From f1faf19f402af4f97c3de9d8e7e3c294767ac0bf Mon Sep 17 00:00:00 2001
From: Daniel Micay
Yes, the baseband is isolated on all of the officially supported devices. Memory + access is partitioned by the IOMMU and limited to internal memory and memory shared + by the driver implementations. The baseband on the officially supported devices with a + Qualcomm SoC implements Wi-Fi and Bluetooth as internal sandboxed processes rather + than having a separate baseband for those like earlier devices.
+ +Earlier generation devices we used to support prior to Pixels had Wi-Fi + Bluetooth + implemented on a separate SoC. This was not was not properly contained by the stock OS + and we put substantial work into addressing that problem. However, that work has been + obsoleted now that Wi-Fi and Bluetooth are provided by the SoC on the officially + supported devices.
+ +A component being on a separate chip is orthogonal to whether it's isolated. In + order to be isolated, the drivers need to treat it as untrusted. If it has DMA access + that needs to be contained via IOMMU and the driver needs to treat the shared memory + as untrusted, as it would data received another way. There's a lot of attack surface + between the baseband and the kernel/userspace software stack connected to it. OS + security is very relevant to containing hardware components including the radios and + the vast majority of the attack surface is in software. The OS relies upon the + hardware and firmware to be able to contain components but ends up being primarily + responsible for it due to control over the configuration of shared memory and the + complexity of the interface and the OS side implementation.
+