I wonder if a website using leaflet.js has better or worse performance in the said case. If it does better, then maybe the problem is on OsmAnd's side?
RKearney 18 minutes ago [-]
"Before installing, please turn off all anti-virus and firewall software."
pjmlp 2 hours ago [-]
Maybe the actual solution is to improve, replace the application.
izacus 2 hours ago [-]
Or maybe there's a reason why the mainline Android OEMs don't ship that allocator by default.
Groxx 2 hours ago [-]
The fairly obvious answer here is "OEMs don't care about security because very few people will pay for it, either with $ or time". Benchmaxxing sells better.
izacus 1 hours ago [-]
That's trivially provable as false.
nvme0n1p1 1 hours ago [-]
If so, I'd love to know which OEM you're thinking of who ships an Android distro more secure than GrapheneOS.
izacus 58 minutes ago [-]
Let's first start with y'all providing any proof that it was "benchmaxxing" that causes OEMs not to ship hardened allocators (and not - for example - breaking compatibility with users' software).
And then we can move the goalposts to "more secure distro with GrapheneOS" which isn't part of the conversation until you dragged it out.
nvme0n1p1 6 minutes ago [-]
If you're expecting some leaked internal document that says "priorities: 1. benchmarks, 2. security", no, that probably doesn't exist. But their priorities are revealed by their actions.
GrapheneOS typically ships security updates within a day. But most of Samsung's phones get quarterly security updates[1]. There will never be a primary source with a Samsung insider saying "we're fine with our customers being vulnerable to widely exploited security bugs for the next 89 days, in order to save our massive corporation a few thousand dollars a month." But their priorities are revealed by their actions.
If the statement "OEMs don't care about security" is trivially proven false, as you said, then you should be able to prove it trivially by naming even just a single OEM whose update cadence matches GrapheneOS's.
Because they cut costs on hardware and not all ship MTE enabled ARMs.
palata 1 hours ago [-]
Maybe... legacy?
mohamedkoubaa 2 hours ago [-]
There needs to be a wall of shame for apps that abuse hardware owned by users
yjftsjthsd-h 2 hours ago [-]
How's it abusing anything? It's an Android app that works fine with the default Android memory allocator.
pjmlp 2 hours ago [-]
The AOSP memory allocator is seldom the one used by OEMs.
rpdillon 59 minutes ago [-]
Really? They're not using Scudo? The hardened_malloc used in GrapheneOS has a bunch of performance issues that were trade-offs against security. Every other major android distribution uses scudo as far as I know. Which OEMs are you thinking of?
Edit: Did some research after writing this? It appears that Samsung may be still using jemalloc, albeit a newer version than the one from the Android 11 days.
perching_aix 2 hours ago [-]
That doesn't necessarily mean it isn't being abusive, just that said allocator tolerates it okay.
perching_aix 2 hours ago [-]
If you have two apps, both maps...
> The reason behind it is the hardened memory allocator, which seems to create a significant overhead for Osmand. That might be because scrolling a map requires constant loading and discarding of data.
... is this really the right hunch, over e.g. the OpenStreetMaps app lacking in discipline with its heap allocations?
himata4113 2 hours ago [-]
Seems unlikely, it's java so this is likely related to loading large amounts of objects and having the GC thrashing.
Osmand and GMaps are working fine.
Waze is almost melting the poor thing. Beside of that working fine.
And then we can move the goalposts to "more secure distro with GrapheneOS" which isn't part of the conversation until you dragged it out.
GrapheneOS typically ships security updates within a day. But most of Samsung's phones get quarterly security updates[1]. There will never be a primary source with a Samsung insider saying "we're fine with our customers being vulnerable to widely exploited security bugs for the next 89 days, in order to save our massive corporation a few thousand dollars a month." But their priorities are revealed by their actions.
If the statement "OEMs don't care about security" is trivially proven false, as you said, then you should be able to prove it trivially by naming even just a single OEM whose update cadence matches GrapheneOS's.
[1]: https://security.samsungmobile.com/workScope.smsb
Edit: Did some research after writing this? It appears that Samsung may be still using jemalloc, albeit a newer version than the one from the Android 11 days.
> The reason behind it is the hardened memory allocator, which seems to create a significant overhead for Osmand. That might be because scrolling a map requires constant loading and discarding of data.
... is this really the right hunch, over e.g. the OpenStreetMaps app lacking in discipline with its heap allocations?