Commit Graph

1014 Commits

Author SHA1 Message Date
Eran Messeri
5cf3783938 Merge "KeyStore: X25519 key import" am: 9db6ee342b am: 03e7318d7d am: 65f1d04dcd
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2183495

Change-Id: I5e1da00bef3f5185396ade33cea906075b4770e9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-25 16:19:00 +00:00
Prashant Patil
25c8f48a8d KeyStore: X25519 key import
Added a KeyAgreement algorithm for X25519(XDH) in KeyProperties.
KM_ALGORITHM_EC is used for XDH because Keymint uses KM_ALGORITHM_EC along
with Curve25519 to differentiate X25519 and other EC keys.

Algorithm name XDH is set for X25519 private key.

Consilidated methods of Keymaster specific conversions of EC_CURVE into
KeymasterUtil.

Bug: 240682299
Test: run cts -m CtsKeystoreTestCases -t android.keystore.cts.Curve25519Test#x25519KeyImportAndAgreementTest
Change-Id: I3f95738194e62be0f1d821b1eb467ed810a5a175
2022-11-14 14:51:15 +00:00
Eran Messeri
6a6a9e73fd Merge "Keystore: EC_CURVE tag added import agruments" am: edce19fef7 am: 51c53d6357 am: 7811859715
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2164659

Change-Id: I81c11e5af30d15b7f1ea74e46c55d40e515f23ff
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-04 17:13:52 +00:00
Eran Messeri
edce19fef7 Merge "Keystore: EC_CURVE tag added import agruments" 2022-11-04 15:59:42 +00:00
TreeHugger Robot
e436b2988a Merge "Annotate KeyStore service as never null" 2022-10-05 01:57:11 +00:00
Treehugger Robot
6ee781740a Merge "Keystore:Expected exception for invalid Keys" am: 4fe1ed8e51 am: d3472b9eed am: 90969f2230 am: 1e6ff36751 am: 34a5947082
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2175743

Change-Id: Ifacca68b9dd4f594f9720c027ff3bdf9e5b6a04c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-04 18:37:31 +00:00
Tomasz Wasilczyk
5ead731c57 Annotate KeyStore service as never null
Bug: 245258360
Change-Id: I4d9215486df275012dad495730ce0ff00839b7a6
Test: TH
2022-09-23 21:43:09 +00:00
Prashant Patil
0ee5912b75 Keystore:Expected exception for invalid Keys
If EC curves of Public and Private keys are different, an
InvalidKeyException is expected.

But the current implementation does not throw exception from doPhase method
and fails in generateSecret method.

The fix is in AndroidKeyStoreECPublicKey to provide
correct ECParameterSpec while creating a PrivateKey object.

Bug: 215175472
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp224r1
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp256r1
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp384r1
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp521r1
Test: run cts -m CtsKeystoreTestCases -t android.keystore.cts.KeyAgreementTest#testDoPhase_withDifferentCurveKey_fails
Change-Id: Ie221926d8a3be3fe6679e723575c5021cafba98e
2022-09-22 11:40:59 +01:00
Prashant Patil
a2b8cdd04e Keystore: EC_CURVE tag added import agruments
As per Keymint documentation EC key import has to provide EC_CURVE tag.
This is required for Strongbox implementation test using wycheproof test
cases.

Also added a support to get KEY_SIZE based on EC_CURVE, if it is not
included into Authorization list.

Bug: 237634216
Test: run cts -m CtsKeystoreWycheproofTestCases
Change-Id: Ie981721c38477e74da3cba6613dc0b34e453609c
2022-09-21 16:27:34 +01:00
Treehugger Robot
4eb3e94812 Merge "Keystore: Included KM_TAG_RSA_OAEP_MGF_DIGEST tag" am: eea63d6aa4 am: f42d5e8847 am: 72b1cc3e49 am: 3f20176ddf am: 074bff50de
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2167462

Change-Id: I6479a9d91248581cadf7cf4acab02b9e01cc6ad2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-20 16:02:16 +00:00
Prashant Patil
0443f760d0 Keystore: Included KM_TAG_RSA_OAEP_MGF_DIGEST tag
Included KM_TAG_RSA_OAEP_MGF_DIGEST for RSA keys generation and import
if supported padding is defined as OAEP. All supported digest are added
as KM_TAG_RSA_OAEP_MGF_DIGEST and also default MGF1-SHA1 digest is added
because crypto operations could fail is MGF1ParameterSpec is not provided.

Note this includes additional Attestation parameter in returned
certificate and need to handle accordingly.

Bug: 203688354
Test: run cts -m CtsKeystoreTestCases -t android.keystore.cts.CipherTest#testKatBasicWithDifferentProviders
Change-Id: I2086f2520667ccac9116e04de39f6328a0d3fc5b
2022-09-14 15:26:12 +01:00
Eric Biggers
34945b1fd2 AndroidKeyStore: support platform use of rollback-resistant keys
The keystore2 binder API supports rollback resistance when KeyMint
supports it, but until now this wasn't exposed to Java code that uses
AndroidKeyStore.  Add support for rollback-resistant keys to
KeyProtection and AndroidKeyStoreSpi.setSecretKeyEntry() so that
LockSettingsService can request it for SP protector keys.

This CL does *not* do any of the following:

- Add any non-hidden APIs.  KeyMint implementations only support a
  limited number of rollback-resistant keys; currently the available
  space is reserved for platform use only.  Note that other examples of
  "hidden", platform-only key properties are
  isCriticalToDeviceEncryption() and getBoundToSpecificSecureUserId().

- Support rollback resistance with keys directly generated by Keystore.
  This isn't currently needed.  Note that this would require changes
  KeyGenParameterSpec and AndroidKeyStoreKeyGeneratorSpi.

- Allow querying the rollback resistance property of keys.  This isn't
  currently needed.  Note that this would require changes to KeyInfo and
  AndroidKeyStoreSecretKeyFactorySpi.

Bug: 239632930
Test: see I05f3b7e5c139471febe5c266a39e3dc3bca4831f
Change-Id: Ifcfd0b8f1bf440ef1ac80a9ac2b0e9c7f62106dd
2022-07-23 00:38:03 +00:00
Seth Moore
8cf2a52033 Ensure key generation retries after remote key provisioning
Previously, the key pair generation would error out even if we
successfully provisioned attestation keys. Instead, we should retry
key generation after the GenerateRkpKeyService reports an OK status.

Bug: 231495834
Test: RemoteProvisionerUnitTests
Change-Id: I049294cbc7119de55b5de02499bf4609d4c6de5d
2022-05-12 17:18:22 -07:00
Eran Messeri
4c20e224f6 Keystore: Wire X25519 key agreement
Implement support for the X25519 key agreement functionality.

Similar to Ed25519, two new classes are added:
* AndroidKeyStoreXDHPrivateKey
* AndroidKeyStoreXDHPublicKey

The private key class is simply a handle to the KeyMint key.
The public key class implements XECPublicKey, the interface
needed for using this key in a platform-backed key agreement.

Because of Conscrypt API boundaries, the functionality of Conscrypt's
OpenSSLX25519PublicKey is duplicated here - namely, matching the
prefix of the encoded key.

Bug: 194359292
Test: atest android.keystore.cts.Curve25519Test
Change-Id: Ifc12be528ab544fd6909bb0dd6224a0a4dd400c6
2022-05-12 10:56:30 +01:00
Eran Messeri
46faab535f Keystore: Wire up Ed25519 signing
Wire Ed25519 signing into Keystore. This consists of registering a
provider for Ed25519.

Ed25519 has its own digest scheme, so the caller should specify "none"
as the digest scheme, and that's the tag that's going to be passed into
KeyMint.
However, unlike other uses of the "NONE" digest scheme, the input to the
signature algorithm should not be truncated.

Bug: 194359292
Test: atest android.keystore.cts.Curve25519Test
Change-Id: Icce4f7f2f8fa10081a9c6beff4813c2d91756469
2022-05-11 18:53:04 +01:00
Eran Messeri
143fa39384 Keystore: Support Ed25519 keys
Implement support for Ed25519 signing keys in Android Keystore.
Because Conscrypt does not yet handle those keys, the Keystore classes
implement EdECPublicKey directly and parse the keys.

Specifically, AndroidKeyStoreEdECPublicKey can take an encoded X.509 key
specification, validate the encoding is of an Ed25519 key, then parse
the oddity and Y point on the curve.
RFC8032 describes EdDSA signature scheme, particularly Ed25519.
RFC8410, Section 3, defines the OID for Ed25519 keys (1.3.101.112).
RFC8410, Section 4, describes the encoding of the public key.

Bug: 195309719
Bug: 194359292
Bug: 214203951
Test: atest android.security.keystore2.AndroidKeyStoreEdECPublicKeyTest
Change-Id: I07b793cbd5029630768368ad4a863bbc1c828ced
2022-05-05 14:58:52 +01:00
Seth Moore
6615ac8b34 Merge "Make generateKey() return a status" am: d6dbf31c61 am: 34eb18107d am: c6030f0765
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2048789

Change-Id: Ib86d332d64f0fae0d83d52a6e55d9dfc25c4f06b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-21 18:25:10 +00:00
Max Bires
9510ef1aa2 Make generateKey() return a status
This change adds some integers to the AIDL interface in order to convey
status back to the caller of generateKey(). This will inform the caller
as to whether or not the errors that may occur during provisioning are
permanent, and if not, what to do with the transient error.

Bug: 227306369
Test: RemoteProvisionerUnitTests
Change-Id: I9202358a102b0fb0a104525632a005acb7355840
2022-04-20 14:31:54 -07:00
David Drysdale
90099ff85c Merge "Clarify doc comment for setUnlockedDeviceRequired" am: a0976a1207 am: f6354a20d5 am: 9025d607a0
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2060058

Change-Id: Id9255df063a48ea3006b9cada59cc5d9543f17ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-13 09:10:13 +00:00
David Drysdale
c92b407979 Clarify doc comment for setUnlockedDeviceRequired
Bug: 187537410
Test: None, comment change only
Change-Id: If6085fa6f46a54df0700e2599f4f98e42f33a164
2022-04-12 14:57:53 +01:00
Eran Messeri
dfe33810c0 KeyStore: Surface RKP failures
On systems that rely solely on remotely-provisioned keys (RKP),
the attestation keys may run out or be unavailable for attesting
a newly-generated key. This could happen when:
* the device first connects to the Internet
* The device had all the keys used and:
 ** It hadn't yet completed obtaining new ones.
 ** The RKP server declines to issue new keys.

In these cases, the caller must be informed that their key generation
request failed (likely temporarily), and that they should retry it.

The retry policy returned tells the caller when to re-try.
Bug: 227306369
Test: atest android.keystore.cts.KeyStoreExceptionTest

Merged-In: Ief30a3ab97da95b68d172e725c38acbefab92fa9
Change-Id: I0b2619fcbcb3ac4d94ed85f3ce5934e015c0828c
2022-03-31 11:06:30 +01:00
Eran Messeri
fda47fb1ca KeyStore: Surface RKP failures
On systems that rely solely on remotely-provisioned keys (RKP),
the attestation keys may run out or be unavailable for attesting
a newly-generated key. This could happen when:
* the device first connects to the Internet
* The device had all the keys used and:
 ** It hadn't yet completed obtaining new ones.
 ** The RKP server declines to issue new keys.

In these cases, the caller must be informed that their key generation
request failed (likely temporarily), and that they should retry it.

The retry policy returned tells the caller when to re-try.
Bug: 227306369
Test: atest android.keystore.cts.KeyStoreExceptionTest

Change-Id: Ief30a3ab97da95b68d172e725c38acbefab92fa9
2022-03-30 15:03:16 +01:00
John Wu
7128e88488 Merge "Revert "Update AndroidKeyStoreMaintenance framework API"" am: b8ebf69571 am: 2e64dda571 am: 289609bdb3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2017095

Change-Id: Iddeb472553b4713fc51613effa6e565188119bf8
2022-03-23 17:20:24 +00:00
John Wu
23571e176a Revert "Update AndroidKeyStoreMaintenance framework API"
This reverts commit bb5c49e510.

Reason for revert: functionality removed

Change-Id: Ib04a1690b8892af53ca6449e3a38e10490baf9da
2022-03-14 15:20:38 -07:00
Treehugger Robot
6de84e117e Merge "Curve 25519: Support use via Android Keystore provider (part 1)" am: bab26cc607 am: 050d61f1b3 am: 8249f4a893
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2015496

Change-Id: I666cce14a67b605c9cc64991ee07755b4d85173a
2022-03-09 22:51:22 +00:00
Eran Messeri
3875cf7e0c Curve 25519: Support use via Android Keystore provider (part 1)
Ensure that the user gets an accurate error message when they try to
generate Curve 25519 keys according to JEP 324
(https://openjdk.java.net/jeps/324).

Android Keystore requires every key to have a name, so it is not
possible to generate a key using NamedParameterSpec only (with a
KeyPairGenerator).

Support this and throw an exception to the caller indicating how they
_can_ generate keys with this curve.

Bug: 222440855
Bug: 195309719
Bug: 194359292
Test: atest android.keystore.cts.KeyFactoryTest android.keystore.cts.Curve25519Test
Test: atest CtsLibcoreTestCases:libcore.java.security.ProviderTest
Change-Id: I5aa163f177507906c6482d079eb6cb55d93accf7
2022-03-09 13:07:52 +00:00
Eran Messeri
259ca1ec61 Do not register Curve25519 as a key factory directly
Do not register Curve 25519 algorithms as key factories, until we fix
the registration to be in compliance with JEP 324.

Bug: 222440855
Bug: 222194540
Test: atest android.keystore.cts.Curve25519Test android.keystore.cts.KeyFactoryTest#testAlgorithmList CtsLibcoreTestCases:libcore.java.security.ProviderTest#test_Provider_getServices
Merged-In: Ibd53070a890955affaff5e4e7213892afd423db7
Change-Id: I11b3574aeff54b3eb8bf496c4c14aa1338629ce5
2022-03-09 11:03:12 +00:00
Eran Messeri
7dece49438 Do not register Curve25519 as a key factory directly
Do not register Curve 25519 algorithms as key factories, until we fix
the registration to be in compliance with JEP 324.

Bug: 222440855
Bug: 222194540
Test: atest android.keystore.cts.Curve25519Test android.keystore.cts.KeyFactoryTest#testAlgorithmList CtsLibcoreTestCases:libcore.java.security.ProviderTest#test_Provider_getServices
Change-Id: Ibd53070a890955affaff5e4e7213892afd423db7
2022-03-07 18:33:56 +00:00
Treehugger Robot
452fdef120 Merge "Keystore: Support Curve 25519 in the SPI layer" am: 76cee808e2 am: 7b17653639 am: cb479e0827
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1984970

Change-Id: Ib9fc34d05614192e4762b9e7934738e074728fca
2022-03-01 21:07:01 +00:00
Eran Messeri
5deebdd570 Keystore: Support Curve 25519 in the SPI layer
Add support for Curve 25519 in the public API.
This requires upgrading the keymint dependency to V2.

Note that this CL only passes tha tags to Keystore,
but does not yet let the caller use the generated keys
because of missing Conscrypt classes.

Bug: 194359292
Test: atest android.keystore.cts.Curve25519Test
Change-Id: I15223abec34b72c857e26fcc47d8ecf08c1f8c8d
2022-03-01 15:00:19 +00:00
Rubin Xu
c96b611d14 KeyChain: always unbind service
Context.unbindService() should always be called even if the
previous bindService() call returns false. Otherwise the service
might be left dangling.

Bug: 211582968
Test: None
Change-Id: Ic1705096254afa12993d8992303432896bfecd57
2022-02-24 15:44:55 +00:00
Eran Messeri
ee3c80f288 Merge "Keystore: Surface service error message" am: af771eb908 am: b3612e019f am: e53fd593b5 am: a2b165989b
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1969819

Change-Id: I0f3d9721af9aa47bf7f7ae6a419d79ec3547210b
2022-02-08 19:50:28 +00:00
Eran Messeri
5eedf5a373 Keystore: Surface service error message
Surface the service-specific error message. To avoid API changes, the
error message is surfaced in the toString / getMessage methods.

Test: atest android.security.keystore.KeyStoreExceptionTest
Bug: 217593122
Change-Id: Id4090564b46db9b3b10ea390390f6683f7314463
2022-02-08 13:26:57 +00:00
Eran Messeri
a31689bc37 KeyStore: Verbose error reporting
Report KeyStore/KeyMint error messages via public API.

This lets developers find out:
* Whether an error is transient or not.
* Whether a failure is due to a system error
(system configuration/state/capabilities), or a key-related error.
* Whether user authentication is required to use the key.

Test: atest CtsKeystorePerformanceTestCases CtsKeystoreTestCases
Bug: 197890905
Merged-In: I776d9e9cc01a9dc3542a63000ee0709847760963
Change-Id: Ica0c93fdd4b89255ee0a03a9b9b948202777d4d4
2022-02-02 22:11:44 +00:00
John Wu
14ce8bc120 Framework support for AndroidKeyStore migration
- Add a new boolean attribute `inheritKeyStoreKeys` to allow apps to
  indicate whether they want keys to be transferred to the updated app
- Call the appropriate KeyStore method to migrate keys from the old
  namespace to the new one
- Clear keys owned by the previous app ID if it is removed

Test: atest SharedUserMigrationTest#testKeyMigration
Test: atest AndroidPackageTest
Bug: 179284822
Change-Id: I321b85b88c150f17709a2270c0cbaf368ca035cc
2022-01-21 01:36:43 +00:00
John Wu
1c632f80e8 Merge "Update AndroidKeyStoreMaintenance framework API" am: 8c34efd29a am: be201a0ed5 am: 7d7010dcf8 am: 253c91192f
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1950401

Change-Id: I8b3f892d829decc104ef2a732af5fbbfa3e08fa8
2022-01-19 01:13:31 +00:00
John Wu
bb5c49e510 Update AndroidKeyStoreMaintenance framework API
Update the Java framework accordingly with the underlying keystore2
changes for key migration.

Test: atest SharedUserMigrationTest#testDataMigration (in internal)
Bug: 211665859
Change-Id: I26c817dffdf2e50a43373114a63242644ee7e712
2022-01-14 15:35:07 -08:00
Seth Moore
ea9d0dd167 Merge "Add missing </pre> to Javadoc" am: 076fb5e987 am: d084c0202a am: 33e0b830dc am: a665f6bd93
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1905490

Change-Id: I5965b31cb15b2cf30596939d4c5cb70e51b332b9
2022-01-07 17:34:34 +00:00
Seth Moore
076fb5e987 Merge "Add missing </pre> to Javadoc" 2022-01-07 16:40:32 +00:00
Eran Messeri
5da05ee3ed KeyStore: Verbose error reporting
Report KeyStore/KeyMint error messages via public API.

This lets developers find out:
* Whether an error is transient or not.
* Whether a failure is due to a system error
(system configuration/state/capabilities), or a key-related error.
* Whether user authentication is required to use the key.

Test: atest CtsKeystorePerformanceTestCases CtsKeystoreTestCases
Bug: 197890905
Change-Id: I776d9e9cc01a9dc3542a63000ee0709847760963
2021-12-14 15:22:35 +00:00
Seth Moore
c78e369c4c Fix incorrect SID matching for bio prompts
The default value for canUnlockViaBiometrics, which determines if we
are able to show a bio prompt, is true. However, if there are 0
biometric authenticator IDs, then it's impossible for the user to
satisfy a bio prompt. In this case, we should set canUnlockViaBiometrics
to false.

The loop that is normally expected to invert canUnlockViaBiometrics was
never run in the case of 0 bio authenticator ids, so we mistakenly
let the crypto init operation succeed when we should have blocked it.

Bug: 188864794
Test: Manual, using sample app that displays a biometric prompt.
Change-Id: Ib95b0564aa098157718b8d4a45b11baa69dad71b
2021-12-01 14:59:24 -08:00
Shawn Willden
f3aac252f7 Add missing </pre> to Javadoc
Change-Id: Iedf0f7f85fecbc2ee274a108887c77add62dcb31
2021-11-29 19:20:19 +00:00
Treehugger Robot
70e7dd44b4 Merge changes Ic6e60752,I2b8b7e74
* changes:
  Test for contract between AndroidKeyStoreKey hash and equals.
  Keystore 2.0 SPI: Fix contract between equals and hashCode 2
2021-10-08 15:31:03 +00:00
Janis Danisevskis
2eef723ced Merge "Keystore 2.0 SPI: Fix NullPointerException in setKeyEntry." 2021-10-08 14:57:47 +00:00
Janis Danisevskis
5fe5f2def0 Test for contract between AndroidKeyStoreKey hash and equals.
Test: atest KeystoreTests
Bug: 196118021

Merged-In: Ic6e60752faa986debe3d325f54242cffaa03b336
Change-Id: Ic6e60752faa986debe3d325f54242cffaa03b336
2021-10-07 16:39:39 -07:00
Janis Danisevskis
e36fe6bf46 Keystore 2.0 SPI: Fix contract between equals and hashCode 2
This fixes the contract between equals and hashCode in
AndroidKeystorePublicKey. The previous fix made only a reference
comparisson between certificate blobs. In this patch java.util.Arrays is
used to compare and compute the hash of the array.

Bug: 196118021
Test: See following CL.
Change-Id: I2b8b7e740fb377de39fd21f763e15cb00024b2fc
2021-10-07 16:24:46 -07:00
Janis Danisevskis
4ff6274fa7 Keystore 2.0 SPI: Fix NullPointerException in setKeyEntry.
Fix a NullPointerException when trying to insert SecretKey that already
exists.

Bug: 202146009
Test: atest android.keystore.cts.AndroidKeyStoreTest#testKeyStore_SetKeyEntry_ReplacedWithSameGeneratedSecretKey
Change-Id: If3a4bd6677ab3173c5c1a7c921ba567b7981662b
2021-10-07 08:24:42 -07:00
Treehugger Robot
6939d8d665 Merge "Fix key alias string comparison" am: 15d1ab2fdd
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1802873

Change-Id: I20bb1006d93233dfe7dd73c12a0eaadee229e3d5
2021-08-24 17:52:12 +00:00
Seth Moore
11cce949b6 Fix key alias string comparison
The code was doing a reference compare, not object value comparison,
resulting in failures in the KeyStore setEntry API.

Test: CtsKeystoreTestCases:android.keystore.cts.AndroidKeyStoreTest
Fixes: 197138784
Change-Id: I2c5e47283eed5694951869e9ea3853364ddef9d1
2021-08-19 12:44:08 -07:00
Max Bires
f5e0c3e257 Merge "Fixing a condition that can cause deadlock" am: 773a378390
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1797475

Change-Id: Id20947de8b039d4a468127a446266c30fbbd1659
2021-08-18 02:06:57 +00:00