Features
GrapheneOS is the north star for intent. This page lists what Cicada actually ships on a laptop — policy OS on Linux, not Android kernel sandboxing.
Exploit mitigations
RUNTIME- mallochardened_malloc (GrapheneOS tag) via ld.so.preload
- Kernellinux-hardened boot entry + lockdown on that entry
- Memoryinit_on_alloc / init_on_free on cmdline
- CETibt + shstk where silicon supports it — not MTE
Permissions
SCOPES- DefaultUnknown apps: NETWORK/FILES deny
- MIC/CAMPer-app deny + system software kill
- PortalFILES=portal ≈ Downloads + picker
- VPN-onlyHost net only while wg0 is up
AFU / coercion
LOCK- RebootAuto-reboot when locked (default 30 min)
- USBUSBGuard blocks inserts while locked
- DuressLUKS slot + session PAM path
- WatchdogHardware AFU ceiling when present
Browser / network
HELIUM- JITOff via managed policy
- TelemetryOff — sync, metrics, DoH theater cut
- VPNWireGuard + nftables kill switch (opt-in)
- MACRandomized; LLMNR/mDNS off
Will not claim
HARD GAPS- MTENo x86 equivalent — do not list as done
- AuditorNo Titan — Pixel pin of TPM quote is the substitute
- Qubesbwrap scopes ≠ Xen compartments
- AV killSoftware cam/mic kill ≠ hardware cut