Microdroid  |  Android Open Source Project Skip to main content Docs What's new? Release notes Latest security bulletins Latest Compatibility Definition Document (CDD) Site updates Getting Started About Start Download Builds Test Create Contribute Community Tools, build, and related reference Security Overview Bulletins Features Testing Best Practices Core Topics Architecture Audio Camera Connectivity Data Display Fonts Graphics Interaction Media Performance Permissions Power Runtime Settings Storage Tests Updates Virtualization Compatibility Compatibility Definition Document (CDD) Compatibility Test Suite (CTS) Android Devices Cuttlefish Enterprise TV Automotive Overview Software Defined Vehicle In-vehicle Infotainment Release Details Reference HIDL HAL Trade Federation Security Test Suite Android Code Search / English Deutsch Español – América Latina Français Indonesia Italiano Polski Português – Brasil Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어 Sign in Documentation What's New? Getting Started Security Core Topics Compatibility Android Devices Automotive Reference Docs More What's New? Getting Started Security Core Topics Compatibility Android Devices Automotive Reference Android Code Search Overview Architecture Overview Hardware abstraction layer (HAL) Overview HIDL (deprecated) Overview Interfaces and packages Interface hashing Services and data transfer Fast Message Queue Use Binder IPC HIDL MemoryBlock Network stack configuration tools Model threading Convert HAL modules Data types Safe union Interface versioning Code style guide HIDL C++ Overview Packages Interfaces Data types Functions HIDL Java Overview Data types Interface methods and errors Export constants Other HIDL framework backward compatibility verification Dynamically available HALs Legacy HALs (AOSP <=v7) Kernel Overview Kernel release notes Stable kernel releases and updates Android common kernels GKI project GKI development GKI versioning scheme GKI release builds Overview android12-5.10 release builds android13-5.10 release builds android13-5.15 release builds android14-5.15 release builds android14-6.1 release builds android15-6.6 release builds android16-6.12 release builds android17-6.18 release builds Deprecated builds android12-5.10 deprecated builds android13-5.10 deprecated builds android13-5.15 deprecated builds android14-5.15 deprecated builds android14-6.1 deprecated builds android15-6.6 deprecated builds android16-6.12 deprecated builds android17-6.18 deprecated builds GKI release builds (JSON) android12-5.10 release builds android13-5.10 release builds android13-5.15 release builds android14-5.15 release builds android14-6.1 release builds android15-6.6 release builds android16-6.12 release builds android17-6.18 release builds GKI release process Request a respin GKI 16-6.12 android-mainline errata Maintain a stable KMI Kernel ABI monitoring Overview Run ABI monitoring Work with symbol lists Modules Overview Configure kernel features as GKI modules Vendor module guidelines Loadable kernel modules Kernel module support Test GKI modules Boot time optimization Debug features Develop kernel code for GKI Android kernel file system support Extend the kernel with eBPF Use DebugFS in Android 12 FIPS 140-3 certifiable GKI crypto module EROFS Android kernel FAQ Kernel networking unit tests Transition from ION to DMA-BUF heaps (5.4 kernel) Incremental File System Configuration Overview Implement system properties as APIs Add system properties Implement Config File Schema API Archive Overview ConfigStore Create the HAL interface Implement the service Client-side use Add ConfigStore classes and items Device tree overlays Overview Implement DTOs DTO syntax Compile and verify Use multiple DTs DTB and DTBO partitions Optimize DTO Vendor NDK (<=AOSP 14) Overview Enable VNDK VNDK build system support VNDK extensions VNDK snapshot design Generate VNDK snapshots Generate vendor snapshots Linker namespace Directories, rules, and sepolicy RenderScript ABI stability Prebuilt ABI usages checker Vendor interface object Overview Manifests Compatibility matrixes FCM lifecycle Device manifest development Match rules Additional resources AIDL Overview AIDL language AIDL backends Stable AIDL AIDL for HALs Run AIDL services dynamically Annotations in AIDL FMQ with AIDL AIDL fuzzing AIDL style guide Binder (Interprocess Communication) Overview Handle threads Priority inheritance Handle cached and frozen apps Bootloader Overview Canonical boot reason Boot image header Implement bootconfig Recovery images DTB images Implement OTA updates Lock and unlock the bootloader Version information in AVB properties Move fastboot to userspace Generic Bootloader Overview Deploy GBL Partitions Overview Partition layout Vendor boot partitions Vendor and ODM DLKM partitions Shared system image Ramdisk partitions Generic boot partition ODM partitions Product partitions Implement a GKI module partition Enforce product partition interfaces Trusty OS partitions 16 KB page size Overview Use Cuttlefish with 16 KB page size on ARM64 Simulate Cuttlefish with 16 KB page size on x86-64 Flash Pixel with 16 KB page size support Get the page size Optimize for 16 KB page size System properties Enable 16 KB toggle Enable 16 KB backcompat option Vendor API level Audio Overview Terminology Implementation Audio HAL AIDL Audio HAL Configurable Audio Policy support in AIDL HAL AIDL and HIDL Audio HAL comparison HIDL HIDL Audio HAL Configure audio policies Configure a shared library Configure preprocessing effects Data formats Attributes Effects High-resolution audio Device type limit AAudio and MMAP Audio warmup Latency Overview Contributors Design for reduced latency Measure audio latency Audio loopback dongle Audio latency measurements Audio latency for app developers Avoid priority inversion Sample rate conversion Audio debugging MIDI Overview MIDI architecture MIDI test procedure USB USB digital audio Preferred mixer attributes on USB devices TV audio Concurrent capture Sound Trigger Combined audio device routing Spatial audio Spatial audio and head tracking Implementation Head tracking over LE audio Sound dose Dynamic soundbar mode Audio Managed SCO rearchitecture Camera Overview Architecture Camera HAL HAL subsystem Core concepts 3A modes and state transition Camera debugging Error and stream handling Metadata and controls Output streams, cropping, and zoom Request creation and submission Stream configurations Performance Camera HAL3 buffer management APIs Session parameters Single producer, multiple consumer Camera features 10-bit camera output Camera bokeh Concurrent camera streaming Camera extensions Camera extensions validation tool Camera preview stabilization External USB cameras High dynamic range modes HEIF imaging Monochrome cameras Motion tracking Multi-camera support System cameras Torch strength control Ultra HDR Use a device as a webcam Wide gamut capture Versioning Camera version support Connectivity Overview Bluetooth Overview Bluetooth services Bluetooth Low Energy Hearing aid audio support using BLE BLE advertising Verify and debug HCI requirements Presence calibration Android OS identification NFC Host card emulation of FeliCa NFC off-host payment synchronization Secure NFC Quick Access Wallet Android proprietary NCI commands Calling and messaging 5G non-standalone (NSA) Implement phone number blocking Call notifications Domain selection service Implement Emergency Affordance Android emergency number database Emergency numbers and emergency calling Implement IMS IMS service entitlement IMS single registration Phone account suggestion Implement RTT Support third-party calling apps Visual voicemail Carrier Overview 5G network slicing APN and CarrierConfig Carrier identification Implement data plans Device identifiers eSIM Implement eSIM Modem requirements for eSIM support eUICC APIs Multiple enabled profiles Handle eUICC API errors Downloadable test profiles eSIM transfer carrier integration Improve VPN user experience Multi-operator network support Customize device behavior for out-of-balance users RIL refactoring Satellite connectivity Small cell support UICC carrier privileges Time Overview Location time zone detection Telephony time zone detection Network time detection GNSS time detection External time detection Time source priority Time zone policy and recommendations Time zone rules Ultra-wideband Overview UWB HAL interface Wi-Fi Overview Wi-Fi HAL Wi-Fi infrastructure features Test, debug, and tune Wi-Fi Android Packet Filter Carrier Wi-Fi MAC randomization behavior Implement Android Custom Tabs for captive portal Implement MAC randomization Passpoint (Hotspot 2.0) Wi-Fi STA/AP concurrency Wi-Fi STA/STA concurrency Trust on First Use (TOFU) Wi-Fi Aware Wi-Fi and cellular coex channel avoidance Wi-Fi Direct Wi-Fi Easy Connect Wi-Fi hotspot (Soft AP) Wi-Fi AP/AP concurrency Wi-Fi low-latency mode Wi-Fi network selection Wi-Fi preferred network offload scanning Wi-Fi Round Trip Time (RTT) WPA3 and Wi-Fi Enhanced Open Wi-Fi 7 Companion device profiles Connectivity Diagnostics API Connectivity user interface Network selection Ranging: Out-of-band message sequence and payload specification OOB version 3 OOB version 2 OOB version 1 Signal strength reporting Data Overview Data usage tags explained Data Saver mode eBPF traffic monitoring Exclude network types from usage data Network interface statistics overview Tethering data Tethering hardware offload Usage cycle reset dates Kernel overview Kernel changes Display Overview Apps Implement adaptive icons App shortcuts Implement circular icons Conversation notifications and widgets Window blurs Widgets and shortcuts Implement synchronized app transitions Color Color management Display cutouts Do not disturb HDR video playback Implement night light Tone mapping HDR luminance to an SDR-compatible range Material You design Dynamic color Foldables Tent and wedge postures Fold lock behavior setting Multi-Window Overview Desktop windowing features Split-screen interactions Picture-in-picture Window magnification Multi-Display Overview Recommended practices Testing and development environment Frequently asked questions Multi-resume Activity launch policy Display support System decorations support Lock screen Input method editor support Input routing Multi-zone audio Notifications Notification history Permission for opt-In notifications Task Manager Retail demo mode Rotate suggestions Implement text classifier Import and export home screen data Mixed SDR and HDR composition Media controls in System UI WindowManager Extensions module Device-state based auto-rotate setting Quick Settings tiles categorization Large screen app compatibility Overview Setup guide Fonts Implement custom font fallback Graphics Overview Architecture BufferQueue and Gralloc Trace window transitions using Winscope Overview Run Winscope Capture traces Overview ViewCapture in system apps On device Use Winscope Use adb commands Load traces Analyze traces Overview Timeline navigation Trace search SurfaceFlinger WindowManager ProtoLog Shell transitions ViewCapture Surface and SurfaceHolder Overview SurfaceView and GLSurfaceView SurfaceTexture TextureView SurfaceFlinger and WindowManager Overview System properties in SurfaceFlinger Hardware Composer HAL Overview Implement HWC HAL Hotplug handling AIDL for HWC HAL Client framebuffer management Reduce graphics memory consumption Productionized DPU readback Layers and displays VSync Frame pacing Multiple refresh rate Adaptive refresh rate EGLSurfaces and OpenGL ES Overview Implement OpenGL ES and EGL OpenGLRenderer configuration Vulkan Overview Implement Vulkan Synchronization framework Testing Implementation testing Integrate with Android CTS drawElements Quality Program testing Unsignaled buffer latching with AutoSingleLayer Add new pixel formats to Android HDR in Android screenshots Interaction Overview Input Overview Key layout files Key character map files Input device configuration files Migration guide Keyboard devices Touch devices getevent tool validatekeymaps tool Haptics Overview Implement haptics Overview Implement constants and primitives Map constants between HAL and API Implement piecewise linear envelope effects Assess the hardware UX foundation for haptic framework Haptics UX design Hardware assessment Overview Set up the testing equipment Set up the test software Measure and record target effects Analyze the waveform Compare results using the performance map Neural Networks Overview Burst executions and fast message queues Compilation caching Control flow Device discovery and assignment Memory pools NNAPI driver implementation best practices Quality of service Vendor extensions Peripherals Overview Audio accessories Overview 3.5 mm headset Headset spec Headset jack device spec USB headset Headset spec Adapter spec Device spec Headset expected behavior Headset testing Custom accessories Overview Android Open Accessory Overview AOA 2.0 AOA 1.0 Disable data signaling over USB Stylus Sensors Overview Sensor stack Sensor types Interaction Head tracker HID protocol Power Batching Power consumption Modes Reporting modes Suspend mode Sensors off Sensors HAL Sensors AIDL HAL Sensors Multi-HAL Sensors HAL 2.0 Sensors HAL 1.0 HAL version deprecation Context Hub Runtime Environment Overview Media Overview Media modules MediaProvider module Customize media components Low-latency decoding in MediaCodec Media framework hardening SoC vendor dependencies OEM dependencies DRM Compatible media transcoding Export video encoding statistics OEM guidance for RoI implementation VVC support Performance Overview APK caching Cached apps freezer Optimize boot times Health Overview Implement Health 2.1 Cgroup abstraction layer Low memory killer daemon Automatic Feedback-Directed Optimization (12 or higher) Use profile-guided optimization Task snapshots Compatibility write-ahead logging App hibernation Performance Hint API Performance boost for games MM events historical memory statistics Obtain system health information Memory Limiter Process memory guardian daemon Memory management daemon NPU manager Permissions Overview Ambient capabilities Background location access reminder Contacts provider and affinities Contact Picker Discretionary access control Immutable device IDs Namespaces for native libraries Privileged permission allowlist Preinstalled system packages Platform-signed shared UID allowlist Privacy indicators Restrict opportunistic locations Restricted screen reading Android roles Runtime permissions Signature permission allowlist Tristate location permissions Implement USB HAL Companion app streaming Full-screen intent limits Capture Content for Notes Power Overview Power management Thermal mitigation Power stats HAL App power management Platform power management with Doze Performance management App background behavior trackers Support batteryless devices Measure component power Measure device power Measure power values Routine Battery Saver TV standby SystemSuspend service Wattson Power analysis overview Collect and analyze traces Runtime Overview Dexpreopt and <uses-library> checks Android 8.0 ART improvements Dalvik bytecode format Dalvik executable format Dalvik executable instruction formats Constraints Configuration Overview ART Service configuration Package manager configuration (deprecated) ART TI Implement Signed Config Debug ART garbage collection Implement ART JIT compiler Change the value of an app's resources at runtime Troubleshoot RROs Boot image profiles Soft restarts (<= AOSP 14) About the Zygote Settings Overview Design guidelines Patterns and components Information architecture Personalized settings Universal search Storage Overview Traditional storage Adoptable storage Scoped storage FUSE passthrough Device configuration Configuration examples Faster statistics SDCardFS deprecation Tests Overview Test development workflow Overview Simple build configuration Complex test configuration Instrumentation tests Overview Self-instrumenting tests example Target an app example GoogleTests (GTests) Overview Add new GTests Metric tests JAR host tests Test mapping Run tests with Atest OmniLab Android Test Station User guide OmniLab ATS 2.0 upgrade guide Virtual devices in OmniLab ATS Cloud Orchestration in OmniLab ATS Autoenable USB debugging on user builds Run UIConductor tests API Release notes FAQ Vendor Test Suite (VTS) Overview Parameterized GTest for HAL testing Test setup Generic system image (GSI) Vendor Test Suite (VTS) 10 Overview Video tutorials Systems testing with VTS Test framework Device shell commands Test templates Service name aware HAL testing HAL testability check Multi-device testing VTS with debug ramdisk VTS Dashboard Setup Database User interface Lab infrastructure Automated testing infrastructure Host controller architecture Performance testing Trade Federation (TF) test harness Get started Overview Start Development environment Work with devices Console Test lifecycle Option handling End-to-end example Write and run Tradefed tests Overview Test through Tradefed Overview Write a test runner Write a sharded IRemoteTest test runner Write a host-driven test Write a host-side deviceless test Report metrics or data from a test Automatic test retry Retry isolation Automated log on failure collection Dry run a configuration Run instrumentation tests from APKs Write a shell test Global filters Test through suites Overview Set up suites Pass options and filters Check system status AndroidTest.xml structure Configure sharding Employ module controllers Use suite retry Multi-device modules Develop TF Overview Test harness guidelines Set up Eclipse Include unit and functional tests Run Error Prone bug checker Contribute non-core code Architecture Overview XML configuration High-level structure Templates and includes Configuration object Global Configuration File options Host options Advanced concepts Keystore secrets Test Command Scheduler Structure of a test runner Test sharding Run tests with multiple devices Use Scripting Layer Load protocols with global config Native device Device Manager Device states Device allocation Device detection Build Build providers BuildInfo Device setup Target preparers Multi-target preparers Results Create a result reporter Handle log files Result reporter summary Log saver Metrics Host-driven metrics collector Device-side metric collection Package index Multidevice testing with Mobly Overview Debug native platform code Overview Read bug reports Understand logging Implement scoped vendor logging Diagnose native crashes Evaluate performance Overview Understand systrace Use ftrace Identify capacity-related jank Identify jitter-related jank Feature implementation Implement Test Harness Mode Use debuggers Debug native memory use Rescue Party Implement storaged Use strace Updates Overview APEX APEX file format Vendor APEX Build OTA packages Sign builds for release Reduce OTA size Virtual A/B Overview Implement Virtual A/B Implement Virtual A/B - patches Legacy A/B system updates Overview Implement A/B updates Frequently asked questions (Deprecated) Non-A/B system updates Overview Block-based OTA Inside OTA packages Device-specific code Dynamic partitions Overview Implement dynamic partitions OTA for A/B devices OTA for legacy A/B devices OTA for non-A/B devices Size the super partition Time zone rules User Data Checkpoint Dynamic System Updates Resume-on-Reboot Upgrade Party for OS updates Upgrade Invite for pending OS updates Mainline Overview AdServices adbd Android Health AppSearch ART Bluetooth CellBroadcast Config Infrastructure Conscrypt Crash Recovery Device Scheduling DNS Resolver DocumentsUI ExtServices IPsec/IKEv2 Library Media MediaProvider ModuleMetadata Network Stack NFC Services NNAPI Runtime OnDevicePersonalization PermissionController Profiling Remote Key Provisioning SDK Extensions Statsd Tethering Time Zone Data UprobeStats UWB Wi-Fi Virtualization Overview Why AVF Try AVF Write an AVF app AVF Architecture Microdroid VirtualizationService Security Implement a pKVM vendor module Use cases What's new? Release notes Latest security bulletins Latest Compatibility Definition Document (CDD) Site updates Getting Started About Start Download Builds Test Create Contribute Community Tools, build, and related reference Security Overview Bulletins Features Testing Best Practices Core Topics Architecture Audio Camera Connectivity Data Display Fonts Graphics Interaction Media Performance Permissions Power Runtime Settings Storage Tests Updates Virtualization Compatibility Compatibility Definition Document (CDD) Compatibility Test Suite (CTS) Android Devices Cuttlefish Enterprise TV Automotive Overview Software Defined Vehicle In-vehicle Infotainment Release Details Reference HIDL HAL Trade Federation Security Test Suite Effective in 2026, to align with our trunk stable development model and ensure platform stability for the ecosystem, we will publish source code to AOSP in Q2 and Q4. For building and contributing to AOSP, use android-latest-release. The android-latest-release manifest branch will always reference the most recent release pushed to AOSP. For more information, see Changes to AOSP. AOSP Docs Core Topics Microdroid Stay organized with collections Save and categorize content based on your preferences. Microdroid is a mini-Android OS that runs in a pVM. You don't have to use Microdroid, you can start a VM with any OS. However, the primary use cases for pVMs aren't running a standalone OS but rather offering an isolated execution environment for running a portion of an app with stronger confidentiality and integrity guarantees than Android can provide. With traditional operating systems, providing strong confidentiality and integrity requires a fair amount of work (often duplicated) because traditional operating systems don't fit with the overarching Android architecture. For example, with the standard Android architecture, developers need to implement a means of securely loading and executing part of their app in the pVM, and the payload is built against glibc. The Android app uses Bionic, communication requires a custom protocol over vsock, and debugging using adb is challenging. Microdroid fills these gaps by providing an off-the-shelf OS image designed to require the least amount of effort from developers to offload a portion of their app into a pVM. Native code is built against Bionic, communication happens over Binder, and it allows importing APEXes from the host Android and exposes a subset of the Android API, such as keystore for cryptographic operations with hardware-backed keys. Overall, developers should find Microdroid a familiar environment with the tools they’ve grown accustomed in the full Android OS. Features Microdroid is a stripped down version of Android with a few additional components specific to pVMs. Microdroid supports: A subset of NDK APIs (all APIs for Android's implementation of libc and Bionic are provided) Debugging features, such as adb, logcat, tombstone, and gdb Verified Boot and SELinux Loading and executing a binary, together with shared libraries, embedded in an APK Binder RPC over vsock and exchange of files with implicit integrity checks Loading of APEXes Microdroid doesn't support: Android Java APIs in the android.\* packages Note: Core Java APIs in the java.\* packages can be supported by activating the ART APEX in the VM. SystemServer and Zygote Graphics/UI HALs Microdroid architecture Microdroid is similar to Cuttlefish in that both have an architecture that's similar to standard Android. Microdroid consists of the following partition images grouped together in a composite disk image: bootloader - Verifies and starts the kernel. boot.img - Contains the kernel and init ramdisk. vendor_boot.img - Contains VM-specific kernel modules, such as virtio. super.img - Consists of system and vendor logical partitions. vbmeta.img - Contains verified boot metadata. The partition images ship in the Virtualization APEX and are packaged in a composite disk image by VirtualizationService. In addition to the main OS composite disk image, VirtualizationService is responsible for creating these other partitions: payload - A set of partitions backed by Android’s APEXes and APKs instance - An encrypted partition for persisting per-instance verified boot data, such as per-instance salt, trusted APEX public keys, and rollback counters Boot sequence The Microdroid boot sequence occurs after Device boot. Device boot is discussed in the pVM Firmware section of the Architecture document. Figure 1 shows the steps that take place during the Microdroid boot sequence: Figure 1. Secure bootflow of microdroid instance Here's an explanation of the steps: The bootloader is loaded into memory by crosvm and pvmfw starts executing. Before jumping to the bootloader, pvmfw performs two tasks: Verifies the bootloader to check if it is from a trusted source (Google or an OEM). Ensures that the same bootloader is used consistently across multiple boots of the same pVM through the use of the instance image. Specifically, the pVM is initially booted with an empty instance image. pvmfw stores the identity of the bootloader in the instance image and encrypts it. So, the next time the pVM is booted with the same instance image, pvmfw decrypts the saved identity from the instance image and verifies that it's the same that was previously saved. If the identities differ, pvmfw refuses to boot. The bootloader then boots Microdroid. The bootloader accesses the instance disk. Similar to pvmfw, the bootloader has an instance disk drive with information about partition images used in this instance during previous boots, including the public key. The bootloader verifies vbmeta and the chained partitions, such as boot and super, and, if successful, derives the next-stage pVM secrets. Then, Microdroid hands control over to the kernel. Because the super partition has already been verified by the bootloader (step 3), the kernel unconditionally mounts the super partition. As with the full Android, the super partition consists of multiple logical partitions mounted over dm-verity. Control is then passed to the init process, which starts various native services. The init.rc script is similar to that of full Android but tailored to the needs of Microdroid. The init process starts the Microdroid manager, which accesses the instance image. The Microdroid manager service decrypts the image using the key passed from the previous stage and reads the public keys and rollback counters of the client APK and APEXes that this pVM trusts. This information is used later by zipfuse and apexd when they mount the client APK and requested APEXes, respectively. The Microdroid manager service starts apexd. apexd mounts the APEXes at /apex/<name> directories. The only difference between how Android and Microdroid mount APEXes is that in Microdroid, the APEX files are coming from virtual block devices (/dev/vdc1, …), not from regular files (/system/apex/*.apex). zipfuse is Microdroid’s FUSE file system. zipfuse mounts the client APK, which is essentially a Zip file as a file system. Underneath, the APK file is passed as a virtual block device by the pVM with dm-verity, same as APEX. The APK contains a config file with a list of APEXes that the app developer has requested for this pVM instance. The list is used by apexd when activating APEXes. The boot flow returns to the Microdroid manager service. The manager service then communicates with Android’s VirtualizationService using Binder RPC so that it can report important events like crash or shutdown, and accept requests such as terminating the pVM. The manager service reads the location of the main binary from the APK’s config file and executes it. File exchange (AuthFS) It's common for Android components to use files for input, output, and state and to pass these around as file descriptors (ParcelFileDescriptor type in AIDL) with access controlled by the Android kernel. AuthFS facilitates similar functionality for exchanging files between mutually distrusting endpoints across pVM boundaries. Fundamentally, AuthFS is a remote file system with transparent integrity checks on individual access operations, similar to fs-verity. The checks allow the frontend, such as a file-reading program running in a pVM, to detect if the untrusted backend, typically Android, tampered with file content. To exchange files, the backend (fd\_server) is started with per-file configuration specifying whether it's meant for input (read-only) or output (read-write). For input, the frontend enforces that the contents match a known hash, on top of a Merkle tree for on-access verification. For output, AuthFS internally maintains a hash tree of the contents as observed from write operations and can enforce integrity when the data are read back. The underlying transport is currently based on Binder RPC, however that might change in the future to optimize performance. Key management pVMs are provided with a stable sealing key that's suitable for protecting persistent data, and an attestation key that's suitable for producing signatures that are verifiably produced by the pVM. Binder RPC A majority of Android’s interfaces are expressed in AIDL, which is built on top of the Binder Linux kernel driver. To support interfaces between pVMs, the Binder protocol has been rewritten to work over sockets, vsock in the case of pVMs. Operating over sockets allows Android’s existing AIDL interfaces to be used in this new environment. To set up the connection, one endpoint, such as pVM payload, creates an RpcServer object, registers a root object, and begins listening for new connections. Clients can connect to this server using an RpcSession object, get the Binder object, and use it exactly like a Binder object is used with the kernel Binder driver. Content and code samples on this page are subject to the licenses described in the Content License. Java and OpenJDK are trademarks or registered trademarks of Oracle and/or its affiliates. Last updated 2026-06-17 UTC. [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-06-17 UTC."],[],[]] Build Android repository Requirements Downloading Preview binaries Factory images Driver binaries Connect @Android on X @AndroidDev on X Android Blog Google Security Blog Platform on Google Groups Building on Google Groups Porting on Google Groups Get help Android Help Center Pixel Help Center www.android.com Google Mobile Services Stack Overflow Issue Tracker About Android Community Legal License Privacy Site feedback Manage cookies English Deutsch Español – América Latina Français Indonesia Italiano Polski Português – Brasil Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어