LineageOS 19
lineageos.org
lineageos.org
(and actually I also wish they could implement the shims developed by https://grapheneos.org/usage#sandboxed-google-play in order to sandbox the google play services, so that the user could choose between approach 1 (microg with signature spoofing) and approach 2 (sandboxed GSF) on any smartphone supported by LineageOS (grapheneos only supports Pixel phones due to their ability to relock the bootloader))
But I agree with your sentiment.
You can also migrate off google and not worry about it.
I'm not sure about paid apps unable to install, never tried, I thought that's the whole point of signing in with your own account
Because of this I'd love to see GrapheneOS' sandboxed Google Play Services shims I'd love to see integrated into LineageOS.
The Lyft equivalent is <https://ride.lyft.com>.
I have no idea why GrapheneOS takes this risk, but am grateful to them nevertheless for the code.
And also, even if it's technically legal, it's such lawsuits/slappsuits can entirely bring down an organization as legal fees can be very expensive. They probably want to err on the side of caution so that Google can't, and wouldn't care to, sue them.
The SafetyNet part is something I read from somewhere else, though unfortunately I don't remember if that was LOS or some random developer on reddit/XDA. You can treat most of this as (oft-repeated) speculation by users.
> Yes MicroG is open source, but they probably had to reverse engineer something.
MicroG being open source is irrelevant. The relevant point is that google play services is not, so MicroG devs could not have copied source from it. Besides the fact that the API used by other programs to interact with play services is public and that the team had no access to the play services source code US law also has a specific carve out for "interoperability" which might (I'm guessing) apply here. Google has already spent many years and many millions in court arguing that an API is not copyrightable.
IANAL but it seems hard to argue that this would be an easy legal case.
First the question is how to transfer all your application data, for which there still seems to be no surefire way. I settled on "Neo Backup", which mostly worked fine, except for Signal (of course...), and the darned Microsoft Authenticator.
So first unlock the bootloader (good luck), then you need to find the correct TWRP for your phone (and careful with 32/64 bit) and flash it via fastboot.
Then I flashed LineageOS, which worked fine. Luckily I found an image which already had the signature spoofing patch included, so I didn't have to worry about that. How do you get root? SuperSU? XPosed? Magisk? OK it seems everybody's using Magisk nowadays. OK, flashing worked fine, but now, how do you get MicroG on it? If you look at the MicroG homepage, you might think you can just install it with F-Droid, and you actually can, but many things won't work (like FCM notifications). It needs to be a system app. I tried using the F-Droid Priviliged Extension, flashed it via TWRP, which seemed to work fine but actually wasn't installed and not working at all. Now what? There's a multitude of information in forums what to do. Some say to flash NanoDroid, but the last release was in January 2021, it seems it's not updated anymore? I settled on the "MicroG installer revived" Magisk module, which worked fine (btw, there's no curated Magisk module repo anymore, you have to search the web and hope you find something that's not malicious).
Of course my banking apps refuse to run because "U ROOTED UR PHONE", I search for Magisk Hide, it doesn't exist anymore, now you need to configure a "Zygisk deny list", whatever that is. Then I also need to hide the Magisk app, my banking works now thank you very much. FCM notifications also work after I uninstall and reinstall my apps which need it...
To be clear: I'm eternally grateful to all the developers who make this possible in their spare time. This is not their fault.
This provides fine-grained control over battery charging if the kernel/device have the required features. The user can set limits on current, voltage, and percentage, as well as pause charging when the battery gets too hot. These settings can be saved into profiles selectable with a tap or on a schedule.
Limiting charge speed/capacity can significantly extend the service life of the battery.
I eventually found out about LineageOS for MicroG [1] which is a variant of LOS with MicroG bundled which cuts out most of the fooling around, removes the need to root my phone and works with both banking apps that I've tried.
I'm shocked and upset to hear that the Magisk repo and Magic hide are dead :(
https://topjohnwu.medium.com/state-of-magisk-2021-fe29fdaee4...
I do like what the project achieved, but I don't understand in the slightest what they are thinking. If I were to speculate, to me it feels like a leftover from their failed attempt to make this a business to ban everything some corporate partner might dislike. But what purpose would that serve for the project now? Just baffling.
https://lineage.microg.org/ really seems to be the way to go, as mentioned in the other comment.
So no root, no GFS or substitute at all. Only tracer free apps (except my bank) and using browsers.
I use a set of privacy add-ons (canvas fingerprinting etc) for wandering on the web and the "WebApps" app to isolate the web sites I use regularly and where I need to log into my account.
Then the TrackerControl app lets me allow or block connections per app and by destination.
Of course, this choice implies to renounce certain services without a web version, but I'm happy with the tradeoff (less time spent procrastining by consuming social networks content).
It's a bit annoying at first but I paid $80 for this secondhand phone (including a good new battery). Within weeks I didn't notice anymore that speed difference with a native web app.
That difference of speed exists, of course, but I'm fine with the whole tradeoff.
Not being at all a security expert, I did my best - following advice found on the net.
How far is my privacy better protected though? I can't really know - that's my only true frustration. I see very few ads and they look poorly targeted.
Well, sorry for the long post, this was just to mention another possible path: no GSF or substitute at all, no root.
Exactly. Even if the phone is already unlocked, the official LinageOS installation instructions explicitly say to do a "Format Data / Factory Reset" in recovery before sideloading the OS.
However if you're flashing a ROM or upgrading an already unlocked phone you do not need to format it.
I hope you're not implying LOS is only useful for old devices.
LOS supports many relatively new devices, including many flagship phones. It also arguably offers much better experience than the default bloatware-ridden OEM OSes, which is the reason I check which currently sold devices are supported before buying a new phone.
Life is too short to struggle and play games with the spyware that ships on phones by default nowadays. Better to be able to blow it all away.
I won't buy one that doesn't have an aux port. Do you know any lineage-supporting modern phones that have an aux port (and an SD slot, ideally!) by chance?
You can’t use that tool’s SD Card column right now, since its code hasn’t been updated to match the LineageOS wiki’s new data shape. (I fixed that bug locally and plan to submit a PR.)
I'm so glad to hear this. Every other custom ROM's Android 12 version had to remove the "disable internet access per app" feature.
Lineage took its time to rebase to Android 12, but they did it without removing important features like this.
Their firewall is pretty simple though (per app enable disable). Does lineage support more complicated policies?
Just yesterday I was wondering if it was still supported by LineageOS, and I see that it is not. What are the chances that a new version will work on this "ancient" device?
And even if I do, would it be safe enough to use or does the hardware have serious, unfixable flaws?
Got me thinking about the obsolescence of our modern gadgets.
> It's currently only used as a fancy alarm clock, I got an app that requires me to solve math problems to disable alarm.
I use Solid Alarm Clock on a relatively-new Note 10 Lite for this purpose.https://forum.xda-developers.com/t/rom-unofficial-11-0-i9305...
https://forum.xda-developers.com/t/rom-unofficial-12-0l-i930...
However, "random reboots" doesn't sound great for a daily driver...
But just look around in the forum, sometimes there's a good alternative, it doesn't have to be Lineage.
Kudos to the LineageOS teams and all contributors! You make Android usable. Which reminds me I should definitely donate.
Does anyone here have experience in porting AOSP/LineageOS to an unsupported device? Any suggested materials and resources?
I have the spare time to give it a go on getting it for my Samsung model, but no idea where to start.
What's the future of AOSP? There are other distros like GrapheneOS and CalyxOS that take advantage of the open-ness of "google pixel" hardware. But I think the end goal is to replace android with a linux userspace like postmarketOS and containerizing android with Waydroid.
You also need to clear the data of Google Play Services and Google Play Store, and of the apps that detected root.
https://nitter.net/topjohnwu/status/1237830555523149824
Luckily, all banking/authenticator apps I depend on only check for root and do not require SafetyNet. Yet....
https://developer.android.com/training/safetynet/attestation...
I'll just wait for the OpenGapps to have at least an unofficial 12.0 version to upgrade, so I can keep using the minimal Gapps required and not bloat my phone with crap I'll never use like Gmail or Youtube.
I could install everything and then uninstall via adb, but still, I'd rather wait.
Gives you filters for battery replacement difficulty and headphone jacks.
edit: add explanation
I just updated it to include the new version. It's called 19.1 in their wiki and I'll just copy that version number for now.
https://lineageos-device-finder.org/lineageos-device-configu...
What I found there was a list of model codenames like "redfin" rather than "Google Pixel 5". Now I've already found the list I wanted, however. Thank you anyway.
https://github.com/LineageOS/lineage_wiki/tree/master/_data/...
It contains the full model name in the yml data.
But if you are from US you can have problems with LTE bands maybe.
not exactly sure how exactly are official Lineage builds more trustful than unofficial, since it's same random forum users developing all these builds whether official or unofficial
Alternatively, you could look to see what resellers such as these people stock.
(No affiliation, I've never heard of them, and they're not cheap.)
At some point, a transitionary .zip was published to help users upgrade between versions. However, I'm pretty sure their official policy is still that you should do a clean install.
I think upgrading between versions works (as long as you do it in order!) but your system will be a lot more stable if you do a clean install. The same can be said for any major OS upgrade, really, be it Windows 10 to 11 or Ubuntu 20.04 to 22.04.
How does it compare to flagship Samsungs/Pixels/iPhones? Is it usable in, say, corporate settings that do have some security standards in the vein of "two years old iPhone OK, six years old Android not"?
Security is not their top competency, nor mission.
Check out the pages on GrapheneOS.org, definitely seems they're who you're after.
Can you provide evidence for this?
From another subthread:
> They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
I don't see any evidence for your claim there.
> From another subthread:
Replied in that one.
If you want to skip paying $150 for a Pixel to use on Graphene or Calyx or something halfway decent, and "just use Lineage how bad could it be", be my guest!
Also, for supported Pixels $150 or less, https://swappa.com only has the Pixel 3a, which loses manufacturer support next month, and the Pixel 4, which loses manufacturer support 6 months from now.
LineageOS's first priority isn't security - it's freedom. Graphene and CalyxOS have security as the first priority - but have only a couple of phones on their support list and they deprecate old devices as soon as they stop receiving vendor updates.
But, importantly, they also care about security, and you'll get security updates faster and more often than with the vendor's stock ROM.
This is sarcasm, to be clear.
(on my device, it is possible to just "fastboot oem lock", but that is aside the point)
What specific security problem does this cause?
> pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.)
This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix what you can.
> ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates)
What's incorrect about it?
> don't support locking the bootloader to enable verified boot on many supported devices
This isn't really their fault. On most devices, relocking the bootloader with anything non-stock has a high chance of permanently hard bricking.
No, it isn't. It's good for reducing e-waste, your security is on the line.
Having the newly shaped and colored Android UI doesn't do anything to fix security issues..
They don't "pretend" anything. They are very clear that, after a device no longer gets kernel/driver updates from the manufacturer, they can only provide OS/framework updates.
> don't support locking the bootloader to enable verified boot on many supported devices
Can you expand on this more? My understanding was that you could do this on Pixel phones, but that no other manufacturer supports adding user keys to the bootloader.
The point is, it's not as secure to run around with this disabled.
No, it's not only about in-person or targeted attacks.
`userdebug` is used to have a few specific debugging capabilities that aren't available on a `user` ROM. Note that this is not the same as the standard `userdebug`, as most security measures that would otherwise get removed are manually reinstated.
> pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.)
So... no security fixes at all are better in your opinion?
> ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates),
Where are you getting this from? Neither F-Droid nor its privileged extension is included in the system.
> don't support locking the bootloader to enable verified boot on many supported devices
There is nothing that inherently prevents you from relocking your bootloader on LineageOS. But technically, something may go wrong at any time, so it neither is officially supported nor endorsed, and the keys necessary for relocking the bootloader are not provided.
If someone wants to, they can always just build LineageOS themselves (with all system modifications built-in, because anything else would break the signature), sign it with their own keys, and reconfigure their bootloader to use that key.
In addition to providing a stable platform to build upon, Android gives additional support to developers in a number of ways. The Android security team looks for potential vulnerabilities in apps and suggests ways to fix those issues. For devices with Google Play, Play Services delivers security updates for critical software libraries, such as OpenSSL, which is used to secure app communications. Android security released a tool for testing SSL (nogotofail) that helps developers find potential security issues on whichever platform they are developing.
Vs.
>Android is designed for users. Users are provided visibility into the permissions requested by each app and control over those permissions. This design includes the expectation that attackers would attempt to perform common attacks, such as social engineering attacks to convince device users to install malware, and attacks on third-party apps on Android. Android was designed to both reduce the probability of these attacks and greatly limit the impact of the attack in the event that it was successful. (Read: Handcuff users to keep them from violating developer expectations and assumptions)
>Android security continues to progress after the device is in the user's hands. Android works with partners and the public to provide patches for any Android device that is continuing to receive security updates. (Read: we work with developers (them again)* to provide patches to devices that are convenient to deliver patches to)
>More information for end users can be found in the Nexus help center, Pixel help center, or your device manufacturer’s help center. (Read: we take no responsibility for explaining how any developer's use of this power is exercised, ask them!)*
>This page outlines the goals of the Android security program, describes the fundamentals of the Android security architecture, and answers the most pertinent questions for system architects and security analysts. It focuses on the security features of Android's core platform and doesn't discuss security issues that are unique to specific apps, such as those related to the browser or SMS app. (Again, even when talking about users, the language drifts back to people we'd lump under developers... who exactly is the User here?)
Then this gem:
>Verified Boot strives to ensure all executed code comes from a trusted source (usually device OEMs), rather than from an attacker or corruption (oh, is corruption where user programs are classed under?).
It establishes a full chain of trust (for whom, OEM's again?), starting from a hardware-protected root of trust to the bootloader (whose root of trust, OEM?), to the boot partition and other verified partitions.
Sorry, but the language used to describe all of this completely lets the cat out of the bag on who the Android community holds to be the true benefactors of your "ownership" of a handset.
https://source.android.com/security/
Straight from the source. Quiet parts emphasized and said out loud by me.
Android is the most transparently User/operator hostile piece of Open Source software I have ever had the misfortune of laying my eyes upon. The fact you basically have to be a developer to list and understand the things you need to do to get anything non-trivial done speaks volumes.
As for the Android stack itself, LineageOS follow the upstream Android branches very closely where it can. Most vulnerabilities in that stack will probably be shared among devices, so security issues will probably be fixed within a reasonable amount of time. Google's Android patches should also be present in the nearest weekly updates after public release.
The lack of official driver and kernel patches make the security of LineageOS a little strange. There are definitely some patches that LineageOS can apply, but in the end they rely on the vendor to publish all the necessary patches, and that can take a while.
There's also the fact to consider that out of necessity, the bootloader on the phones is unlocked. Most phones won't allow you to lock it again with your own keys (if you try, you'll often brick the device!) so it's trivial for a malicious actor to flash a new OS full of spyware and key loggers onto the system partition.
Having said that, LineageOS supplies weekly updates to my Oneplus One, even though it's showing its age. Neither Qualcom nor Oneplus will ever release any more patches for this device, so for kernel level security I'm boned. However, I still get the latest and greatest Android 11 framework security patches. This should protect the phone against the huge Bluetooth exploit found a few years back despite it being over eight years old now.
LineageOS is quite transparent about this, even showing that their device is missing patches right inside the settings (https://www.xda-developers.com/lineageos-trust-centralized-i...). I don't think you can expect much more from a project run by volunteers.
My daily driver phone receives "quarterly" security updates (sometimes off by a month or so) so I'd rate LineageOS above Xiaomi in this sense. The LOS Android stack itself should also be on par with or even better than some flagship phones.
Sadly, for the complete picture, Qualcom and other manufacturers determine how secure LineageOS can be. In general, the bootloader lock status and lacking supply of source code are a real pain for open source efforts. Some phones may see a mainline kernel with all of the recent Linux patches as a result of the postmarketOS efforts (https://wiki.postmarketos.org/wiki/The_Mainline_Kernel) but cleaning up vendor code and reverse engineering drivers isn't exactly a fast process.
I personally think the booloader lock is of dubious value. It protects against physical attacks against the device (evil maid attacks).
That's very low in the list of threats I worry about.
(Though I am using GrapheneOS, and am happy with it.)
I'd be more worried about the lag between Android security patches (and vendor blobs, which GrapheneOS gets direct with android updates, from what I can tell) and custom ROM updates.
You're much more likely to get hit by some Samsung zero day that impacts 100M active devices than something targeting a custom ROM.
(All of this is assuming you're a boring target, which most people are.)
Anyway, the main deciding factor for me between the two operating systems was device support.
I have no experience with GrapheneOS, but I've heard good stories so far. It's very good to hear that the Pixel devices allow re-locking of the bootloader.
Personally, I consider exploits in the Android framework itself and drive-by-exploits (like BlueFrag) to be the most important security vulnerabilities so I'm fine with LineageOS.
Not everyone might agree, though, and custom ROMs come with some security challenges or problems that stock software does not. I don't think such flaws should be left out of discussions like these.
Well, you get weekly updates, and you can see what changes are made. Most of them are security ones, and you're getting them 4/5 times a month vs once per month with stock Android in my previous experience.
For example, here you can see the changekog for the Motorola Moto G7 Plus.
I don't think this can be compatible woth corporate policies, though. As an end user, I'm more than satisfied.
> corporate settings that do ha
Use a dedicated phone
Of course, phones don't work as regular desktop computers do for some reason, though i really enjoy being able to just throw Debian/Ubuntu/Rocky/Alma (or some of the BSDs as well, though support varies) at some pile of x86 consumer hardware and have it vaguely work.
The only exceptions to that have been specific components in laptops: trackpads (disabled in default config back in CentOS/Fedora for some reason), Wi-Fi drivers (needed to be compiled off of GitHub) and fingerprint scanners (no idea, never worked on *nix no matter what i did).
Edit: apparently there is an older version of LineageOS available, though. https://www.getdroidtips.com/lineage-os-17-1-ulefone-armor-x... (just one device, i have a slightly different one)
This is because ARM uses device trees to know what hardware's on the device, versus x86 which discovers it at boot. Every rom has to be specifically built for that exact device model.
I can't use it right now, but I have many fond memories of LineageOS (and CyanogenMod before that), and I look forward to using it again in the future!
[0] https://forum.xda-developers.com/t/lineageos-19-1-android-12...
Highly recommend either of these as a way to keep a perfectly good Pixel working.
Is there a more valuable free open-source community project like it for anything else in the world? Because it seems incredible to have.
Hard to figure a new tablet to buy that will get that same 10 year life, some custom rom development just vanishes over time. Popularity doesn't seem to be a guarantee.
I have a second-hand Nexus 7 (repartitioned flo), probably the same as you, and I'm super happy with it thanks to Lineage OS. LineasOS 19 doesn't seem to be available for it though (yet?).
> Hard to figure a new tablet to buy that will get that same 10 year life, some custom rom development just vanishes over time. Popularity doesn't seem to be a guarantee.
If I would be buying a new tablet today, beside second hand (better for Earth, more guaranties to have a FOSS ROM running on it, and cheaper), I guess that I would go for open hardware like what Pine64 is doing: the community is dynamic, and I would not be surprised to see the device still updated in 10 years.
For phones, I guess that Fairphone is a very good option too: FOSS friendly, easily fixable, and minding about resources.
I just wish the devs clarified timelines around merges (but not builds) on older branches.
"When it's ready."
Stuff is merged in once it's well tested and ready. It also is only updated as long as someone still cares to update it.
Why on earth do I need to manage YET ANOTHER account just to ask a question, get a response, and leave?
Isn't Android mostly isolated in its enclave?
I got many answers to my Lineage questions on reddit. All were already answered in fact.
This means that ~95% of users would break their installation by pressing the "auto-update" button because they didn't update their GApps accordingly.
Also, nowadays there is the problem of requiring a certain version of the built-in firmware as well, and in case there are any incompatibilities, a major version upgrade is the perfect time to require updating that as well.
I can't even get a response from Google's support about the issue. (Although, based on what I've seen from other people in the same situation, the response would be pretty useless if I did get one.)
I'm still using the phone, because the hardware is perfectly fine for my needs, but it's slowly turning into e-waste as the software gets more and more out of date. (I replaced the battery about a month before learning about the bootloader, so it's good for another 3-4 years.)
Edit: I'm not the only one this happened to - see https://support.google.com/pixelphone/thread/14920605/google... and https://issuetracker.google.com/issues/73217322 and https://issuetracker.google.com/issues/68897739 and https://forum.xda-developers.com/t/rma-phone-from-google-is-... and https://forum.xda-developers.com/t/oem-unlocking-grayed-out-... and https://www.reddit.com/r/Android/comments/9xcdle/psa_rma_ref...
And, yeah, I agree that it's probably the worst of all situations. If I'd have known that a google repair would cut the phone's lifespan in half, I'd have just done the repair myself, or else hired someone local to do it.
Anecdotally, I purchased a 4a 5g from Google with a dead headphone jack. My replacement also had an unlocked bootloader though I think it was also new.
Based on anecdotes like yours, I believe Google stopped doing it after the Pixel 2, but that doesn't help me.
I'm not the only one to experience this issue, see https://support.google.com/pixelphone/thread/14920605/google... and https://issuetracker.google.com/issues/73217322 and https://issuetracker.google.com/issues/68897739
I had the same plans, but I was always afraid that running the camera for a long(-er) time will degrade the sensor fast, so te phones are collecting dust in a drawer now :)
There are enough settings to allow for just about any use-case. For me, I had issues doing full HD over wifi, since the router is upstairs in a different room, but you can play around with settings for resolution and FPS until you find something stable enough for your setup.
The heating seems okay, leave it on 24/7 with no downtime. Occasionally the phone falls off the wall due to the advanced taping mechanism keeping it there, but that's not the software's fault.
You can have it automatically run at boot. We have load shedding here often, and the phone recharges quickly enough after the 2 hour shutdown of power and can stream throughout (connected to mobile hotspot wifi - also for loadshedding reasons)
I don't buy many apps, but this one I recommend for sure.
Note that I have no specific knowledge on the subject ; it's quite possibly a fear without any reasonable ground.
But I had a cheap speaker that I used with a Chromecast audio to listening to podcasts ; I left it always on and... I came back just in time one night, the speaker was producing a large dark smoke.
I almost put fire to one of the oldest habitation building in Paris (1704) - with a lot of apparent wood etc. :-(
Not proud of it, but good lesson. I recently read about the risk of fire in cheap replacement phone chargers. Google's ought to be of quality but... still a no-no for me.
Obviously, advice from people with knowledge on the issue will be appreciated.
Having it plugged in, OTOH, probably doesn’t matter. There’s safety IC to prevent overcharging. Actually fully draining, mechanical damage, water damage etc. are more dangerous, which can happen during normal use anyway.
I google "flashing unlock is not allowed" every few months, but there's nothing new to try.
LineageOS (running on a different device) has changed the game for me. It has been a smoother, more accessible Android experience, and I'm so grateful to the developers who make it happen.
The primary reason is the loss of iptables, and the older kernels that do not support eBPF.
U.S. carriers are also moving to VoLTE, and this is not supported on any Samsung devices at all. AT&T has already made the move, and published a list of allowed devices.
It's sad to see them go.
> The primary reason is the loss of iptables, and the older kernels that do not support eBPF.
It's worth noting that the pmOS folks are working on mainline kernel support for older devices. This is not always easy, since e.g. some devices are only supported via non-free kernel or userspace blobs. But good quality hardware might regain support at some point. If you have devices that are going unsupported because of this issue, you might want to experiment with porting them to a mainline kernel by following the instructions on the pmOS wiki.
Just bookmarked your site for inspiration, I love how smooth it is to switch languages.
Also, I find it unlikely that we could compel google to do the right thing and unlock everyone's phones, even if we won. I think the more likely outcome would be a small monetary compensation that was hardly worth anyone's time (except for the lawyers).
It's clearly becoming mafia-like, you are afraid of them just because of their reach.
I've definitely had this stance in the past, but at the same time, where there is no repercussion for the company doing this kind of stuff, it just makes them(and others) more open to it in the future.
IMO, that shouldn't cause SafteyNet to fail either, but that's a different issue...
Also, the phone was bought in 2017, and the repair happened in 2018, so I think all of it predates that SafteyNet tightening.
I didn't know that 19.1 was released until now but it looks like it can't be installed using the updater on that phone.
Then again, Google would probably terminate your Google Account if you did this. And good luck suing Google for retaliation...
Also, given that you can get a used pixel 2 for under $100, I doubt it'd be worth the trouble in the first place.