GrapheneOS says Google violates GPLv2 with Google Drive source delivery
GrapheneOS, an open source, privacy and security focused mobile operating system with Android app compatibility, says Google has changed how it hands over the source code for certain repositories the project depends on. Instead of pushing Git tags directly, as GrapheneOS says Google previously did, requesters must now file a Google Forms request and then download a tarball of the same source through Google Drive. GrapheneOS laid out the complaint in an eight-post Mastodon thread from its official account on August 8, 2026, calling the new process 'completely ridiculous' and arguing it puts Google 'in clear violation of the GPLv2.'
According to GrapheneOS, Google initially granted access to the tarballs within a couple of hours of a request. Lately, the group says, Google is often taking weeks to respond. GrapheneOS also says it needs to request access to additional files multiple times a month, which it attributes partly to Google granting access to individual files rather than whole folders. Before moving to the Google Drive process, GrapheneOS says Google had already started squashing the Git history into a single commit before pushing release tags. The source code inside the Google Drive tarballs, GrapheneOS says, is exactly the same as what was previously pushed as tags, but Google, in its words, 'went out of the way to make it more inconvenient in several ways.'
GrapheneOS says the change 'only negatively impacts Pixels' and, in its words, 'hurts Google more than anyone else.' It says the shift will not negatively affect GrapheneOS builds for its upcoming Motorola Mobility devices, and that this is a major part of why its partnership with Motorola Mobility exists in the first place. For those Motorola devices, GrapheneOS says it plans to prepare releases early so builds are ready at launch, and that it will host the relevant AOSP Git repositories itself rather than rely on Google's process.
GrapheneOS argues Google could avoid the dispute by simply pushing signed tags to Git instead of routing requests through forms and file-by-file access, or, short of that, by automating access and granting it by folder rather than by file. The group says access should not depend on a person working through what it calls a low-priority backlog, and that requests going unhandled for weeks is unacceptable; as it puts it, Google is 'obligated to fulfill' its requests. GrapheneOS says it specifically needs each Beta tag because it ports and tests in advance of release, and that Google 'chose to waste the time of several employees' by handling the process this way instead of pushing the tags directly.
Key facts
- GrapheneOS says Google replaced pushing Git tags for certain source code with a process that requires a Google Forms request and then a Google Drive download of a tarball.
- GrapheneOS says Google used to grant tarball access within a couple of hours of a request, but now often takes weeks to respond.
- GrapheneOS says it needs to request access to additional files multiple times a month because Google grants access file by file rather than by folder.
- GrapheneOS says the change 'only negatively impacts Pixels' and will not affect its upcoming Motorola Mobility devices, which it says is a major reason the Motorola partnership exists.
- GrapheneOS says it plans to host the AOSP Git repositories itself and prepare Motorola releases early so builds are ready at launch.
Why it matters
GrapheneOS frames this as more than a process change: it says Google replaced automatic Git tag pushes for certain source code with a Google Forms and Google Drive request process, and that doing so alone puts Google 'in clear violation of the GPLv2.' The complaint is less about whether the code is available at all (GrapheneOS says the Google Drive tarballs contain 'exactly the same source code' as the old tags) and more about how long access now takes, which matters directly to any project whose release schedule depends on getting source promptly after Google tags it.
Who it affects
GrapheneOS itself is the party directly affected: it says it needs each Beta tag specifically because it ports and tests in advance of release, so delays of weeks instead of hours hit its own release timeline. Scope-wise, GrapheneOS says the change 'only negatively impacts Pixels' and will not affect its upcoming builds for Motorola Mobility devices; it says that is a major part of why its partnership with Motorola Mobility exists in the first place. For those Motorola devices, GrapheneOS says it plans to prepare releases early and host the relevant AOSP Git repositories itself.
How to use it
For anyone who still needs source through Google's new process, the mechanics as GrapheneOS describes them are: submit a Google Forms request, then wait for Google to grant access to a tarball through Google Drive, which GrapheneOS says can now take weeks rather than the couple of hours it used to take, and which it says it must repeat multiple times a month because Google grants access file by file rather than by folder. GrapheneOS's own proposed fix is for Google to push signed tags to Git instead, or, short of that, to automate the Google Drive access and grant it by folder. Its practical fallback, at least for Motorola Mobility devices, is to stop depending on Google's process altogether: prepare releases early and host the AOSP Git repositories itself.
How solid is it
The account comes directly from GrapheneOS's own official Mastodon account, in an eight-post thread from August 8, 2026, not from a leak or an anonymous source. Its specific figures are stated plainly and consistently across the thread: a couple of hours for access before, weeks now, and extra file requests multiple times a month. What is missing is Google's side. This text includes no response, comment or confirmation from Google, and the framing of the change as a GPLv2 violation, along with GrapheneOS's reading of Google's motives, is the group's own legal and strategic assessment rather than a ruling or an admission.
Risks and caveats
Everything here is one side's account. The thread does not name a specific repository, filename or Pixel model, so the exact scope of what changed cannot be pinned down from this text, and it gives no count of how many files, requests or releases have actually been affected. No individual at Google is named as responsible, and the thread does not say whether GrapheneOS has taken, or plans to take, any formal step to enforce the GPLv2. Some of the language reads as pointed commentary rather than established fact: GrapheneOS writes that 'Google wants to make Pixels worse for no apparent reason,' a claim about motive that the thread does not back with evidence.
“They're in clear violation of the GPLv2 now.”
— GrapheneOS