跳到正文
原文
Google AI:DEV 作者专属(RSS)· Samuel Mensah·· 3 小时前AI 评分51

Google 开发者验证政策将波及 F-Droid,开发者呼吁协调应对

Is open source dead?.

AI 导读

一位刚上架 F-Droid 的开发者警告,Google 开发者验证已于 2026 年 9 月 30 日起在巴西、印尼、新加坡和泰国执行,2027 年将扩展到包括 F-Droid 和直接 APK 在内的所有安装渠道,要求 $25 Play Console 账户加政府照片证件,组织还需约 28 天办理 D-U-N-S 号。

正文

Google's 2027 verification mandate will break F-Droid. Let's coordinate a technical response.

I recently got my app accepted on F-Droid. A week later, I got a cold email warning me about Google's developer verification rollout:

Enforcement began September 30, 2026 in Brazil, Indonesia, Singapore, and Thailand. It expands globally in 2027 to all install sources, including F-Droid and direct APKs. It requires a $25 Play Console account plus a government photo ID. Organizations also need a D-U-N-S number, which takes about 28 days.

F-Droid, EFF, FSFE, the Software Freedom Conservancy, and others have formed the Keep Android Open coalition and are formally opposing this. But opposition alone won't keep apps installable.

The Real Problem

The open-source mobile ecosystem is fragmented into pieces that don't cohere.

On the OS layer, we have /e/OS, iodéOS, GrapheneOS, CalyxOS, and LineageOS. The gap is that there's no unified onboarding and each ROM is its own island.

On attestation, we have UnifiedAttestation from Volla, Murena, iodé, and Apostrophy. The gap is that it's early stage and banks and digital IDs still don't work reliably.

On Google API compatibility, we have microG and ReVanced. The gap is that Play Integrity checks still break many apps.

On app distribution, we have F-Droid, App Lounge, and Aurora Store. The gap is that users don't know where to go and discovery is poor.

On cloud and services, we have Murena Workspace and Volla Cloud. The gap is that there's no seamless migration path from Google.

On AI, we have Odysseus by PewDiePie and Mozilla Thunderbolt. The gap is that local-first AI is new and there's no OS-level integration.

The combined market share of all de-Googled phones is less than one per thousand.

That's not a technology problem. That's an integration and UX problem.

What I'm Proposing

A coordinated compatibility and integration effort driven by app developers, people like us who ship on F-Droid and want our apps to work everywhere.

Concrete asks:

First, a compatibility testing matrix. A shared spreadsheet or repo where developers log things like "My app works on /e/OS but breaks on GrapheneOS because of X." Aggregate this so ROM maintainers and microG devs can prioritize fixes.

Second, UnifiedAttestation early adopters. The consortium is actively looking for first movers. If your app needs attestation for banking, auth, or secure login, integrate it now and report back. This is the single biggest blocker for mainstream adoption.

Third, a microG bug bounty pool. Pool small contributions to fund fixes for the most common Play Services breakages. Even $500 targeted at one bug can unblock thousands of users.

Fourth, an F-Droid onboarding guide. A single, canonical, up-to-date guide for normal users on how to leave Google without losing your apps. Written for non-technical people. Hosted somewhere permanent.

Fifth, a regulatory pressure tracker. Track EU DMA enforcement, US antitrust remedies, and any other government action. Make it easy for developers to file comments or contact regulators.

What I'm NOT Proposing

Another ROM. Another app store. Another foundation. A "Google killer."

We don't need more pieces. We need the existing pieces to talk to each other.

The Uncomfortable Question

Do we build bridges by integrating with UnifiedAttestation and working within the system to make de-Googled phones viable, or do we fight the system by refusing attestation entirely, accepting that banking apps won't work, and targeting only the privacy-hardcore niche?

GrapheneOS argues the Play Integrity API should be regulated out of existence rather than making another system where companies permit their own products while disallowing others.

Both positions are defensible. But they lead to different products, different users, and different strategies. We need to pick one, or explicitly support both tracks.

What I Want From This Thread

If you're an F-Droid developer, what breaks when you test on de-Googled ROMs? What fixes have you found?

If you're a ROM maintainer, what do you need from app developers?

If you're a microG contributor, what's the highest-impact bug right now?

If you're a user, what's the one thing that made you go back to stock Android?

If you're none of the above but care, what's missing from this list?

I'll compile responses into a public document and post it back here. If there's enough interest, I'll set up a repo and a Matrix or Discord space to coordinate.

Let's stop waiting for someone else to fix this.

来源:Google AI:DEV 作者专属(RSS) · dev.to