· via dev.to (home feed)
Android 17 QPR1's 84 new APIs stay Pixel-only until December as Google withholds AOSP source
Google shipped Android 17 QPR1 to Pixels with 84 new APIs but kept the source out of AOSP, leaving other OEMs and custom ROMs waiting until December — and security patches are delayed too.

Google shipped Android 17 QPR1 to Pixel phones on September 15 with 84 new APIs for developers, but did not publish the matching source code to the Android Open Source Project. According to a dev.to analysis of the release, that leaves every other Android device maker and custom ROM project unable to ship those APIs until QPR2 reaches AOSP in December — roughly three months in which only Google's own hardware can carry them.
What QPR1 actually adds
Android 17 QPR1 is API level 37.1. The official API diff, dated June 29, records 84 additions, 233 changes and zero removals, which Google's own page puts at about 0.52 percent of the platform. The largest item is an entirely new package, android.hardware.hid, with its own system service and permission, letting apps talk directly to USB and Bluetooth HID peripherals such as controllers, keyboards and custom input devices without writing a driver. The diff also adds java.util.jar CEN constants, photo picker UI parameters and a telecom CAPABILITY_TRANSFER capability.
The release reached 25 Pixel models, from the Pixel 6 to the Pixel 11 Pro Fold. Developers who want to use the 37.1 APIs today are effectively building for that installed base alone; the dev.to piece recommends gating on the minor SDK version and keeping a fallback path until December.
Why the code is Pixel-only
According to GrapheneOS, cited in the dev.to write-up, Google has settled into a pattern since Android 16: the yearly platform release and QPR2 land in AOSP, while QPR1 in September and QPR3 in March go to Pixels alone.
The underlying change came on March 26, 2025, when Google confirmed to Android Authority that all Android OS development had moved to a private internal branch, with a stated commitment to publish source after each release. The first visible consequence was Android 16 QPR1, which shipped to Pixels on September 3, 2025 while its source reached AOSP only on November 11 — 69 days later, even though Google had told Android Authority it usually publishes source within 24 to 48 hours. What is new this cycle is that a Pixel-only release now carries public APIs.
GrapheneOS draws the comparison to Honeycomb, the tablet-only Android 3.x from 2011 whose source Google also held back until Ice Cream Sandwich arrived. For fifteen years that stood as Android's single exception; there are now two scheduled ones per year.
The security patch gap
The APIs are the visible half of the story. GrapheneOS says the September Pixel Update Bulletin contains fixes for standard Android platform components that every other OEM builds on, and that those fixes appear in neither the public Android Security Bulletin nor the preview patches partners receive. Other manufacturers get them in December with QPR2.
For one quarter, Pixels are patched against bugs in code that runs on billions of other devices, and the fix exists only in binary form. GrapheneOS says it intends to reverse engineer the patches from that binary and ship them early — something anyone with a disassembler and worse intent can equally do. Kernel source is a separate friction point: GrapheneOS requested the GPL-mandated kernel sources for build CD1A.260905.001.A1 on September 1 and received access on September 16.
GrapheneOS is moving off Pixels
GrapheneOS spent seven years recommending Pixel phones as the base for a hardened OS. It had Android 17 QPR1 ported before the release but says it lacks permission to ship it, and is instead hand-backporting Pixel firmware, kernel drivers and HALs onto plain Android 17 until December. The project now describes Pixels as harder to support than many other devices, and on March 2, 2026 it announced a long-term partnership with Motorola that includes official firmware and driver code.
Not everyone reads this as a crisis. A highly rated Hacker News comment from user bri3d argued that Pixel market share is too small for app developers to depend on the new APIs, which makes Pixels an early-access testbed for what arrives a quarter later. The dev.to author broadly agrees on the APIs while treating the security patch delay as the more serious problem.
Why it matters
Eighty-four APIs — half a percent of the platform — will not fork Android, and the HID package will be available on every device by December. The structural change is timing: twice a year, Google's phones get a quarter's head start on platform code, and with it months of early protection against security bugs in components the entire ecosystem runs. Android's openness has also been its core defence in antitrust arguments, and GrapheneOS has asked whether Google's own legal team realises the advantage being handed to the company's hardware over its OEM partners. As of the report, Google had not publicly responded.
- #android
- #aosp
- #open-source
- #pixel
- #mobile-os