Virtual machines with KVM on Pixel 6 and Android 13 DP1
twitter.com
twitter.com
Since virtualization abstracts those historic incompatibilities and driver issues away, there's a lot more stability you can expect from there. That is in addition to some other legitimate changes Google is making to make Pixel phones somewhat closer to mainstream Linux.
[1]: PostmarketOS shows that it's very possible to do so on plenty of devices, but just not without a lot of tradeoffs: https://postmarketos.org
Don't get me wrong, it'd be nice to have a simple modem you could put Yocto on and then attach to some other thing over a memory interface. But it's really just a dumb set of pins you read and write to; the "meat" of the device security happens outside of it, and long before the data hits it.
Also I think there is some work on reverse engineering the AT commands for some PinePhone modems, which means you can install a Linux distro on the device to manage and talk to the radio. It's not the same as FDA-approved baseband firmware or anything (that wouldn't run Linux), but it's probably as close you can get for now.
By design, a baseband is able to track and report your location in real time without ever involving anything outside its silicon. Most basebands are also hooked directly into the microphone and maybe even camera.
Since all but a handful of phones have the necessary hardware allowing the CPU to disconnect the baseband from the mic/camera, no amount of clever software can stop a compromised baseband from eavesdropping and even with special hardware, unless you're willing to cut power completely, it will always be able to track you.
There's a lot wrong with hardware openness on mobile devices, but closed bootloaders and radio firmwares are also true on most Linux laptops that can thrive nonetheless.
At that stage, any further discussion (being able to read system ram or not, segregation or not) is moot, for, it's the ultimate in lack of trust.
On Qualcomm SoCs, EL2 is occupied by their HypX hypervisor, so KVM is impossible without exploiting HypX. I don't think OEMs are allowed to do much about it, and it seems to be a somewhat integral part of their platform, so removing it would likely be a big undertaking even if OEMs were allowed to do so.
On Exynos SoCs, the kernel boots in EL1, but Samsung has a security feature called RKP that involves loading code in EL2. This means that it's theoretically possible to hack it up for enabling KVM, but KVM doesn't just work out-of-the-box.
I'm not sure about other SoC vendors, but the most popular one by far (Qualcomm) effectively makes KVM impossible.
> On Qualcomm SoCs, EL2 is occupied by their HypX hypervisor, so KVM is impossible without exploiting HypX. I don't think OEMs are allowed to do much about it, and it seems to be a somewhat integral part of their platform, so removing it would likely be a big undertaking even if OEMs were allowed to do so.
For Chrome OS firmware stack, full EL2 is given to the kernel, the regular way.
For the Windows on Arm64 stack (on currently shipped SoCs), a mechanism, Secure Launch, is provided to escalate from EL1 to EL2. bootmgfw issues a SMC call, the function is the same as the one used to initialise Intel ACM or AMD SKINIT. QHEE intercepts it, does some sanity and integrity checks then remaps memory to load the TCB launcher and jumps to the entry point. This means that if you run Linux on those, you don't have EL2.
I get that 'infinitely nestable' is hard to implement in hardware, and it's much easier to design things with a fixed nesting depth/number of privilege levels, but I really don't think it would have been much of a stretch to design the instruction set with traps in the right place to allow software to implement infinite nestability without too much of a performance hit.
Nested virtualisation is available for server cores starting from Neoverse V1 onwards, but not for Cortex…
(Also, EL0 could be used as a problem state for this, but some complexities associated to that make it awkward. Unlike POWER (which does have KVM-PR), VBAR doesn’t link to a physical address)
Check out Samsung's "DeX" feature[1], though -- it's pretty much exactly what you're describing.
Google expects you to use Chromecast or buy an expensive DisplayLink adapter.
Every time I've used it, there is so much lag that it's unusable for a 2nd screen. Even for non-interactive screen mirroring like letting someone else watch you browse the web or play a game it's jerky and laggy.
It may sound weird, but I love Windows, and the opportunity to run Win11 on better hardware than a Lumia 950 is very tempting to me!!
For example this one[1] for the Oneplus 6/6T.
[1]https://forum.xda-developers.com/t/windows-10-arm-on-oneplus...
https://threadreaderapp.com/thread/1492712401262710784.html
Looks like the meat of this is just 4 photos, 2 videos, 3 tweets. Unless you want to dig through the rest of the conversation, in which case you could click through to the Twitter thread linked originally.