Earlier quoted context omitted.
No, chain-of-trust only has one trick... it can check that what you're about to run is unaltered from what was signed to some degree of probability. If that is the - shipped and validly signed - bugridden nightmare-fuel like the propreitary Qualcomm 802.11 stack or proprietary multimedia bits that are a rich and continuous source of vulnerabilities (take a look through the last months here https://source.android.com/…
> No, chain-of-trust only has one trick... it can check that what you're about to run is unaltered from what was signed to some degree of probability. This is only one of many privacy and security regressions from moving to a far less secure software stack without anything close to the same level of hardening or work on privacy / security. > If that is the - shipped and validly signed - bugridden nightmare-fuel like…
Kind of, Google can release Android running on top of any OS that implements the NDK stable APIs, plus their POSIX subset, and besides OEMs no one would notice the change.
https://developer.android.com/ndk/guides/stable_apis
Other than that I fully agree with your statement regarding being a security weakness.