Conversation

The initial goal will simply be having fully working production builds of the Android Open Source Project running inside QubesOS. AppVM integration and an update system will need to be developed from that baseline. It should really be done differently than existing OS support.
2
38
The integration should provide an equivalent or better implementation of Android Verified Boot and atomic A/B updates. It doesn't fit well into the system used for existing OS support since the base system is read-only and updated atomically as a single unit at the block level.
23
Replying to
qubes-os.org/intro/ has a good description of QubesOS and that part of the work will add support for running Android apps compartmentalized inside it. It's harder to explain the hardened allocator other than it being a great defence against a large number of vulnerabilities.
22