Live data from Hacker News

Hardening the Kernel in Android Oreo

android-developers.googleblog.com

71–80 of 108 posts

Re: Hardening the Kernel in Android Oreo

#71
post #57
post #44

Earlier quoted context omitted.

It's not like more than 1% of android phones that have shipped to date will actually get an android update to Oreo anyway so why not leave them behind and update the kernel? New phones need new drivers which must support the new kernel, period. I don't see what the big deal is. You aren't getting Oreo on your old ass Samsung Galaxy S2 anyway.

Nougat runs fine on a Galaxy S2 with Lineage OS. I would not be unexpected for them to port Oreo eventually too.

GP's point was about OEM support for newer versions of Android, though; I can't imagine that third-party ROMs on old devices are even slightly a factor in Google's hesitation to upgrade to newer kernel versions

Re: Hardening the Kernel in Android Oreo

#72
post #22
post #15

Did they have to license the name?

My understanding was you can use a trademarked name but only if it was in an unrelated category. Clearly no one will confuse a phone running Oreo with a cookie you eat and dip in milk. now if google made a cookie and called it oreo, they would get sued. But IANAL and am probably totally wrong here.

Your understanding covers the basic intent of U.S. trademarks, but it got much more complicated with the Federal Trademark Dilution Act of 1995: https://en.wikipedia.org/wiki/Federal_Trademark_Dilution_Act. Nowadays, impairing a famous trademark's distinctiveness can be an issue, even in the absence of confusion or competition.

Re: Hardening the Kernel in Android Oreo

#73

Earlier quoted context omitted.

Agreed, but let's point fingers at the whole stack if we want this to happen. Treble [0] will finally add a HAL to the base system, so updates to the kernel and drivers should in theory be easier on devices that ship with 8.0 (of which there are exactly zero so far). So at least Google's on the right track. But Google doesn't create the drivers and Google doesn't ship the board support packages which vendors build up…

Agreed, it really is a shared problem. It seems like a kind of "collective action problem" [1], where coordination between different parties is required - but they all have different interests and they're not all interested in splitting the costs. Google is in a difficult position. In order for Android to catch up to the iPhone they needed to encourage a wide consortium of vendors to adopt and sell Android hardware.…

It worked for Microsoft to impose hardware designs on PCs, the big difference was that OEMs did not had the source code of MS-DOS and later Windows available to them, to do whatever they felt like it.

Re: Hardening the Kernel in Android Oreo

#75
post #56

Earlier quoted context omitted.

OnePlus ships modern kernels. My OnePlus 5 is using kernel 4.4.21 - this is with Nougat 7.1.1, by the way; no Oreo here yet.

Ok I am very disappointing with Google in that case

The kernel you get is entirely up to the SoC vendor.

Snapdragon 820/821 ships with 3.18. Snapdragon 830 ships with 4.4. Snapdragon 830+1 will ship with 4.9

There's a huge amount of work involved in porting a chipset from one kernel version to another. While I'm sure Google _could_ do it, it's ultimately not worth their while - they'd probably lose support from Qualcomm, and if they hit any weird bugs they'd be on their own.

Re: Hardening the Kernel in Android Oreo

#76
post #4

"Android 8.0 makes KASLR available in Android kernels 4.4 and newer." And yet on my pixel with Android 8.0, I am only using 3.18.52. Who actually ships Android with kernel 4.x?

OnePlus ships modern kernels. My OnePlus 5 is using kernel 4.4.21 - this is with Nougat 7.1.1, by the way; no Oreo here yet.

OnePlus ships the kernel that Qualcomm gives them. The BSP for Snapdragon 835 (aka msm8998) is based on 4.4

Re: Hardening the Kernel in Android Oreo

#77
post #24
post #12

Earlier quoted context omitted.

Anyone beliveing that project Treble will change anything should listen to the ADB Podcast about it. http://androidbackstage.blogspot.de/2017/08/episode-75-proje... Key points: 1 - Google will keep on allowing OEMs to customize Android 2 - OEMs will keep being responsible for delivering updates 3 - OEMs are advised to push fixes upstream and provide updates Given that they are just advised, and not required to act ac…

You are dead on. The problem is incentives. There is no technical solution to solve the issue of OEMs not wanting to spend time/resources on updating older phones. Treble will help out LineageOS, CopperheadOS, and XDA devs. But it won't improve the update cycles for OEMs when their business (ie profit aims) pressures them to limit development resources to new phones.

but wouldn't treble allow for there custom Android to be updated across there fleet of devices where currently each product has to get its custom build with drivers etc.

Re: Hardening the Kernel in Android Oreo

#79
post #42

Earlier quoted context omitted.

Yes, and I addressed that in my comment. Google, however, can effectively do whatever they want. If they require kernel X, and a manufacturer doesn't support it, they'll either get their shit together, or they'll get left behind. I bet most of them do enough business supplying parts for Android phones that they'd get their shit together. And it' not hard! Writing an initial driver for some hardware might take a lot o…

I expect if google had that strength in position, they would. Perhaps that would lead to more fragmentation and less vendors releasing the latest android, leading to a highly dominant maker squashing the others and then having a stronger position in negotiating with google.

Perhaps it would be more desirable to reduce dependency on blobs? What can we do to encourage manufacturers to release source for their hardware? I assume they care about selling hardware and the firmware is just incidental?

Re: Hardening the Kernel in Android Oreo

#80
post #73

Earlier quoted context omitted.

Agreed, it really is a shared problem. It seems like a kind of "collective action problem" [1], where coordination between different parties is required - but they all have different interests and they're not all interested in splitting the costs. Google is in a difficult position. In order for Android to catch up to the iPhone they needed to encourage a wide consortium of vendors to adopt and sell Android hardware.…

It worked for Microsoft to impose hardware designs on PCs, the big difference was that OEMs did not had the source code of MS-DOS and later Windows available to them, to do whatever they felt like it.

OEMs can't do whatever they like with Android outside of China PR. They need Google play services.
Post reply on HN