# Android application domains cannot open the filesystem root ## Environment - Termux on Android 14, kernel `6.1.177-android14-11`, `aarch64` - Application domain `u0_a165`, app home under `/data/data/com.termux` - Probed with a throwaway Zig program using `openat(AT_FDCWD, "/", O_RDONLY | O_DIRECTORY | O_CLOEXEC | O_NOFOLLOW)`; result `EACCES` ## Observation Opening the filesystem root `/` fails with `EACCES` in the application domain. Opening a configured scan root by its absolute path (for example `/data/data/com.termux/files/usr/tmp/`) succeeds with the same flags. Traversal that anchors at `/` therefore always fails closed on this platform, while the scan itself, which opens configured roots directly, works unchanged. ## Conclusion Mutation ancestry revalidation must anchor at the configured selected root and reopen every reviewed ancestor below it descriptor-relative (`PRODUCT.md` section 11.1, `TJ-EXEC-02`). It must never attempt to open `/` or any prefix outside the configured roots. ## Limits - One device, one kernel, one application domain; no SELinux policy enumeration was performed. - The probe does not establish whether other Android versions or vendor configurations behave the same; anchoring at the selected root is required regardless because it is the reviewed root.