Live data from Hacker News

Google has stopped pushing Git tags for some Android source code

grapheneos.social

191–200 of 350 posts

Re: Google has stopped pushing Git tags for some Android source code

#191
post #56
post #48

Earlier quoted context omitted.

Doesn’t Apple do the same?

Did Apple claim iOS is open source?

So you're saying Google should stop open sourcing Android? That should like a bad incentive to make to defend Apple.

Re: Google has stopped pushing Git tags for some Android source code

#192

They stopped pushing tags for any of the Pixel kernel or userspace driver repositories to AOSP. They also stopped pushing AOSP releases specific to Pixels which is why AOSP now only gets yearly releases, QPR2 releases and security backports to both of those. Other OEMs use the yearly and theoretically also the QPR2 releases. Both the yearly and QPR2 releases get monthly security backports. Since they dropped Pixel su…

> They need to do it in a reasonable amount of time.

If they did that for years within hours and if we look at the tools available today, I would expect that "reasonable" equates to how they provided it prior: fast.

Re: Google has stopped pushing Git tags for some Android source code

#193
post #35

Earlier quoted context omitted.

There might be some merit to a claim that Google Drive isn't a medium customarily used for software distribution these days, but, yeah, it's definitely not paying a thousand+ cent bill in pennies, and I'm skeptical that it's a violation of the letter of the GPL. It is definitely a dick move by Google.

While I don't find any requirements on how timely the source distribution must be upon request, one can reasonably say that there must be a line between 1 nanosecond and 1 century.

Google can trivially provide it nearly instantly with no hardship. In fact, it's much harder for them to implement manual handling than automation. They have no justification for it beyond deliberately making it harder. It does have to be provided in a reasonable time or the license wouldn't work. What amount of time is reasonable is up to a court.

Google being incapable of timely handling of these requests is not believable. They're one of the largest tech companies in the world. They deliberately moved from a system without any need for manual handling of requests to requiring it with the clear goal of creating a hassle. By failing to provide it for long enough periods of time to cause tangible harm to people relying on it, they're failing to comply with the license.

Re: Google has stopped pushing Git tags for some Android source code

#194

But why? What can be the internal justification? What do they think they win by doing this?

Difficult to say at the moment, but there might be some speculation as to why.

One might be that they dont security patches reverse engineered and vulnerabilities to come out faster (some critical and high severity fixes in GPU drivers/bootloaders were often delayed), and this decision was done long before LLMs were considered powerful/useful for vulnerability research.

Second reason might be simply "Control of the android ecosystem", Google may just want to build a wall around android and make it frustrating for other vendors to compete.

Third, again, this is only speculation, is the current push for electronic ID in the EU and other countries, as well as DRM/copyright protections for media and locally ran LLMs (we've heard of how google pushed small LLMs with chrome updates), if they can do the same on some high end android devices, Google would be more invested into further locking down Android devices.

Re: Google has stopped pushing Git tags for some Android source code

#195

They stopped pushing tags for any of the Pixel kernel or userspace driver repositories to AOSP. They also stopped pushing AOSP releases specific to Pixels which is why AOSP now only gets yearly releases, QPR2 releases and security backports to both of those. Other OEMs use the yearly and theoretically also the QPR2 releases. Both the yearly and QPR2 releases get monthly security backports. Since they dropped Pixel su…

> They need to do it in a reasonable amount of time. If they did that for years within hours and if we look at the tools available today, I would expect that "reasonable" equates to how they provided it prior: fast.

They did it for many years with 0 delay because they pushed the tags to AOSP. It was moved to Google Drive with a Google Forms setup to request access with manual fulfillment of the request. It was deliberately done to make it into a hassle. The delays are by design through making it a manual system regardless of how much of a delay was intended as part of this change. They could be automatically handling the requests especially from people who have already been given sources for a product. They're deliberately making it take substantially more work on their end to make it into more of a hassle.

Re: Google has stopped pushing Git tags for some Android source code

#196
post #4

“In violation of GPL” is a stretch. Can’t imagine Google is making the process of obtaining source code easier on themselves though. Android has always been more source-open than “open source”. The vast majority of community contributions that make it into the codebase are security fixes and small bug fixes. Everything else is essentially all the work of Google and (to some extent) Samsung.

I see your point, However the majority of Android devices have lots of closed source firmware/drivers, a large part of the Android OS doesn't run without them.

I'm refering to Bootloaders, TrustZone OS, Trusted Applications, then firmware for Bluetooth, Wifi, GPU, Sensors and power management. All of those are always closed source binary blobs running in the background.

Re: Google has stopped pushing Git tags for some Android source code

#197
post #185

Earlier quoted context omitted.

> GPL doesn't set a standard time limit for providing the sources, but that doesn't mean they can delay it indefinitely. I wonder actually what a court would say here and if "doesn't set a time limit" could mean "the source needs to be made available immediately". IANAL.

In the US? Under the current political and economic circumstances? Against Google's legal department? I wouldn't get my hopes up...

No, it would be in Canada.

Re: Google has stopped pushing Git tags for some Android source code

#198
post #87
post #63

Earlier quoted context omitted.

I specifically use Android because of this, among other requirements, that Apple imposes on software development on their platform. I do not own general purpose computers that I am not allowed to develop software for without permission. I have always avoided consoles for that reason as well (Steam Machine and other similar platforms would be fine, but I've been avoiding consoles for long enough that it's not somethin…

I switched to an iPhone last year, mostly because I was getting sick of Samsung’s shit, and google doesn’t sell their pixel phones locally (and I don’t like Oppo). But the other reason is that most of Android’s openness is quickly disappearing, so my main argument against iPhone is gone. And on the topic of privacy, I actually trust Apple way more than I trust the company that makes most of their revenue via advertis…

>makes most of their revenue via advertising.

Apple already have a huge chunk of the ad pie and are growing all the time. Dont think Apple are keeping you safe from ads and all the profiling of your behaviour that involves.

https://www.businessinsider.com/apple-gets-serious-about-its...

https://www.wired.com/story/apple-is-an-ad-company-now/

https://www.bbc.co.uk/news/business-67417987

https://www.businessinsider.com/apple-tests-ai-app-store-ads...

Re: Google has stopped pushing Git tags for some Android source code

#199
post #183

They stopped pushing tags for any of the Pixel kernel or userspace driver repositories to AOSP. They also stopped pushing AOSP releases specific to Pixels which is why AOSP now only gets yearly releases, QPR2 releases and security backports to both of those. Other OEMs use the yearly and theoretically also the QPR2 releases. Both the yearly and QPR2 releases get monthly security backports. Since they dropped Pixel su…

Well, it's as you wrote: they are making the source available, albeit in a very inconvenient way, and because there is no time limit specified, they're complying with the letter of the GPL (although not with its spirit), so you can't even realistically sue them. And the number of people who buy new Pixels to immediately install GrapheneOS on them is (no offense) negligible, so I don't think they'll see a sales impact…

> they are making the source available

Not in the preferred form for modification expected by the build system and not in a reasonable amount of time. It's artificially delayed with no legitimate reason.

> And the number of people who buy new Pixels to immediately install GrapheneOS on them is (no offense) negligible

Nearly all of our current users bought a device specifically to install GrapheneOS. Our current userbase is around 500k and many of those are users had one or more earlier devices with GrapheneOS. Our userbase is rapidly growing. Look up how many Pixels are actually sold in a year. It's not negligible at all.

There are also many large companies wanting GrapheneOS devices with official support from the OEM.

Re: Google has stopped pushing Git tags for some Android source code

#200

They stopped pushing tags for any of the Pixel kernel or userspace driver repositories to AOSP. They also stopped pushing AOSP releases specific to Pixels which is why AOSP now only gets yearly releases, QPR2 releases and security backports to both of those. Other OEMs use the yearly and theoretically also the QPR2 releases. Both the yearly and QPR2 releases get monthly security backports. Since they dropped Pixel su…

> They'll sell far fewer Pixels because of these overall changes. It pushes GrapheneOS and other projects towards other devices instead. For us, Pixels are being used due to security rather than ease of supporting them. It's now a lot harder to deal with Pixels than it would be for many other devices but they're currently still the most secure option. We're working on changing that and have a lot less reason to contr…

Only Pixels, most other device are ironically locked down a lot more (not allowing custom keys for verified boot) or lack modern security features (like hardware security modules).

So you'll have to wait for the mentioned Motorola Flagship

Post reply on HN