Interesting; but I feel that their choice of a hypervisor-based design here supports my point of plain container-based isolation (or even containers + gVisor) being insufficient to achieve true sandboxing on Android.
> Android's sandboxing is not limited to ART and has multiple layers [0]. Native apps cannot bypass sandboxing, I don't think.
Yes, but when I say "sandboxing", I mean just the ART sandbox, not the other layers. I don't care whether you can get root / jailbreak the device. I (and presumably Google, in not publishing apps that do this in the Play Store) care about whether an application that, upon installation, doesn't request permission to e.g. read your contacts, can actually read your contacts. There are certain capabilities like that (not sure if "reading your contacts" is one of them, but you get the idea), that are only prevented from being accessed by ART, not by Linux ACLs. This is especially true when there's one level of permission that gets you access to a certain database file through an API, but then another level of permission that gets you access to certain special records in that database file through the same API. The lower level of permission is already granting you Linux filesystem ACLs to the database file; the only difference between the two permissions comes down to what ART will allow you to request through the higher-level API.