English

FP2 missing security bulletins?

Hi. The current version of the FP2 OS (19.05.3) only has the Android monthly security updates up until March 2019. Before that update I believe it was December 2018. Shouldn’t we get security patches delivered a bit more frequently?

The latest ones were released on 2019-07-01 (https://source.android.com/security/bulletin/2019-07-01.html)

Fairphone is the first company offering Android 7 for the CPU used in the FP2, so it is requires quite some work for them to update. See also the Fairphone Blog about Android 7: https://www.fairphone.com/en/2019/01/23/whats-next-for-android-7-on-fairphone-2/

7 Likes

True.

Would it help if I ran LineageOS instead? Do they do monthly patching?

Yes, they do monthly security updates.

2 Likes

To a certain extent. Patches from Qualcomm don’t come in monthly, only when FP OS updates so you’re not entirely up-to-date either that way.

1 Like

Ok. Thanks for the info.

It’s very unfortunate that the patches are hardware specific. Does anyone know why that is? I mean, Linux or any other OS doesn’t have that problem.

Google has decided to include hardware vendor’s patches into their monthly patch levels as well. On other OSes those are often separate, so they get less attention.

The underlying problem exists on computers as well: drivers are closed source and vendors can decide any moment to stop updating them. On Windows, you won’t notice that unless you upgrade your OS from Windows 7 to Windows 10 (for example); you can continue to run drivers that are years old on Windows 7 just because 7 has been around since 2009 and is still supported at the moment.

On Linux it is less bad indeed as you do get kernel updates, but there you also have to deal with closed drivers for graphics/wifi at times.

2 Likes

I’m not sure I fully understand what you mean.

My knowledge is

  • LOS does not include vendor patches (those from Qualcomm)
  • vendor patches may only be included in updates to Fairphone (Open) OS (the community provides a modem.zip that can be flashed for LOS; this modem.zip would include the vendor patches)
  • not every FP(O)OS Update includes vendor patches
  • Qualcomm has stopped support for the Snapdragon 801 so there won’t be any vendor patches anymore for the FP2
4 Likes

Yes, I mean the modem.zip. I was on mobile and didn’t have time to look up the exact phrase.