# Android application domains cannot open the filesystem root
## Environment
- Termux on Android 14, kernel `6.1.177-android14-11`, `aarch64`
- Application domain `u0_a165`, app home under `/data/data/com.termux`
- Probed with a throwaway Zig program using `openat(AT_FDCWD, "/", O_RDONLY | O_DIRECTORY |
O_CLOEXEC | O_NOFOLLOW)`; result `EACCES`
## Observation
Opening the filesystem root `/` fails with `EACCES` in the application domain. Opening a configured
scan root by its absolute path (for example `/data/data/com.termux/files/usr/tmp/
`) succeeds
with the same flags. Traversal that anchors at `/` therefore always fails closed on this platform,
while the scan itself, which opens configured roots directly, works unchanged.
## Conclusion
Mutation ancestry revalidation must anchor at the configured selected root and reopen every reviewed
ancestor below it descriptor-relative (`PRODUCT.md` section 11.1, `TJ-EXEC-02`). It must never
attempt to open `/` or any prefix outside the configured roots.
## Limits
- One device, one kernel, one application domain; no SELinux policy enumeration was performed.
- The probe does not establish whether other Android versions or vendor configurations behave the
same; anchoring at the selected root is required regardless because it is the reviewed root.