Comment by grapheneos
15 hours ago
Google likely cut MTE to reduce the die space required by CPU cache. It saves them money on a feature they never deployed by default and only used for a few processes as part of Android Advanced Protection Mode (AAPM) without enabling it in the Linux kernel. Their security team should have gotten it deployed by default for a large portion of the OS by now and then it would have been much harder to justify removing it. The small performance impact of asymmetric mode is irrelevant for the vast majority of the OS and it can also be used in the near zero cost asynchronous mode. We use synchronous in the kernel for security reasons but they didn't have to do that.
It's a completely different story for GrapheneOS where it means losing one of the main kernel and userspace security protections. This is one of the only ways we can significantly harden the Linux kernel with existing security features. The Linux kernel has always been a huge security liability for Android and AI models are making that much more obvious to everyone.
Google will likely end up heavily using MTE in the future. Pixel 11 devices won't be able to benefit from it. They're at the start of 7 years of updates but they won't be getting the benefit of future updates enabling MTE. Pixel 8 and later will benefit from Google likely expanding use of MTE for AAPM and eventually beginning to use it by default. It's unlikely Google will stop working on expanding MTE due to the Pixel 11 hardware decision. Multiple other OEMs are interested in MTE for devices made for businesses and governments even if Google decided it wasn't worth the cost for Pixels.
Ironically the recent CVE that's being used to root Android phones (Ghostlock) running GKI images is mitigated by MTE.
The supposed "security team" is busy fighting Google engineers connecting to internal systems to do their work. E.g. somebody figured how to control the coding AI agent from their phone -- red alert, ban all access from phones to AI for everybody (even with corporate accounts).
You say that like it's a bad thing. If I am trusting Google with all sorts of personal information, I expect robust access controls to data and systems
If there will be a GrapheneOS image for the Pixel 11 without MTE, could that open the door for GrapheneOS on a lot more phones that support AOSP?
We don't plan to make official GrapheneOS releases for any more devices without MTE. If we decided to provide support for the Pixel 11 series, it likely won't be branded as GrapheneOS to make it clear it isn't on the same level.
It would be inconsistent to require Motorola to provide MTE support and then to support the Pixel 11 without it.
There are no phones directly supported by AOSP. Motorola is helping us support their devices and port our features to them. We have to do an immense amount of work on it ourselves for Pixels and already did a lot of it for the Pixel 11 devices. Other devices are missing more than MTE.
Regarding the differentiated branding, I've been hoping for a GrapheneLite for many years now.
Regarding direct AOSP support, there are many devices that work fine with just the generic system image, which I'd count as direct AOSP support.
1 reply →
Weird omission then... Seems asinine...