I think podman by default does do that, but it’s easy to disable almost all of it, at least.
I think podman by default does do that, but it’s easy to disable almost all of it, at least.
TB docks are very well supported. Depending on the DE you use, you’ll need to “authorize”/allow the dock for it to get used.
Can confirm that btrfs on nvme with sleep/suspend has been working fine for me on my Framework laptop (haven’t tested hibernate, though).
A manufacturer’s Android can have special privileges for their own apps, and almost will certainly have special privileges for Google’s apps.
Graphene by default wouldn’t give special privileges to any app, so that’s at least a plus.
It’s true that it would be locked down, but you at least have a couple more controls over how locked down compared to a manufacturer’s OS.