Earlier quoted context omitted.
It's not like more than 1% of android phones that have shipped to date will actually get an android update to Oreo anyway so why not leave them behind and update the kernel? New phones need new drivers which must support the new kernel, period. I don't see what the big deal is. You aren't getting Oreo on your old ass Samsung Galaxy S2 anyway.
Nougat runs fine on a Galaxy S2 with Lineage OS. I would not be unexpected for them to port Oreo eventually too.
Hardening the Kernel in Android Oreo
71–80 of 108 posts
Re: Hardening the Kernel in Android Oreo
#72Did they have to license the name?
My understanding was you can use a trademarked name but only if it was in an unrelated category. Clearly no one will confuse a phone running Oreo with a cookie you eat and dip in milk. now if google made a cookie and called it oreo, they would get sued. But IANAL and am probably totally wrong here.
Re: Hardening the Kernel in Android Oreo
#73Earlier quoted context omitted.
Agreed, but let's point fingers at the whole stack if we want this to happen. Treble [0] will finally add a HAL to the base system, so updates to the kernel and drivers should in theory be easier on devices that ship with 8.0 (of which there are exactly zero so far). So at least Google's on the right track. But Google doesn't create the drivers and Google doesn't ship the board support packages which vendors build up…
Agreed, it really is a shared problem. It seems like a kind of "collective action problem" [1], where coordination between different parties is required - but they all have different interests and they're not all interested in splitting the costs. Google is in a difficult position. In order for Android to catch up to the iPhone they needed to encourage a wide consortium of vendors to adopt and sell Android hardware.…
Re: Hardening the Kernel in Android Oreo
#74"Android 8.0 makes KASLR available in Android kernels 4.4 and newer." And yet on my pixel with Android 8.0, I am only using 3.18.52. Who actually ships Android with kernel 4.x?
Re: Hardening the Kernel in Android Oreo
#75Earlier quoted context omitted.
OnePlus ships modern kernels. My OnePlus 5 is using kernel 4.4.21 - this is with Nougat 7.1.1, by the way; no Oreo here yet.
Ok I am very disappointing with Google in that case
Snapdragon 820/821 ships with 3.18. Snapdragon 830 ships with 4.4. Snapdragon 830+1 will ship with 4.9
There's a huge amount of work involved in porting a chipset from one kernel version to another. While I'm sure Google _could_ do it, it's ultimately not worth their while - they'd probably lose support from Qualcomm, and if they hit any weird bugs they'd be on their own.
Re: Hardening the Kernel in Android Oreo
#76"Android 8.0 makes KASLR available in Android kernels 4.4 and newer." And yet on my pixel with Android 8.0, I am only using 3.18.52. Who actually ships Android with kernel 4.x?
OnePlus ships modern kernels. My OnePlus 5 is using kernel 4.4.21 - this is with Nougat 7.1.1, by the way; no Oreo here yet.
Re: Hardening the Kernel in Android Oreo
#77Earlier quoted context omitted.
Anyone beliveing that project Treble will change anything should listen to the ADB Podcast about it. http://androidbackstage.blogspot.de/2017/08/episode-75-proje... Key points: 1 - Google will keep on allowing OEMs to customize Android 2 - OEMs will keep being responsible for delivering updates 3 - OEMs are advised to push fixes upstream and provide updates Given that they are just advised, and not required to act ac…
You are dead on. The problem is incentives. There is no technical solution to solve the issue of OEMs not wanting to spend time/resources on updating older phones. Treble will help out LineageOS, CopperheadOS, and XDA devs. But it won't improve the update cycles for OEMs when their business (ie profit aims) pressures them to limit development resources to new phones.
Re: Hardening the Kernel in Android Oreo
#78For similar content but in much greater depth, this is a pretty excellent series of blog posts: https://outflux.net/blog/archives/2017/07/10/security-things...
Re: Hardening the Kernel in Android Oreo
#79Earlier quoted context omitted.
Yes, and I addressed that in my comment. Google, however, can effectively do whatever they want. If they require kernel X, and a manufacturer doesn't support it, they'll either get their shit together, or they'll get left behind. I bet most of them do enough business supplying parts for Android phones that they'd get their shit together. And it' not hard! Writing an initial driver for some hardware might take a lot o…
I expect if google had that strength in position, they would. Perhaps that would lead to more fragmentation and less vendors releasing the latest android, leading to a highly dominant maker squashing the others and then having a stronger position in negotiating with google.
Re: Hardening the Kernel in Android Oreo
#80Earlier quoted context omitted.
Agreed, it really is a shared problem. It seems like a kind of "collective action problem" [1], where coordination between different parties is required - but they all have different interests and they're not all interested in splitting the costs. Google is in a difficult position. In order for Android to catch up to the iPhone they needed to encourage a wide consortium of vendors to adopt and sell Android hardware.…
It worked for Microsoft to impose hardware designs on PCs, the big difference was that OEMs did not had the source code of MS-DOS and later Windows available to them, to do whatever they felt like it.