/dani-garcia/vaultwarden?tab=readme-ov-file#get-in-touch
Please only report issues on Bitwarden's repositories when you are able to reproduce the behavior with an official Bitwarden server (cloud or self-hosted).
You can find information about using Bitwarden's self-hosted servers here: https://bitwarden.com/help/self-host-bitwarden/
This issue will now be closed.
Thanks!
@sw5ciprl commented on GitHub (May 14, 2026):
I believe that the server used here isn't relevant, as the change comes from client-side APIs. Maybe this should be reopened? @rmcdowell-bitwarden
@CrayCJ commented on GitHub (May 16, 2026):
@sw5ciprl:
Yes: I'm able to recreate my issue with bitwarden.com account: On my device with app version 2026.4.0 (21434), the biometrics option is grayed out, eventhough it has class 3 biometrics available. But the workaround found does not work, as logins with the older app version 2025.1.0 (19622) seem to be rejected by the server ("an error occured, try again"). This suggests that the issue is not connected to the server, but the workaround seems to be. I added this info to the initial bug report. I also don't know, how accurate Claude is in this, I just wanted to provide all info I have and be helpful.
Whether this issue is addressed, is up to you, @rmcdowell-bitwarden. With Vaultwarden, the workaround works.
@Cosaque commented on GitHub (May 19, 2026):
Got exactly the same problem.
Used workaround too to temporary resolve.