So, the real thing that's happening here is:

* Google drop "real" Android source-code updates to OEMs _and_ the public every half.

* But they ship four Pixel updates, including documentation + SDKs.

* Now they added new APIs in a Pixel-only update.

* Google also drop security update backports to "trusted" OEMs monthly (which GrapheneOS have had access to for years).

So, there are now Pixel-exclusive app features on the Pixel SDK version which isn't available to OEMs - but, it's highly unlikely any app developer would actually depend on these new APIs, since Pixel marketshare is tiny to begin with. This in essence just makes Pixels a weird beta-testing device for what will come out a quarter later to "normal" devices, which is sort of an odd business decision, but also a weird thing to get really mad about, in my opinion (I do see what GrapheneOS are trying to do, with having OEMs saber-rattle about not getting features on the same cadence as Pixels, it just doesn't resonate very loudly for me).

However, the API headline seems to bury a deeper lede; in the thread, GrapheneOS also claim that the quarterly Pixel releases contain security content which is not appearing in the monthly backports. This is quite bad and very sloppy if true, since the Pixel releases can easily be patch-diffed and exploits backed out of them. I'd be interested in seeing this enumerated in more depth.

> * Google drop "real" Android source-code updates to OEMs _and_ the public every half.

All of the major OEM shave access to the internal source with a _very_ small delay. OEMs don't ship these intermediate releases because they choose not to, not because Google witholds the source for them.

Oh! I had thought they stopped at the same time they closed off AOSP commits - that makes this entire rabble-rousing effort _exceptionally_ silly, then; I can't see the angle GrapheneOS are trying to push at all in that case (like, I get their side of the _concern_, but "Google are shipping features to Pixels that you don't get" becomes... quite a poor argument indeed in that scenario).

The whole security embargo things seems incredibly stupid. OEMs are always too late rolling out security patches. So Google thought, "let's create an embargo of months so that the OEMs have time to integrate the patches". Anyone could see it coming that nothing would change and the OEMs would still wait until the very last moment.

So now everybody is off worse. Not only are OEMs still slow with security updates, while CVEs float around for months among those within the know (or reverse engineering skills) for months.

Patch embargoes are a debate as old as security.

I think the overall source embargo is rational _until_ fixes appear in a released binary build. Otherwise there's an integration/QA/rollout window where a source patch is public while the binary patch is unavailable to anyone, including attackers, which is undesirable. In "full" open source this has always been a time-suck mental gymnastics exercise around hidden mailing lists and obfuscated commit messages (which probably aren't useful in the LLM era anyway). It makes sense for Google to avoid engaging with that given they don't need to; I think it would be fully logical for them to perform source drops gated on the rollout cadence to the first available binary release channel.

I fully agree the slower-than-Pixel "vendor lead time" windows are really detrimental. Once the binary patch is out, the source patch and disclosure is effectively out too; those extra windows just let OEMs continue to be lazy as a matter of policy (which they love to do regardless) while exploits are already available.

> which is sort of an odd business decision

It's probably no decision at all, but merely poor coordination between separate departments.

Once a bureaucracy surpasses a certain size, odd side effects accumulate on their own, and the growing number of people affected by them seek to cast blame where no purpose ever existed.

I felt compelled to reply to this because I agree with it so strongly (which is also why I phrased my initial post as "sort of odd" rather than "some evil anti-consumer monopoly volcano lair conspiracy"); so many corporate oddity theories are easily caused by dysfunction that I wonder how many of their proponents have ever really been exposed to a corporate job.

I don't really see what the Pixel-only early API releases achieve except for allowing developers to work on Pixels ahead of time, but Pixels are such a small sliver of the universe that it basically just gives Google a leg up, I would assume. And if you're on Graphene why would you care about Google's beta edge apps?

Exclusive access to QPR1 and QPR3 releases gives Pixels an unfair advantage over other Android OEMs. They get an extra 2 major updates per year. Introducing new APIs for third party app developers as part of these updates means third party apps will now run best on the Pixel OS. Google apps already run best on the Pixel OS due to many exclusive features. It's Google's standard overall approach to propping up parts of their business with their monopolies in other markets. It's not legal.

I honestly don't think anyone would care. They have a "leg up" for what 3 months every 3 months?

Nobody buys a Pixel because of this minute software advantage.

Maybe get Motorola or Samsung to support security updates for six years and get back to Pixel users.

Pixel 9a and earlier were officially sold as Android Open Source Project reference devices. Google made a commitment to providing 7 years of updates from launch for 8th/9th gen Pixels. Google then arbitrarily declared they were no longer AOSP reference devices with the release of Android 16 and stopped providing those updates. Many people bought Pixels due to this and it wasn't fulfilled. GrapheneOS has been able to continue support with a massive amount of work including reverse engineering, but other operating systems haven't been as successful and mostly haven't even moved to Android 17 yet or supported 10th gen Pixels.

There are currently around 400k to 600k active Pixels with GrapheneOS. There have been far more than that when including the past devices our users have purchased. Pixels are a small segment of the overall market and that's substantial. If you add in people on other operating systems such as LineageOS then there are even more people using Pixels with another OS. A significant portion of people who bought Pixels did so because they were AOSP reference devices.

Samsung provides 7 years of support with monthly updates for their flagship devices. Unlike the Pixel OS, Samsung ships a lot of the security preview patches early.

Motorola Signature (2026) has 7 years of support. The upcoming successor to it is the first non-Pixel meeting all of the update and hardware security feature requirements for GrapheneOS.

Pixel 11 currently doesn't meet our security requirements due to at least temporary lack of MTE support which may get added in Android 17 QPR2. The upcoming Motorola device is also going to be using a 6.18 kernel at launch rather than 6.12. We would have launched Pixel 11 series support already if they met our security requirements. It's likely they will down the road but it's not clear why they omitted firmware and software support for a major security feature at launch. It's the firmware part which impacts us.

“many people”? Almost no one cared when they bought Pixel is more like it.

Many people bought Pixel because they saw it in a store or online. A few people bought Pixel because it was supposed to represent the leading edge of Android and it still does. Almost no one bought Pixel for AOSP reasons or even know what AOSP is.

> Many people bought Pixel because they saw it in a store or online

That's usually reserved for iPhones and Samsungs. Pixels have a tiny marketshare compared to Apple and Samsung. The GP is right when they say a significant portion of buyers bought a Pixel believing Google's claim that it was the 'purest' Android experience since it was a reference AOSP device.

> Many people bought Pixels due to this and it wasn't fulfilled.

Did they though? Or is this just conjecture? Because, honestly, Pixels are not even available worldwide so a few AOSP enthusiasts dropping off and going to Graphene hardly seems concerning for the mighty G.

AOSP reference was a tagline for a few nerds that still wanted the Nexus devices of yore, but it was clear from day one that Google wanted their Pixel phones to be their iPhones.

Android's official documented listed Pixels as the Android Open Source Project reference devices until the release of Android 16. It also promised 5-7 years of support from launch.

Pixels are sold in 33 countries across North America, Europe, Asia and Oceania. A substantial portion of the Pixel userbase is using other operating systems. 400k to 600k active GrapheneOS users on Pixels is a significant amount based on how many Pixels are sold. It's only one of the alternate operating systems people are using. It's not only a few users as you're claiming.

I did

> a few AOSP enthusiasts dropping off

> I did

Precisely my point.

This is literally gaslighting; using someone's opinion as proof that nobody else holds it.

It quite literally isn’t.

No, this isn't what gaslighting is or means.

Saying that holding a particular opinion makes you irrelevant is not gaslighting? It's not nice to respond to a frustrated developer by saying they don't exist. It feels comparable to saying someone's concerns are not real, which does amount to gaslighting to me.

No one says graphene os doesn’t exist, or the developers don’t exist, just that their opinions don’t matter because they are a miniscule fraction of the market. 2% of active devices drives no decisions at Google.

Gaslighting is making a person question the validity of their own true memories.

I'm pretty sure the commitment has always been is for security updates, not for the latest OS.

My first phone was a Motorola that shipped with Eclair. Froyo had already been released and Motorola had a release date for Froyo scheduled in their website. They changed their mind. I don't trust Motorola one iota. Google has never lied to me they way they Motorola has. Good luck.

No, there's a clear commitment to 5-7 years of major OS updates in addition to security updates. Both commitments have been broken for the Pixel 6 through Pixel 9a. Those were sold as Android Open Source Project (AOSP) reference devices but had the updates to it prematurely cut off with Android 16. Pixel 10 and later weren't sold as AOSP reference devices so there was no commitment to providing it, but that's not the case for the earlier devices.

Thats a long time for a critical security patch to land (like this one [0], although it looks like it has been fixed now, at least in their alpha channel, which is annoying (not their fault) because we really need this patch).

[0] https://news.ycombinator.com/item?id=4974151

That link has nothing to do with android or google or graphene or security patches whatsoever.

The rattling is because of the security patches of course.