dc32f0cfe84def651e0e Good point, actually. How GrapheneOS would circumvent this?
Since GrapheneOS does not include any end-to-end encrypted services by default, the gag order would probably be to order a backdoor in the disk encryption layer so law enforcements can decrypt data without your PIN or passphrase.
Either way, I think the protection would be the same. Everything being open source, and the builds being reproducible. This would increase the likelihood that such a compromised security would be detected. And being open source, the community could then choose to patch away the added backdoor or weakness, in a minimal fork of GrapheneOS. I really believe open source is what will keep us safe from such things, and why open source is so important.
Hopefully, GrapheneOS being open source is enough to deter governments from making such gag orders to begin with, since the risk of discovery is much larger.