Field Notes

source

CalyxOS hiatus and return announcements

Letter to the community. Official release is back.

Two pages from the CalyxOS project, captured 28 July 2026. The first is the August 2025 letter announcing the project’s hiatus, which the project kept as a living document and appended nine dated updates to between August 2025 and July 2026. The second announces the return to maintained releases. Together they are the project’s own record of an eleven-month suspension of security updates.

The timeline the letter records

Date Event
1 August 2025 Hiatus announced; leadership transition disclosed
5 August 2025 Project recommends users uninstall CalyxOS
27 August 2025 Final OTA pushed to warn remaining users
30 September 2025 New contact channels for the team
10 November 2025 Progress report on signing and team capacity
17 December 2025 Signing-ceremony preparation
24 February 2026 HSM-based signing process completed
1 April 2026 Detailed progress breakdown
4 May 2026 Android 16 test build (7.2.1.0)
1 July 2026 Release 7.2.2.0; full maintenance restored

Two departures prompted it: Nicholas Merrill, the founder and president, and Chirayu Desai, the technical lead. Ellen McDermott became interim executive director.

What the project says against its own interest

The letter is unusually direct about the consequences for users, and the wording matters more than a paraphrase:

It states that current users “will not be able to receive further security software updates until our new security protocols are in place,” and that without them the project “can only be honest that this does not guarantee the level of security we strive for.” When images were later republished in response to community demand, the letter added that “this decision is not a recommendation to migrate to CalyxOS now.”

The stated reason for changing keys is routine rather than alarming: “When senior personnel have access to signing keys and leave a team, it is security best practice to update signing keys and conduct audits.” The project says it has “no reason to believe the security of CalyxOS and its signing keys have been compromised.”

The estimate and the outcome

The letter estimated “four to six months” for the audit and new signing protocols. The hiatus ran from 1 August 2025 to 1 July 2026, about eleven months, roughly double the upper estimate. The gap between the two is the most useful number in these documents and the one a reader should carry forward, because it is the project’s own forecast measured against the project’s own record.

Reading these as evidence

These are self-published announcements, so they are authoritative for what the project decided and when, and weak evidence for whether the decisions were correct. Their unusual value is that the central claims cut against the publisher: a project telling its users to uninstall its product, and publishing a timeline that overran its own estimate, is not the shape of a document written to flatter. That makes the timeline above safe to rely on in a way the project’s security claims are not.

The technical claims about the replacement infrastructure — an open-source HSM-based signing solution with no single point of failure — are not verified by these pages. LWN reports that Trail of Bits audited the provisioning ceremony script, which is a narrower scope than an audit of the signing system. The broader security audit the letter promised to publish appears neither in these pages nor in the reporting on the project’s return.

Built on 2 sources (2 external).

Working out connections…