Source copied from AxionAOSP's android_axion_sdk (ax_sandbox) and the integration-relevant parts of their frameworks/base fork (AxionAOSP/android_frameworks_base, lineage-23.2) -- explicit, informed decision to reuse the actual source rather than reimplement, made with full knowledge that all but one file (AxSandboxManager.java, which carries a real Apache-2.0 header) has no license grant of any kind. See README.md and notes/axion-port-plan.md in the main workspace for the full decision record. common/: the public android.app.* manager classes, meant to compile directly into frameworks/base's core/java sources (filegroup reference, not a normal library -- see the companion framework patch). server/: the system_server implementation (AxSandboxService as a SystemService, AppLockService, and the apphide/isolation/spoof sub-packages), meant to compile into services.jar the same way. Neither directory builds standalone; both need the framework patch that references these filegroups and wires in the IActivityManager surface, AMS delegates, SystemServer/Context/SystemServiceRegistry registration, and the WM focus-lifecycle call sites this depends on.
48 lines
2.5 KiB
Markdown
48 lines
2.5 KiB
Markdown
# ax_sandbox
|
|
|
|
App-lock, app-hide, sandbox isolation, and settings-spoof for PawletOS.
|
|
Design and source copied from AxionAOSP's `android_axion_sdk` (`ax_sandbox`
|
|
module) and their `frameworks/base` fork's integration points
|
|
(`AxionAOSP/android_frameworks_base`, branch `lineage-23.2`) — explicit,
|
|
informed decision (2026-09-29) to reuse the actual source, not just the
|
|
design, made with full knowledge of the licensing gap below.
|
|
|
|
## License status (per-file, verified 2026-09-29)
|
|
|
|
Only `common/src/android/app/AxSandboxManager.java` carries a real
|
|
Apache-2.0 grant (a full license header, not just a copyright line). Every
|
|
other file in this repo — the other 3 manager classes in `common/`, and
|
|
everything in `server/` — has neither a repo-level LICENSE nor a per-file
|
|
header, in the source repos this was copied from. There is no LICENSE file
|
|
in this repo either, for the same reason. This is a known, accepted risk,
|
|
not an oversight — see `notes/axion-port-plan.md` in the main PawletOS
|
|
workspace for the full decision record.
|
|
|
|
## Structure
|
|
|
|
- `common/` — public `android.app.*` manager classes (`AxSandboxManager` +
|
|
3 thinner wrapper classes that expose subsets of the same surface).
|
|
Compiled directly into `frameworks/base`'s `core/java` sources via a
|
|
filegroup reference (see the small framework patch in `patches/`), not
|
|
packaged as a normal app-facing library — these classes live in the
|
|
platform's own `android.app` namespace.
|
|
- `server/` — the actual `system_server` implementation:
|
|
`AxSandboxService` (a `SystemService`, constructed in `SystemServer.java`
|
|
alongside `ActivityTaskManagerService`) plus `AppLockService` and the
|
|
`apphide`/`isolation`/`spoof` sub-packages, all under
|
|
`com.android.server.wm`. Compiled into `services.jar` via a filegroup
|
|
reference the same way.
|
|
|
|
Neither directory builds anything on its own — both are consumed as
|
|
Soong `filegroup`s from a small patch against `frameworks/base`
|
|
(`IActivityManager.aidl` extension, `ActivityManagerService.java`
|
|
delegates, `SystemServer.java`/`Context.java`/`SystemServiceRegistry.java`
|
|
wiring, and the WM focus-lifecycle call sites in `TaskFragment`/
|
|
`ActivityRecord`/`ActivityTaskSupervisor`/`DisplayContent`/
|
|
`KeyguardController`/`Task`/`RecentTasks`). See that patch for exactly
|
|
where these sources get pulled in.
|
|
|
|
Not yet included: the `shared/` credential-verification + Compose UI layer
|
|
(Axion's own PIN/pattern/password screens) and the app-level consumers
|
|
(`AxSandbox`, `AppLocker`) — tracked separately.
|