4 ms·
The browser is an extremely fast-moving security-critical attack surface, so it’s for the best that Android WebView is maintained separately in the Chromium rep
by anderskaseorg 5y ago
The browser is an extremely fast-moving security-critical attack surface, so it’s for the best that Android WebView is maintained separately in the Chromium repository, and doesn’t need to be held back by the AOSP release schedule. It’s still open source.
https://chromium.googlesource.com/chromium/src/+/HEAD/android_webview/docs/aosp-system-integration.md https://chromium.googlesource.com/chromium/src/+/HEAD/androi...
- a012 5y ago> fast-moving and fast-breaking, there are multiple occasions that faulty WebView updates released to the world and crashed phones. Also you'll need root to change the default WebView to something else like Bromite.
- mathfailure 5y agoWhy not just release AOSP as frequently? Then it'd be easier to push other small updates.
- jayd16 5y agoApp store updates vs OS updates.
- xorcist 5y agoThis distinction is not definitive. None of the normal Linux distributions makes it.
- pkaye 5y agoI thought OS updates require cooperation of the phone manufacturer/carriers.
- xorcist 5y agoOnly because lazy manufacturers ships patched monstrosities that passes for software. If "Android" was responsible for booting and device drivers, or if Android was GPL for that matter, that would have ceased to be the case.
- phh 5y agoIt's fun that you should mention that, because assuming it is true that webview is best upgraded out-of-aosp (which I guess I kinda agree with), then why does AOSP ship with a webview? AOSP is lacking a browser, not a webview.
- anderskaseorg 5y agoIt doesn’t: https://android.googlesource.com/platform/external/chromium-webview/+/refs/heads/master https://android.googlesource.com/platform/external/chromium-... “Building the Chromium-based WebView in AOSP is no longer supported or required. WebView can now be built entirely from the Chromium source code. Docs on how to build WebView from Chromium for use in AOSP are available here: https://chromium.googlesource.com/chromium/src/+/HEAD/android_webview/docs/aosp-system-integration.md https://chromium.googlesource.com/chromium/src/+/HEAD/androi... For questions about building WebView, please contact our mailing list: https://groups.google.com/a/chromium.org/forum/#!forum/android-webview-dev https://groups.google.com/a/chromium.org/forum/#!forum/andro... The prebuilt APKs provided here are built from Chromium upstream sources; you should check the commit message to see the version number for a particular prebuilt. The version number is formatted like “12.0.3456.789” and matches the tag in the Chromium repository it was built from. If you want to build your own WebView, you should generally build the latest stable version, not the version published here: newer versions have important security and stability improvements.” https://android.googlesource.com/platform/packages/apps/Browser2/+/refs/heads/master/README https://android.googlesource.com/platform/packages/apps/Brow... “Browser2 is a copy of the WebViewShell, a minimal test browser using WebView. The old Browser is no longer supported. This is *not* a production quality browser and does not implement suitable security UI to be used for anything other than testing WebView. This should not be shipped in production devices, or used as the basis for implementing a real browser. To build a full-fledged browser for AOSP, one option is to build a standalone (non-WebView-based) Chromium browser by following the instructions at: https://www.chromium.org/developers/how-tos/android-build-instructions https://www.chromium.org/developers/how-tos/android-build-in... ” If you’re going to build the WebView from an external repository, you might as well build the browser from there too.