Google Maps used to work without it but recently gained a hard dependency on Play services. We could add more shims to make more apps work without it installed but that hasn't been a focus yet.
Makes sense. Any idea if there's any interest in a shim to get notifications working sans Play services?
I haven't looked at anything shim related in quite a while and am not super familiar with the notification stack for Android, so if that's a stupid question I apologize.
CoMaps and Waze definitely work well on GrapheneOS. There's a known performance issue experienced by some users with the OsmAnd OpenGL renderer which can be worked around disabling hardened_malloc. We could likely provide a performance vs. security toggle for hardened_malloc to avoid it, but we also plan to continue optimizing the default high security mode.
And yet problems exist. Live Updates are not rendered if both OsmAnd V2 rendering and hardened memory allocator are enabled: <a href="https://github.com/osmandapp/OsmAnd/issues/20190" rel="nofollow">https://github.com/osmandapp/OsmAnd/issues/20190
Those are memory corruption bugs which are potentially exploitable vulnerabilities. There are no false positives for the security protections in hardened_malloc including the hardware memory tagging (MTE) integration. It only detects invalid memory corruptions via use-after-free or out-of-bounds accesses. Due to a relatively high number of apps having invalid memory accesses during regular use, we don't enable MTE for all user installed apps yet. We always use MTE for the kernel and userspace code in the base OS but it's opt-in for most user installed apps via a global toggle to enable it by default and a per-app toggle mainly intended for opting out for incompatible apps.
OsmAnd has a massive amount of legacy C++ code which hasn't been heavily tested with HWASan and MTE. It has a history of having many memory corruption bugs discovered and reported by GrapheneOS users. That's the exploit protections in GrapheneOS working as intended and it's why there are per-app compatibility toggles to work around apps which can't be used due to memory corruption during regular use. It would be better if apps had higher quality native code and didn't need us to provide compatibility toggles but that's the way things are. It's much worse on desktop operating systems.
negative_zero · · focus · HN ↗
BlackRabbit1 · · focus · HN ↗
Osmand and GMaps are working fine.
Waze is almost melting the poor thing. Beside of that working fine.
ThePowerOfFuet · · focus · HN ↗
broodbucket · · focus · HN ↗
DuncanCoffee · · focus · HN ↗
DaSHacka · · focus · HN ↗
worldsavior · · focus · HN ↗
Shared404 · · focus · HN ↗
Waze is fairly easy to run without play services. GMaps I haven't yet found a way to run, but also haven't looked in quite some time.
grapheneos · · focus · HN ↗
Shared404 · · focus · HN ↗
I haven't looked at anything shim related in quite a while and am not super familiar with the notification stack for Android, so if that's a stupid question I apologize.
DaSHacka · · focus · HN ↗
<a href="https://plexus.techlore.tech/apps?q=waze" rel="nofollow">https://plexus.techlore.tech/apps?q=waze
Nux · · focus · HN ↗
subscribed · · focus · HN ↗
pizzaiolo · · focus · HN ↗
gunalx · · focus · HN ↗
methuselah_in · · focus · HN ↗
archturtle · · focus · HN ↗
grapheneos · · focus · HN ↗
Self-Perfection · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
grapheneos · · focus · HN ↗
OsmAnd has a massive amount of legacy C++ code which hasn't been heavily tested with HWASan and MTE. It has a history of having many memory corruption bugs discovered and reported by GrapheneOS users. That's the exploit protections in GrapheneOS working as intended and it's why there are per-app compatibility toggles to work around apps which can't be used due to memory corruption during regular use. It would be better if apps had higher quality native code and didn't need us to provide compatibility toggles but that's the way things are. It's much worse on desktop operating systems.