Luigit
repositories / termux-janitor

termux-janitor

Interactive cleanup assistant for Termux: transparent, safe, confirmed disk reclamation.

owned by admin

spec/experiments/android_root_open_denied.md

Raw
Rendered preview

Android application domains cannot open the filesystem root

Environment

  • Termux on Android 14, kernel 6.1.177-android14-11, aarch64
  • Application domain u0_a165, app home under /data/data/com.termux
  • Probed with a throwaway Zig program using openat(AT_FDCWD, "/", O_RDONLY | O_DIRECTORY | O_CLOEXEC | O_NOFOLLOW); result EACCES

Observation

Opening the filesystem root / fails with EACCES in the application domain. Opening a configured scan root by its absolute path (for example /data/data/com.termux/files/usr/tmp/<dir>) succeeds with the same flags. Traversal that anchors at / therefore always fails closed on this platform, while the scan itself, which opens configured roots directly, works unchanged.

Conclusion

Mutation ancestry revalidation must anchor at the configured selected root and reopen every reviewed ancestor below it descriptor-relative (PRODUCT.md section 11.1, TJ-EXEC-02). It must never attempt to open / or any prefix outside the configured roots.

Limits

  • One device, one kernel, one application domain; no SELinux policy enumeration was performed.
  • The probe does not establish whether other Android versions or vendor configurations behave the same; anchoring at the selected root is required regardless because it is the reviewed root.
# Android application domains cannot open the filesystem root

## Environment

- Termux on Android 14, kernel `6.1.177-android14-11`, `aarch64`
- Application domain `u0_a165`, app home under `/data/data/com.termux`
- Probed with a throwaway Zig program using `openat(AT_FDCWD, "/", O_RDONLY | O_DIRECTORY |
  O_CLOEXEC | O_NOFOLLOW)`; result `EACCES`

## Observation

Opening the filesystem root `/` fails with `EACCES` in the application domain. Opening a configured
scan root by its absolute path (for example `/data/data/com.termux/files/usr/tmp/<dir>`) succeeds
with the same flags. Traversal that anchors at `/` therefore always fails closed on this platform,
while the scan itself, which opens configured roots directly, works unchanged.

## Conclusion

Mutation ancestry revalidation must anchor at the configured selected root and reopen every reviewed
ancestor below it descriptor-relative (`PRODUCT.md` section 11.1, `TJ-EXEC-02`). It must never
attempt to open `/` or any prefix outside the configured roots.

## Limits

- One device, one kernel, one application domain; no SELinux policy enumeration was performed.
- The probe does not establish whether other Android versions or vendor configurations behave the
  same; anchoring at the selected root is required regardless because it is the reviewed root.