3 ms·
I was very excited for Android's new virtualization features until I discovered that Android will only allow GOOGLE/OEM SIGNED VM IMAGES!?!? You won't be able t
by nulld3v 2y ago
I was very excited for Android's new virtualization features until I discovered that Android will only allow GOOGLE/OEM SIGNED VM IMAGES!?!? You won't be able to use your own kernel in the VM. https://source.android.com/docs/core/virtualization/security https://source.android.com/docs/core/virtualization/security
Custom kernels would have been an important use case for virtualization since you might be stuck on an old kernel due to lack of updates from the OEM, or your kernel might be heavily trimmed down and missing many useful features.
And not only that, virtualization is also restricted to only Google/OEM apps. There will be no way to grant user apps access to the virtualization API.
So the only benefits you get from virtualization are the minor security improvement and maybe a slightly less locked-down user space.
One thing that is nice though, is how the VM architecture not only protects the host from the guest, but also the guest from the host. Other than that, incredibly disappointing....
- megous 2y agoEh, how does that work with GPLv2. I get to have source code for the bundled Linux, but I can't compile my own modifications of it and run them? I really dislike companies that shit on the spirit of licenses they profit from.
- numpad0 2y ago0: https://xkcd.com/1053/ https://xkcd.com/1053/ 1: https://en.wikipedia.org/wiki/Tivoization https://en.wikipedia.org/wiki/Tivoization 2: https://www.gnu.org/licenses/rms-why-gplv3.en.html https://www.gnu.org/licenses/rms-why-gplv3.en.html
- megous 2y agoEven with GPLv2 it's pretty clear what the purpose of the license is.
- pabs3 2y agohttps://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-the-gpl-right-to-install/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017/11/Safely-Copylefted-Cars-Reexamining-GPLv3-Installation-Information-Requirements-ALS-Bradley-Kuhn-Behan-Webster-1.pdf https://events19.linuxfoundation.org/wp-content/uploads/2017...
- nulld3v 2y agoTechnically there is nothing stopping you from running your own compiled kernel since you can just unlock the bootloader and run whatever you want. I'm still with nunpad0 though since if you unlock bootloader on a Pixel you lose a ton of features and on a Samsung you lose the warranty. Many apps will stop working too. The whole Android ecosystem is just a few steps away from complete Tivoization.
- kurtoid 2y agoNot on devices from verizon, though
- walterbell 2y agoGrapheneOS could allow device owners to choose their own signature root of trust?
- nulld3v 2y agoI believe you indeed can do this, but you need to recompile GrapheneOS. Which brings me to another one of the turn-offs of GrapheneOS: you also need to recompile GrapheneOS if you want to have root access. I understand that it's for security, but compiling Android ROMs is generally painful and GrapheneOS is otherwise quite flexible is letting the user choose their own security/paranoia level.