6 ms·
I really wish Android would properly enable containers like they've done for Chrome OS. It's silly we run little Linux machines and can't pop a fully isolated
by qbasic_forever 3y ago
I really wish Android would properly enable containers like they've done for Chrome OS. It's silly we run little Linux machines and can't pop a fully isolated container shell on them!
- AviationAtom 3y agoNot quite the same, but interesting: https://www.xda-developers.com/android-13-dp1-google-pixel-6-kvm-virtual-machine/ https://www.xda-developers.com/android-13-dp1-google-pixel-6...
- derefr 3y agoI think it hasn't happened because much of the sandboxing of Android is part of the Android runtime, thereby only sandboxing code compiled for the Android runtime. If you could spawn a native Linux executable (that hasn't been compiled for Android the way the Termux executables have) from an Android application, then that process can escape the application's sandbox and do stuff it shouldn't be able to do given the permissions granted to the Android application. That just means no container-based virtualization, though. There's nothing stopping a sufficiently-powerful Android device from running a Linux virtual machine, presuming that the hypervisor is implemented as a regular Android application using regular Android-runtime APIs.
- ignoramous 3y agoAndroid 13+ includes a crosvm based virtulization setup: https://source.android.com/docs/core/virtualization https://source.android.com/docs/core/virtualization > ...then that process can escape the application's sandbox and do stuff it shouldn't be able to do given the permissions granted to the Android application. Android's sandboxing is not limited to ART and has multiple layers [0]. Native apps cannot bypass sandboxing, I don't think. [0] https://hernan.de/blog/tailoring-cve-2019-2215-to-achieve-root/ https://hernan.de/blog/tailoring-cve-2019-2215-to-achieve-ro...
- derefr 3y ago> Android 13+ includes a crosvm based virtulization setup Interesting; but I feel that their choice of a hypervisor-based design here supports my point of plain container-based isolation (or even containers + gVisor) being insufficient to achieve true sandboxing on Android. > Android's sandboxing is not limited to ART and has multiple layers [0]. Native apps cannot bypass sandboxing, I don't think. Yes, but when I say "sandboxing", I mean just the ART sandbox, not the other layers. I don't care whether you can get root / jailbreak the device. I (and presumably Google, in not publishing apps that do this in the Play Store) care about whether an application that, upon installation, doesn't request permission to e.g. read your contacts, can actually read your contacts. There are certain capabilities like that (not sure if "reading your contacts" is one of them, but you get the idea), that are only prevented from being accessed by ART, not by Linux ACLs. This is especially true when there's one level of permission that gets you access to a certain database file through an API, but then another level of permission that gets you access to certain special records in that database file through the same API. The lower level of permission is already granting you Linux filesystem ACLs to the database file; the only difference between the two permissions comes down to what ART will allow you to request through the higher-level API.
- Zak 3y agoGoogle does, in fact publish apps that require root access in the play store. Titanium Backup is a popular example (though I'd recommend the open source Neo Backup instead). They presumably don't publish apps that use exploits to help the user gain root without unlocking the bootloader and wiping the data partition.
- skrowl 3y agoThere are many file explorer apps ( MiXplorer is my favorite https://play.google.com/store/apps/details?id=com.mixplorer.silver https://play.google.com/store/apps/details?id=com.mixplorer.... ) on Google Play that have optional root access as well. You can use it w/o root, but if you have root it prompts for elevation and then lets you use it.
- moondev 3y agoIf it works like crosvm on ChromeOS, you can launch a KVM virtual machine and then run containers inside that. It even supports nested virtualization (at least it does on my framework Chromebook) so you can then run vms inside the VM for stuff like multipass or gnome-boxes. It actually works really. Would be amazing if this same pattern is enabled for Android devices with proper vmx/vt extensions on the CPU.
- saagarjha 3y agoThis is not how sandboxing works on Android: it’s SELinux -based. The Linux ABI is explicitly supported by Android, though generally not recommended.