한국어 · Documentation · Glossary
DawnShell starts Debian and a network service with root privileges before PIN entry. Its security rules are therefore stricter than those of an ordinary app.
- Never bypass Android Credential Encrypted (CE) storage.
- Keep only BFU-essential, non-secret data in Device Encrypted (DE) storage.
- Never store passwords, API tokens, reusable auth keys, or SSH private keys in DE.
- Permit SSH public-key authentication only.
- Limit root operations to fixed actions and fixed paths.
- Never describe the Debian root environment as a fully isolated virtual machine.
See Google's Direct Boot storage guidance and the AOSP FBE guide.
The design considers unauthenticated network clients, other Android apps, stale PID state, a modified rootfs, host-wide Docker or VPN changes, and secret leakage through logs or the clipboard. A compromised kernel, ROM, or root manager remains outside what an app can fully defend against.
DawnShell has a dedicated UID and keeps internal components unexported. Android's UID and SELinux isolation is described in the AOSP app sandbox guide.
DE contains boot settings, public keys, non-secret logs, markers, and verified
runtime files. CE contains the generated SSH client private key. The boot gate
uses a sentinel and receipt to prove that app CE is inaccessible before unlock,
and checks UserManager.isUserUnlocked().
If a modified ROM exposes CE during BFU, the default policy blocks startup. The explicit override accepts that risk; it does not restore encryption.
Helpers accept reviewed operation IDs, validate fixed rootfs targets, reject
unsafe values, never remount host /data, and verify UID, executable, and
namespace identity before stopping a supervisor or deleting data.
The default policy is public-key authentication for debian, with password
authentication, empty passwords, and direct root login disabled. Local passwords
are passed to chpasswd through standard input and are not persisted in app
preferences, DE storage, logs, or command-line arguments.
Private-key export requires explicit user action. The local-shell import command contains the complete private key, so file export is safer even though the app attempts to clear the clipboard after 120 seconds.
Debian shares Android's network namespace. Root network changes can therefore affect the whole device. Docker defaults to host-network-only mode with bridge, iptables, forwarding, and masquerading disabled. Bridge mode should be used only with a separate recovery path.
The Docker host IPC compatibility option is enabled by default because private
IPC/mqueue setup can reboot the whole Android device on affected kernels. Its
managed CLI wrapper adds --ipc=host to container creation, so containers can
observe or interfere with IPC objects shared by Android and Debian. This is a
stability default, not a stronger isolation mode. Avoid untrusted containers.
Explicit --ipc/ipc: values take priority, but a private-IPC container may
fail with a permission error where DawnShell blocks dangerous namespace creation.
Raw host USB access is opt-in. The default policy hides /dev/bus/usb in the
Debian mount namespace and denies USB character major 189 in DawnShell's
delegated devices policy. Direct mode removes those two restrictions only for
Debian and retains Android's kernel driver bindings. Exclusive mode also
unbinds interfaces that match an explicit VID:PID allowlist. That unbind is a
host-wide hardware state change even though the cgroup permission remains
delegated. The supervisor attempts to restore every interface on normal stop;
SIGKILL, kernel failure, or power loss can prevent restoration. Unplug or reboot
to recover. SELinux remains effective in either mode.
USB devices are an active trust boundary: firmware programmers, input devices,
network adapters, and removable storage can affect hardware or host state. Do
not expose untrusted devices, do not use broad Docker --privileged access, and
never mount one removable filesystem from Android and Debian simultaneously.
Do not put the phone's internal USB/gadget controller in the exclusive allowlist.
The codec bridge is disabled by default and opens no external TCP port.
Secure/DRM codecs are excluded from inventory and creation, and software fallback
is never automatic. The app :codec process handles capability and file
diagnostics only. Debian media commands launch one private bionic NDK worker and
communicate only through inherited memfd/eventfd objects, with no public
listener. DE stores only codec names, capabilities, and errors—never frames,
bitstreams, media paths, or credentials. Automatic processing of untrusted media
remains opt-in.
Verify Release checksums and use a private production signing key. Android update identity is explained in Google's app-signing guide.
- Use a dedicated BFU SSH key.
- Keep reusable credentials out of the BFU rootfs.
- Grant permanent root only to the expected DawnShell package.
- Back up data and keys before destructive operations.
- Prepare local recovery before Docker bridge or high-risk root changes.
- Rotate the SSH key and reconfigure SSH after suspected compromise.