Google Meet & Virtual Audio Pipeline
The Google Meet integration enables the assistant to participate in scheduled virtual conferences, transcribe multi-party discussions, and provide real-time meeting synthesis.
1. Headless Virtual Display & Audio Topology
graph TD
subgraph ContainerEnvironment [Podman Quadlet Container: Unprivileged User]
Xvfb[Xvfb :99 Headless Virtual Display]
PipeWire[PipeWire Audio Daemon]
WirePlumber[WirePlumber Session Manager]
Sink[Virtual Audio Sink: virtual-sink]
Source[Virtual Audio Source: virtual-mic]
Chromium[Headless Browser: Meet Client]
Core[Assistant Audio Engine]
Chromium -->|Speaker Output| Sink
Source -->|Microphone Input| Chromium
Sink -->|PCM Frame Capture| Core
Core -->|TTS Audio Injection| Source
end
subgraph ExternalCloud [Google Cloud Services]
STT[Google Speech-to-Text API]
TTS[Google Text-to-Speech API]
end
Core -->|Encrypted Streaming gRPC| STT
TTS -->|Synthesized Audio Stream| Core
- Virtual Display & Audio Loopback: The container operates a headless X11 server (
Xvfb) and a local PipeWire audio daemon. Virtual audio nodes (virtual-sinkandvirtual-mic) decouple the browser from physical hardware. - Headless Browser Execution: A sandboxed Chromium browser connects to the designated Google Meet meeting URL.
- Real-Time Speech Processing: PipeWire captures incoming audio frames from the virtual sink and streams them over encrypted gRPC channels to the Google Speech-to-Text API for transcription.
2. Privacy & Anti-Eavesdropping Invariants
- Explicit Invitation Trigger: The assistant never joins meetings autonomously without an explicit calendar invitation or direct invitation link dispatched by an authorized meeting participant.
- Dormant Default State: When no scheduled conference is active, audio daemons and browser processes are completely stopped. The system does not maintain passive listening streams.
- Zero Audio Storage: Raw audio frames are processed in-flight in volatile memory and discarded immediately following transcription. No raw audio files (
.wav,.mp3) are written to disk. - Participant Transparency: The assistant enters the conference with a clearly identifiable display name and visual avatar, notifying participants of automated note-taking.
3. Threat Model & Mitigations
| Threat Vector | Attack Path | Security Mitigation |
|---|---|---|
| Browser Sandbox Escape | Malicious WebRTC or JavaScript payload delivered through Google Meet. | Chromium sandbox enabled with strict seccomp filters. Container operates under rootless user (UID 1000) with restricted namespace capabilities. |
| Ambient Audio Leakage | Leaking private conversation before or after meeting. | Lifecycle hooks terminate browser and PipeWire processes immediately upon meeting conclusion or when participant count drops to 1. |
| Unauthorized Meeting Infiltration | Bot joining private or restricted meetings. | Meetings are validated against allowed corporate domains. Uninvited connection attempts are rejected. |
| Cloud Credential Abuse | Container IAM identity misused for data access. | Ambient service account holds only roles/speech.client. It cannot read mailboxes, chat history, or Cloud Storage buckets. |