Google has recently and quietly altered how developers access kernel source code for its Pixel series devices. Previously, Google published the relevant source code and its complete commit history directly to a public Git repository. Now, however, Google no longer releases the source code openly – developers who need it must contact Google directly to request access, and once approved, Google delivers the source code through Google Drive instead.
From Open Download to Manual Application
For many custom ROM developers, Pixel devices have long stood out as an especially developer-friendly choice. Google not only publishes the Linux kernel source code as required under the GPLv2 license, but has historically provided the complete Git commit history as well – allowing developers to review every individual modification, patch vulnerabilities, and adapt their work to new Android releases with relative ease.
However, the GrapheneOS development team reported that portions of Pixel’s kernel source code have now shifted to a manual application process. Developers must fill out a form provided by Google and then wait for Google’s review before receiving a Google Drive download link. Source code that developers could previously retrieve instantly by browsing Git now sometimes takes weeks for Google to respond to.
Adding to the complication, the source code Google now provides may merge multiple changes together, no longer preserving the clear, granular commit history developers previously relied on. This makes it considerably harder for developers to pinpoint exactly which changes Google made, further complicating both vulnerability auditing and general troubleshooting.
Third-Party ROM Developers Bear the Brunt
This change carries no direct impact for ordinary users. Anyone running the official system on a Pixel device will continue receiving Android version updates and security patches as usual. The developers genuinely affected are those working on third-party ROM projects, which require access to the corresponding kernel source code in order to compile, test, and conduct security audits when adapting their systems to new Pixel releases.
If simply obtaining the source code now takes weeks, third-party ROM projects may be forced to delay the release of new versions and security updates as well. The Linux kernel itself remains bound by the terms of the GPLv2 license, meaning Google is still obligated to provide the corresponding open-source code.
The core of the controversy centers on whether source code can still be obtained promptly and conveniently, and whether the full development history should continue to be made public. In practice, this shift has diminished Pixel’s appeal to ROM developers, and by extension, affects users who rely on third-party ROMs on their Pixel devices – since the timeline for new ROM releases now stands to be pushed back as a direct consequence.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.