Heaps of questions from a brand new grapheneos user

https://thelemmy.club/post/51589388

Heaps of questions from a brand new grapheneos user - The Lemmy Club

Hi everyone Writing this on my new (second hand) pixel with grapheneos. Have been watching this project for a few years and stoked to finally be here. I’m getting closer and closer to the online life I want all the time. I have a few questions: 1. Sourcing apps - is it safer to use f-droid (in my case I like the neo-store) or obtainium? 2. For non open-source apps, Aurora or sandboxed google play? 3. Is it OK to use WiFi at my work? Or at the mall? What are the risks? I’ve got a VPN but using it prevents me from accessing my server via tailscale 4. WhatsApp - I’ve tried to set up whatsapp but I get stuck at retrieving the backup from google drive. I’m seeing conflicting views on weather or not this is possible. It’d be great but its a price I’m willing to pay if it means not using WhatsApp 5. Can any app be sandboxed? 6. What else should I know about operating the phone? I’m effectively an absolute beginner to grapheneos 7. My phone now won’t connect to the internet without the VPN, is this normal? Any advice appreciated, thank you

GmsCompatConfig version 171 released

https://mander.xyz/post/53995070

GmsCompatConfig version 171 released - Mander

> Changes in version 171: > > - disable default enabled theft protection notification in Android 17 > - update Gradle to 9.6.0 > > A full list of changes from the previous release (version 170) is available through the Git commit log between the releases [https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/compare/config-170...config-171] (only changes to the gmscompat_config text file and config-holder/ directory are part of GmsCompatConfig). > > GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims. > > This update is available to GrapheneOS users via our app repository and will also be bundled into the next OS release.

GrapheneOS version 2026062100 released

https://mander.xyz/post/53995059

GrapheneOS version 2026062100 released - Mander

> Upgrading this release from a release not yet based on Android 17 requires using the standard over-the-air update system rather than ADB sideload. For users who only update via ADB sideload, we’ll be releasing a special Android 16 QPR2 release with a backported fix for the upstream Android bug causing the issue. This bug also exists in the Pixel OS for both Android 16 QPR3 and Android 17 too but it bypasses it through being bloated enough to always trigger a fallback path. We confirmed adding a 1GiB randomly generated file to GrapheneOS would bypass the issue similarly to the stock Pixel OS but we’ll be fixing the issue instead. > > Tags: > > - 2026062100 [https://github.com/GrapheneOS/platform_manifest/releases/tag/2026062100] (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets) > > Changes since the 2026061800 release: > > - disable MTE for Widevine Rikers service since it’s incompatible with it (issue predates Android 17) > - Sandboxed Google Play compatibility layer: avoid opening extra file descriptions to obtain Play services data prefix paths to avoid a compatibility issue with anti-tampering code used by the Kia Connect app and likely others (issue predates Android 17) > - separate GrapheneOS framework resource IDs from AOSP resource IDs to avoid incompatibilities with Pixel vendor components (issue predates Android 17) > - kernel (Pixel 10): fix for an upstream Broadcom Wi-Fi bcm4383 driver memory corruption bug to avoid invalid memory accesses caught by the kernel hardware memory tagging enabled by GrapheneOS > - disable UBLK feature flag for over-the-air updates due to it likely causing update reliability issues for devices with support for it (6.6 kernel or newer) > - disable UBLK for generated over-the-air update packages to force disable it for updates from the initial Android 17 release > - increase the maximum size of log events in production builds to match debug builds to avoid the kernel panic message and traceback being cut off > - use DevicePolicyManager.MAX_PASSWORD_LENGTH PIN length limit for the new upstream SystemUI PIN user interface for entering the PIN outside of the lockscreen to fix support for the expanded limit of 128 on GrapheneOS instead of using Android’s limit of 16 (this didn’t apply to passwords and it was straightforward to work around it by changing the PIN to a password) > - Settings: show night light settings even when Pixel Comfort View is enabled since we’re missing the settings for it (currently only relevant to the 10th gen Pixels other than the Pixel 10a) > - allow using the new flashlight quick tile while locked (GrapheneOS requires unlocking by default for system quick tiles) > - SystemUI: avoid crashing when trying to edit a screen recording without a video editor app > - fix upstream bug causing the security scan in the Settings app to take much longer in Android 17 (also impacts the stock OS) > - fix compatibility issue breaking resetting permissions for apps with special-runtime permissions (Nearby Devices is now split to have Local Network access enabled by default for compatibility for apps not targeting Android 17 and there are bugs with how this is handled) > - Launcher: remove quick search bar from showing on large display devices since Android 17 > - Launcher: remove space reserved for the quick search bar since Android 17 > - add Pixel Comfort View settings for supported devices (Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold) > - add back error message for entering an incorrect 2nd factor PIN for the GrapheneOS 2-factor fingerprint unlock feature > - fix compatibility with the native zygote spawning system added by Android 17 which isn’t enabled yet (this was added to provide more lightweight sandboxed renderer processes for Chromium and will benefit Vanadium even more due to having finer-grained process isolation but isn’t used by Chromium/Chrome yet and our secure spawning will need to be ported to it) > - GmsCompatConfig: update to version 171 [https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-171] > > All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026062101 security preview release. List of additional fixed CVEs: > > - Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531 > - High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880 > - Unclassified: CVE-2026-28653 > > For detailed information on security preview releases, see our post about it [https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases].

Is there a way to hide the thick status bar?

https://lemmy.world/post/48430446

Is there a way to hide the thick status bar? - Lemmy.World

This command belkw isn’t working in adb to to force immersive mode. Was wondering if there are any workarounds. The status bar is such a waste of space on my Pixel 10 Pro Fold. I tried in Settings>Display>Display Size reducing the slider but didn’t help. adb shell settings put global policy_control immersive.full [http://immersive.full/]=*

I'm working toward fully eliminating Google from my world.. I'm building out my own Linux server for files, media, DNS. I even took a stab at installing GrapheneOS on my phone today. I had to revert back to Google Android because I couldn't get Graphene to a point that was satisfactory for what I need to do right away. I'll work at it though.

#homelab #linux #NAS #graphene_os

GrapheneOS Community Helping Test New GrapheneOS Port to AOSP 17

https://mander.xyz/post/53887677

GrapheneOS Community Helping Test New GrapheneOS Port to AOSP 17 - Mander

> Our community is helping us test the initial release of GrapheneOS based on Android 17. It’s working very well for most people with very few issues. We’ve resolved the main regressions reported to us already. We’ll start builds for a 2nd public release based on 17 later today after a few more fixes. > > The most serious issue we fixed is an upstream memory corruption bug in the Broadcom Wi-Fi driver memory corruption bug for the Pixel 10, 10 Pro, 10 Pro XL and 10 Pro Fold. The invalid memory access is caught by our use of hardware memory tagging which causes a kernel panic instead of allowing it. > > We already fixed this Broadcom Wi-Fi bcm4383 memory corruption bug in our 2026050900 release for the Pixel 8a, 9a and 10a. Pixel 6 through 9a share the same kernel source tree which the 10a is based on. Android 17 added the new code with this bug for real 10th gen Pixels which we missed initially. > > Android 17 added a unified PIN interface to SystemUI for use outside of the lockscreen. Our PIN scrambling feature now works beyond the lockscreen too. We increase the DevicePolicyManager PIN and password length to 128 but Android’s new PIN entry had it hard-wired to 16 which we’ve resolved now. > > We add a feature making system quick tiles require unlocking by default and exclude tiles where it isn’t needed which accidentally caused the new flashlight quick tile to require unlocking which is now fixed. Those are the main issues found so far other than minor UI quirks we’re working on fixing

GrapheneOS version 2026061800 released

https://mander.xyz/post/53887118

GrapheneOS version 2026061800 released - Mander

> This is the initial release of GrapheneOS based on Android 17. > > Due to an upstream Android 17 bug, updating to this release via ADB sideload to recovery from a previous release is unavailable. There will be no issues updating to it over-the-air and we’ll provide instructions in our testing channels for early experimental testing prior to Alpha. We’ve added a workaround resolving updating via ADB sideload from this release to a future release. We’re working on a resolution to updating via sideload from a previous release. If necessary, we could make a final release based on Android 16 QPR2 with the same workaround solely released for people who only update via sideloading. > > Tags: > > - 2026061800 [https://github.com/GrapheneOS/platform_manifest/releases/tag/2026061800] (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets) > > Changes since the 2026061600 release: > > - full 2026-06-05 Pixel security patch level (released with Android 17) > - rebased onto CP2A.260605.016 Android Open Source Project release (Android 17) > - revert in-process Opus codec sandboxed with LFI (Lightweight Fault Isolation) to dedicated sandboxed process in order to restore compatibility with hardware memory tagging and avoid likely holes in LFI > - Sandboxed Google Play compatibility layer: add stubs for BluetoothLeBroadcast methods > - Vanadium: update to version 149.0.7827.159.0 [https://github.com/GrapheneOS/Vanadium/releases/tag/149.0.7827.159.0] > > All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026061801 security preview release. List of additional fixed CVEs: > > - Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531 > - High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880 > - Unclassified: CVE-2026-28653 > > For detailed information on security preview releases, see our post about it [https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases].

GrapheneOS Based On AOSP 17 Progress and Upcoming Bug Fixes

https://mander.xyz/post/53885685

GrapheneOS Based On AOSP 17 Progress and Upcoming Bug Fixes - Mander

> We built an initial release of GrapheneOS based on Android 17 (2026061700) but aren’t going to release it through our Alpha channel due to discovering a serious upstream bug. Android 17 broke support for sideloading updates via recovery unless the OS images are large enough to exhaust COW space. > > The stock Pixel OS is drastically larger than GrapheneOS due to having a massive amount of additional bundled app code for Google Mobile Services, many other Google apps and various Pixel apps. It’s always above the threshold triggering the fallback code path for sideloading OS updates in recovery. > > Over-the-air updates from both older versions to Android 17 and Android 17 to Android 17 work fine. It’s only sideloading impacted by this. We don’t want to release an OS version with broken OS update sideloading so we’ve cancelled 2026061700 and are building 2026061800 with a workaround for it. > > Our current workaround is to force enable the fallback code path triggered by large OS images. This will fix sideloading an Android 17 version of GrapheneOS to another Android 17 version of GrapheneOS. However, sideloading Android 17 updates to older versions won’t work without a further workaround. > > We’ve tried making a build with a randomly generated 1GiB file included to make GrapheneOS about as large as the stock Pixel OS which fully works around the issue. We’re not actually going to do that but rather we’ll use the workaround forcing the fallback path for now and we’ll find a proper fix > > Our workaround will provide working sideloading from our initial Android 17 release to a future release. However, it isn’t currently possible to sideload from 16 QPR2. We could make an extra 16 QPR2 update for people who only sideload updates with the workaround to use until we make a proper fix. > > Google didn’t run into this because they add so much bloat to the OS for Google Mobile Services including Google Play services along with a bunch of other Google and Pixel apps. Pixel OS is a lot smaller than the OS on most Android devices but it’s drastically larger than AOSP and even GrapheneOS. > > GrapheneOS uses ahead-of-time compilation for Java/Kotlin code which greatly increases the size of the apps in the OS images. Despite this, it’s still drastically smaller than the Pixel OS. It would be substantially larger if we bundled as much code as they do but instead it’s the opposite…

#graphene_os #pixel_6_pro

Problem, die App der AXA und der Krankenkasse funktionieren auf einmal nicht mehr.

Fehlermeldung wie im Bild.

Was und wie kann ich tun?

Heute Vormittag jemandem geholfen, sein neues Pixel 10 mit dem datensatzorientierten Betriebssystem GrapheneOS auszustatten. Nach wenigen (na gut, vielleicht ein paar mehr) Mausklicks war das erledigt. Die Installation über WebUSB ist erstaunlich einfach. 📲

Deutlich mehr Datenschutz und gleichzeitige Alltagstauglichkeit sind kein Widerspruch. 🦾

#Graphene_os #android #privacy #diy