> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.
> That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services.
> Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.
EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.
Google Mobile Services apps installed on GrapheneOS including Play services run as regular sandboxed apps. They receive absolutely no special access compared to other apps by installing and running them. There are the standard permission toggles for granting those but none of those are required for typical usage to provide compatibility with many apps from the Play Store depending on their services.
There are additional special permission toggles for RCS and Android Auto. The issue with RCS is mainly that they split the implementation across Google Messages and Play services. Android's standard permission model gives special access to the app selected by the user as the messaging app but Google Messages expects Play services to have special access too.
The shims defined with GmsCompatConfig are a small subset of the overall compatibility layer. It has many shims which need to actually implement the functionality such as remapping the Play Store using privileged installation APIs to the regular ones available to user installed app stores. It has to remap the APIs used by dynamite modules to ones not requiring privileged SELinux policies too. It has a mix of shims which simply stub out the functionality and many which need to handle it as a regular sandboxed app would need to do it.
I used this for my family's recent trip in Lisbon and Prague. It worked great! The OSM data was reasonably up-to-date for all of our destinations; I don't remember encountering bad information, even though I often double-checked with other mapping providers (which aren't immune to issues with out-of-date information).
One awesome feature was being able to find "drinking water" while we were walking around. I did come across a tap that was shut off/unavailable, but only once. Again, this is more of an OSM data thing than CoMaps, but I generally found the app pleasant to use.
There sometimes feels like there is something slightly off with the "Route To/From" UX that I can't put my finger on, but no complaints.
The problem I have most of all with the routing is that it seems to default to my location as either the From or To value (whichever is the one I haven't selected). Once that's been chosen it's not immediately clear how to change it, all you can do is view the route. That's a fine solution when you're immediately looking to go somewhere, but it's not great when you're trying to plot a route between two places in advance.
I've been using CoMaps for a few months and only just discovered that if you choose another location on the map once you've got an initial route and select Route To/From, it then updates the current routing.
> The problem I have most of all with the routing is that it seems to default to my location as either the From or To value (whichever is the one I haven't selected). Once that's been chosen it's not immediately clear how to change it
Yeah this is an oft-asked question at least for OsmAnd, but I was recently corrected on this myself: so long as you don't press 'start' on the route, you can always change the from position freely and it won't flip back to your current location. You can close the navigation window (back button, swipe it away, or tap on the map) to get the map view back in full-screen for further browsing and selecting another point that you want as departure point, waypoint, or (subsequent) destination. Rinse and repeat until you have the route figured out with all the waypoints :)
I use this a lot for planning mapping routes. Another protip is to go into the waypoints view and on the top right you can do traveling salesman sorting to get the shortest way that visits all waypoints
CoMaps/OrganicMaps I don't know; I'm one of those who grew up with OsmAnd and got used to having all those features
The runner's high I've experienced comes after completing a long, hard race and finally getting to rest after pushing myself beyond what training was like.
It's the opposite of shade, unless GP is being sarcastic. "Class act" is normally a compliment, and in the context here it sounds to me like they're congratulating Baidu/the researchers in being transparent about where their ideas came from.
Any compliment can be repurposed as sarcasm, but it's obscenely cynical to immediately assume a compliment is sarcastic - instead of just a compliment. And by the way, there's no 'real' in the poster's message.
Yet you responded to my comment in the most cynical way possible. I was excusing the misunderstanding -- I assumed that the parent might only have seen it used cynically as that is a charitable way to interpret the apparent miscommunication and is quite possible. You shit on my comment and then told me doing such things is "cynical". Imagine a pipe before the closing square-bracket if you wish -- the standard editorial convention as I learnt it was that square-bracketed terms may be present or not (in English Language prose).
For sure, that or just ensuring they have laws in place that grant them access to the unencrypted data we are sending to CDNs operating in their jurisdiction (when necessary for national security reasons).
There's probably a useful middle ground between tossing people in jail and rewarding with great wealth, power, and influence those people whose main drive appears to be accumulation of said things without regard for their fellow citizens.
We have CI actions we use to configure and deploy dev namespaces. We document a bunch of steps for these actions in a doc, including situational tweaks. I could see this being a great replacement for that, given the right integrations.
I've read good things about Seafile and have considered setting it up on my Homelab... though when I looked at the documentation, it too seemed quite large and I worried it wouldn't be the lightweight solution I'm looking for.
reply