‹ BackHN Continuity

Thread

GrapheneOS – When an app is slow

86 points · 65 comments · speckx

  1. pjmlp · · focus · HN ↗
    Maybe the actual solution is to improve, replace the application.
    1. mohamedkoubaa · · focus · HN ↗
      There needs to be a wall of shame for apps that abuse hardware owned by users
      1. yjftsjthsd-h · · focus · HN ↗
        How's it abusing anything? It's an Android app that works fine with the default Android memory allocator.
        1. perching_aix · · focus · HN ↗
          That doesn't necessarily mean it isn't being abusive, just that said allocator tolerates it okay.
        2. pjmlp · · focus · HN ↗
          The AOSP memory allocator is seldom the one used by OEMs.
          1. rpdillon · · focus · HN ↗
            Really? They're not using Scudo? The hardened_malloc used in GrapheneOS has a bunch of performance issues that were trade-offs against security. Every other major android distribution uses scudo as far as I know. Which OEMs are you thinking of?

            Edit: Did some research after writing this? It appears that Samsung may be still using jemalloc, albeit a newer version than the one from the Android 11 days.

            1. grapheneos · · focus · HN ↗
              No, it does not have "a bunch of performance issues". It has carefully considered performance vs. security compromises which are largely configurable. GrapheneOS uses hardened_malloc in a very security-oriented configuration and has the option to disable it per-app if there's ever a compatibility or performance issue. GrapheneOS could also offer another toggle for setting it to a performance mode where it isn't significantly slower than Scudo either via dynamic configuration or a 2nd build of hardened_malloc with a lighter configuration. Most overhead is from slab allocation quarantines which are optional.
              1. rpdillon · · focus · HN ↗
                Yikes, didn't mean to trigger any defensiveness. Can't edit my comment, but mentally replace "bunch of performance issues" with what you said: "performance vs. security compromises".
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.