Skip to content

Security: MadeByAlpha/dawnshell

Security

docs/security.md

DawnShell security model

한국어 · Documentation · Glossary

DawnShell starts Debian and a network service with root privileges before PIN entry. Its security rules are therefore stricter than those of an ordinary app.

Principles

  1. Never bypass Android Credential Encrypted (CE) storage.
  2. Keep only BFU-essential, non-secret data in Device Encrypted (DE) storage.
  3. Never store passwords, API tokens, reusable auth keys, or SSH private keys in DE.
  4. Permit SSH public-key authentication only.
  5. Limit root operations to fixed actions and fixed paths.
  6. Never describe the Debian root environment as a fully isolated virtual machine.

See Google's Direct Boot storage guidance and the AOSP FBE guide.

Threat model

The design considers unauthenticated network clients, other Android apps, stale PID state, a modified rootfs, host-wide Docker or VPN changes, and secret leakage through logs or the clipboard. A compromised kernel, ROM, or root manager remains outside what an app can fully defend against.

Android isolation

DawnShell has a dedicated UID and keeps internal components unexported. Android's UID and SELinux isolation is described in the AOSP app sandbox guide.

Storage

DE contains boot settings, public keys, non-secret logs, markers, and verified runtime files. CE contains the generated SSH client private key. The boot gate uses a sentinel and receipt to prove that app CE is inaccessible before unlock, and checks UserManager.isUserUnlocked().

If a modified ROM exposes CE during BFU, the default policy blocks startup. The explicit override accepts that risk; it does not restore encryption.

Root helpers

Helpers accept reviewed operation IDs, validate fixed rootfs targets, reject unsafe values, never remount host /data, and verify UID, executable, and namespace identity before stopping a supervisor or deleting data.

SSH and passwords

The default policy is public-key authentication for debian, with password authentication, empty passwords, and direct root login disabled. Local passwords are passed to chpasswd through standard input and are not persisted in app preferences, DE storage, logs, or command-line arguments.

Private-key export requires explicit user action. The local-shell import command contains the complete private key, so file export is safer even though the app attempts to clear the clipboard after 120 seconds.

Network and Docker

Debian shares Android's network namespace. Root network changes can therefore affect the whole device. Docker defaults to host-network-only mode with bridge, iptables, forwarding, and masquerading disabled. Bridge mode should be used only with a separate recovery path.

The Docker host IPC compatibility option is enabled by default because private IPC/mqueue setup can reboot the whole Android device on affected kernels. Its managed CLI wrapper adds --ipc=host to container creation, so containers can observe or interfere with IPC objects shared by Android and Debian. This is a stability default, not a stronger isolation mode. Avoid untrusted containers. Explicit --ipc/ipc: values take priority, but a private-IPC container may fail with a permission error where DawnShell blocks dangerous namespace creation.

Host USB

Raw host USB access is opt-in. The default policy hides /dev/bus/usb in the Debian mount namespace and denies USB character major 189 in DawnShell's delegated devices policy. Direct mode removes those two restrictions only for Debian and retains Android's kernel driver bindings. Exclusive mode also unbinds interfaces that match an explicit VID:PID allowlist. That unbind is a host-wide hardware state change even though the cgroup permission remains delegated. The supervisor attempts to restore every interface on normal stop; SIGKILL, kernel failure, or power loss can prevent restoration. Unplug or reboot to recover. SELinux remains effective in either mode.

USB devices are an active trust boundary: firmware programmers, input devices, network adapters, and removable storage can affect hardware or host state. Do not expose untrusted devices, do not use broad Docker --privileged access, and never mount one removable filesystem from Android and Debian simultaneously. Do not put the phone's internal USB/gadget controller in the exclusive allowlist.

Hardware video codecs

The codec bridge is disabled by default and opens no external TCP port. Secure/DRM codecs are excluded from inventory and creation, and software fallback is never automatic. The app :codec process handles capability and file diagnostics only. Debian media commands launch one private bionic NDK worker and communicate only through inherited memfd/eventfd objects, with no public listener. DE stores only codec names, capabilities, and errors—never frames, bitstreams, media paths, or credentials. Automatic processing of untrusted media remains opt-in.

Signing and releases

Verify Release checksums and use a private production signing key. Android update identity is explained in Google's app-signing guide.

Operational recommendations

  • Use a dedicated BFU SSH key.
  • Keep reusable credentials out of the BFU rootfs.
  • Grant permanent root only to the expected DawnShell package.
  • Back up data and keys before destructive operations.
  • Prepare local recovery before Docker bridge or high-risk root changes.
  • Rotate the SSH key and reconfigure SSH after suspected compromise.

There aren't any published security advisories