Android application domains cannot open the filesystem root
Environment
Termux on Android 14, kernel 6.1.177-android14-11, aarch64
Application domain u0_a165, app home under /data/data/com.termux
Probed with a throwaway Zig program using openat(AT_FDCWD, "/", O_RDONLY | O_DIRECTORY | O_CLOEXEC | O_NOFOLLOW); result EACCES
Observation
Opening the filesystem root / fails with EACCES in the application domain. Opening a configured
scan root by its absolute path (for example /data/data/com.termux/files/usr/tmp/<dir>) succeeds
with the same flags. Traversal that anchors at / therefore always fails closed on this platform,
while the scan itself, which opens configured roots directly, works unchanged.
Conclusion
Mutation ancestry revalidation must anchor at the configured selected root and reopen every reviewed
ancestor below it descriptor-relative (PRODUCT.md section 11.1, TJ-EXEC-02). It must never
attempt to open / or any prefix outside the configured roots.
Limits
One device, one kernel, one application domain; no SELinux policy enumeration was performed.
The probe does not establish whether other Android versions or vendor configurations behave the
same; anchoring at the selected root is required regardless because it is the reviewed root.
# Android application domains cannot open the filesystem root
## Environment
- Termux on Android 14, kernel `6.1.177-android14-11`, `aarch64`
- Application domain `u0_a165`, app home under `/data/data/com.termux`
- Probed with a throwaway Zig program using `openat(AT_FDCWD, "/", O_RDONLY | O_DIRECTORY |
O_CLOEXEC | O_NOFOLLOW)`; result `EACCES`
## Observation
Opening the filesystem root `/` fails with `EACCES` in the application domain. Opening a configured
scan root by its absolute path (for example `/data/data/com.termux/files/usr/tmp/<dir>`) succeeds
with the same flags. Traversal that anchors at `/` therefore always fails closed on this platform,
while the scan itself, which opens configured roots directly, works unchanged.
## Conclusion
Mutation ancestry revalidation must anchor at the configured selected root and reopen every reviewed
ancestor below it descriptor-relative (`PRODUCT.md` section 11.1, `TJ-EXEC-02`). It must never
attempt to open `/` or any prefix outside the configured roots.
## Limits
- One device, one kernel, one application domain; no SELinux policy enumeration was performed.
- The probe does not establish whether other Android versions or vendor configurations behave the
same; anchoring at the selected root is required regardless because it is the reviewed root.