Why not hardcode this for microG only, and not any system app ?
() No app spoofing () Microg apps can spoof Google apps () Any apps can spoof any apps
This would be similar to how root apps originally allowed anything to use root capabilities (with user permission), and then they made the default "Apps-only".
The only thing this patch does is provide a clean API for it, so that microG doesn't have to patch your entire system every time.