← Executive Summary • Pillar 02: Deterministic Edge & Platform Sandboxing
Custom AOSP ROMs, SEPolicy & System Daemons

Custom Android OS System Architecture,
SEPolicy Hardening & AIDL Services

Demonstrating deep low-level Android operating system development: security-hardened SELinux policy rules (sepolicy), custom kernel netfilter extensions, elevated system IPC daemons (cleargfs), Gateway Management (ClearGM), framework patches, and de-Googled GmsCore AIDL implementations.

Layered mobile operating-system components protected by a security shield
PROCESS → POLICY → SANDBOX AOSP System Sandboxing, Custom SELinux Domain Rules, eBPF Firewalls & StrongBox HSM
Executive TL;DR

AOSP & Android OS Platform

View 5 Pillars →
🎯 Business Context

Built sovereign, de-Googled OS platform for hardened biometric identity and mission-critical enterprise hardware.

⚡ Technical Hurdle

Strict Enforcing-mode zero-denial SELinux isolation, custom init daemons, and microG unified NLP location spoofing resistance.

🏆 Deliverable & Impact

Production-ready custom ROM manifest, 72 platform patches, 5 AIDL IPC services, and hardware StrongBox TEE integration.

100%
Custom SEPolicy Hardening
Granular Domain Enforcement & IPC Rule Sets
3 System Daemons
Elevated FIFO & Network Services
ClearGM, ClearGFS & ClearSU
72 System Patches
AOSP Framework Modifications
Grants Manager & URI Authorization Patches
15+ AIDL Interfaces
System Binder Interfaces
Decentralized Storage & Key Derivation Layers

Conceptually Distinct Android Projects

Select any project card below to open its dedicated technical deep-dive sub-page with architecture diagrams, code snippets, and SEPolicy definitions.

PROJECT 01 AOSP / APEX

Custom AOSP Build & APEX Infrastructure

Custom AOSP ROM build manifests (BoardConfig.mk, device.mk), kernel extensions (IPv6 NAT, IPSET), updateable APEX payload packaging, and system image deployment.

PROJECT 02 SEPolicy / Netfilter

SEPolicy & Gateway Management Layer (ClearGM)

Specialized SELinux policy (cleargm.te) enabling low-level socket binding, BPF loader maps, netfilter masquerade rules, and dynamic DID-authenticated domain whitelisting.

PROJECT 03 SEPolicy / DAC Override

Elevated System Services & Cross-Domain IPC (ClearGFS)

Architecture solving Android's app_domain sandbox restrictions via elevated FIFO IPC (clearfifo, clearshell), DAC overrides, and system backup daemons.

PROJECT 04 Framework Patches

AOSP Framework Patches & Grants Manager

72 custom single-handed AOSP framework patches, including modifying the Grants Manager Service to allow backup daemons (`clearsync`) to create content URI grants across app sandboxes.

PROJECT 05 AIDL / microG

Custom microG Services Core & AIDL Implementations

De-Googled replacement for Play Services (GmsCore, ClearMS) featuring custom AIDL binder definitions (IDroidGuardService, INearbyExposureNotificationService).

PROJECT 06 AIDL / Crypto

Decentralized System AIDL Layer (HKDF & Storage)

Exposing system-level AIDL binder services for derived cryptographic key generation (HKDF) and decentralized storage, abstracting HKDF & P2P DHT mechanics for third-party Android apps.

Custom AOSP ROM Engineering & Kernel Extensions

Building an enterprise-grade, de-Googled custom Android ROM with kernel netfilter extensions and updateable APEX packaging.

  • ✓
    Custom Target Board Configuration: Configured custom AOSP build targets via BoardConfig.mk, device.mk, and product inheritances for custom ARM64 hardware platforms.
  • ✓
    APEX Module Integration: Packaged system services and native libraries into modular APEX (Android APEX) updateable payloads for out-of-band security updates.
  • ✓
    Kernel Netfilter & IPSET Extensions: Patched the Linux kernel to support IPv6 NAT, ipset packet matching, and custom netfilter modules in system/netd.
  • ✓
    De-Googled Firmware Stripping: Stripped telemetry, Google Mobile Services (GMS), and proprietary vendor blobs to build a 100% open-source security-hardened ROM.
  • ✓
    Secure Boot & AVB 2.0 Integration: Integrated Android Verified Boot (AVB 2.0) with custom OEM RSA signing keys to ensure hardware root-of-trust firmware validation.
  • ✓
    Automated Vendor Image Compilation: Engineered Makefile and Android.bp build targets for generating flashable fastboot images (system.img, vendor.img, boot.img).

Gateway Management Layer & SEPolicy (ClearGM)

Executing low-level socket binding, netlink routing, BPF loader maps, and IP table filtering through specialized SELinux domain policies.

SEPolicy Hardening & ClearGM Architecture
Inspect Architecture Diagram
SEPolicy cleargm.te • eBPF Firewall

SELinux Domain Transition & eBPF Packet Filter Pipeline

Executing low-level socket binding and DID-authenticated network filtering under strict zero-denial Enforcing mode.

  • ✓
    Custom SELinux Domain Definitions: Authored cleargm.te policy files defining isolated SELinux domain labels (cleargm_t) and file context transitions (cleargm_exec_t).
  • ✓
    Low-Level Socket & Network Binding: Configured SELinux permissions allowing system daemons to bind raw sockets, manipulate routing tables, and manage netlink interface events.
  • ✓
    Dynamic BPF Loader Maps: Built extended Berkeley Packet Filter (eBPF) loader maps for real-time per-uid network packet accounting and kernel-level firewall enforcement.
  • ✓
    DID-Authenticated Access Whitelisting: Implemented dynamic domain name and IP address whitelisting bound to Decentralized Identifier (DID) cryptographic identity tokens.
  • ✓
    Netfilter Masquerading & Tethering Rules: Integrated custom iptables/nftables rules for encrypted P2P tethering and network address translation across mesh interfaces.
  • ✓
    Strict Enforcement & Audit Analysis: Eliminated SELinux dontaudit masks, analyzed audit2allow outputs, and validated 100% zero-denial execution under strict Enforcing mode.

Elevated System Services & Sandbox Override (ClearGFS)

Solving Android's app_domain sandbox restrictions via elevated FIFO IPC, system app domain isolation, and DAC override capabilities.

Cross-Domain FIFO IPC & DAC Sandbox Override Architecture
Inspect Architecture Diagram
FIFO IPC • DAC Override

Elevated FIFO IPC, Capability Overrides & Fuse Storage Pipeline

Enabling audited cross-domain communication between untrusted app sandboxes and privileged system services.

  • ✓
    App Domain Sandbox Bypass via FIFO IPC: Designed clearfifo and clearshell daemons to enable secure, audited IPC between untrusted app_domain sandboxes and privileged system services.
  • ✓
    Discretionary Access Control (DAC) Overrides: Configured system daemon capabilities (CAP_DAC_OVERRIDE, CAP_SYS_ADMIN) with strict SELinux constraints to allow cross-user storage management.
  • ✓
    Decentralized Storage Mount Point Management: Built C++ native daemons (cleargfs) managing encrypted Virtual File System (VFS) mounts and Fuse filesystem passes.
  • ✓
    Unix Domain Socket Security Verification: Enforced peer credential checks (SO_PEERCRED) on all incoming socket connections to verify client process UID/GID before processing IPC requests.
  • ✓
    Automated Daemon Lifecycles: Integrated system daemons into AOSP init.rc configuration files with automated crash restart loops and OOM score adjustments (oom_score_adj -900).
  • ✓
    Encrypted Cross-App Backup Sync: Built clearsync daemon for asynchronous encrypted backup syncing across isolated multi-user Android profiles.

AOSP Framework Patches & Grants Manager Service

Authoring 72 single-handed AOSP framework modifications, including patching Android's Grants Manager Service to allow platform backup services (clearsync) to create content URI grants across user sandboxes.

  • ✓
    72 Single-Handed AOSP Framework Modifications: Authored 72 clean patches across frameworks/base, frameworks/native, and system/core.
  • ✓
    Patched Grants Manager Service: Modified AOSP GrantUriPermission mechanisms to allow system backup daemons (clearsync) to mint content URI grants dynamically.
  • ✓
    Cross-Sandbox File Descriptor Sharing: Patched Android's ContentProvider security checks to enable secure stream access for encrypted file objects across un-networked sandboxes.
  • ✓
    Custom Permission Annotations: Introduced platform-level custom permissions (android.permission.MANAGE_CLEAR_STORAGE) guarded by Signature-or-System protection levels.
  • ✓
    SystemServer Lifecycle Hooks: Injected initialization hooks into SystemServer.java for registering custom system services during early boot stage 2.
  • ✓
    Backwards Compatibility Preservation: Maintained 100% CTS (Compatibility Test Suite) pass rates and API compatibility for third-party Android apps.

De-Googled GmsCore & Custom AIDL Implementations

Developing system-level AIDL binder interfaces to provide open, privacy-respecting alternatives to proprietary Google Play Services.

De-Googled GmsCore & Open AIDL Binder Architecture
Inspect Architecture Diagram
microG Core • Zero Telemetry

Open AIDL Binder Stubs & Privacy-Preserving Providers

Seamless binary compatibility for unmodified Android apps while eliminating cloud tracking and analytics pingbacks.

  • ✓
    Open AIDL Service Definitions: Re-implemented proprietary Google Play Services interfaces via open AIDL definitions (IClearServices.aidl, IDroidGuardService.aidl).
  • ✓
    IPC Binder Proxy & Stub Architecture: Engineered custom Java/C++ Binder stubs handling multi-threaded transaction marshalling across client-server IPC boundaries.
  • ✓
    Privacy-Preserving Location & Maps Provider: Replaced proprietary location tracking with open-source network location providers (UnifiedNlp) and local offline geocoders.
  • ✓
    Exposure Notification Service Replacement: Developed privacy-first INearbyExposureNotificationService AIDL stubs using BLE rotating ephemeral identifiers.
  • ✓
    Zero Telemetry Background Execution: Eliminated periodic Google analytics reporting, cloud pingbacks, and background battery-draining telemetry loops.
  • ✓
    App Compatibility Layer: Ensured legacy Android applications compiled against official Google Play Services SDKs run seamlessly without modification.

Decentralized System AIDL Layer (HKDF & Storage)

Exposing a unified system-level AIDL service for derived key generation and decentralized file handling so Android applications can operate without needing to understand HKDF key derivation or P2P storage protocols.

Decentralized System AIDL & HKDF Derivation Architecture
Inspect Architecture Diagram
System AIDL • Hardware HSM

Hardware HKDF Key Derivation & PFD Storage Streaming

Abstracting complex cryptographic key derivation and decentralized P2P storage into clean system-level Binder interfaces.

  • ✓
    System-Level HKDF Key Derivation Service: Exposed ICryptographicKeyService.aidl allowing unprivileged apps to request master-derived keys (HKDF-SHA256) without accessing master secrets.
  • ✓
    Hardware Security Module (HSM) Backing: Bound derived key generation to Android KeyStore hardware-backed keys (StrongBox / ARM TrustZone TEE).
  • ✓
    Abstracted P2P Storage Binder Interfaces: Built IDecentralizedStorageService.aidl providing high-level file read/write IPC methods abstracting underlying Kademlia DHT mechanics.
  • ✓
    Asynchronous Parcel File Descriptor (PFD) Streaming: Implemented ParcelFileDescriptor streaming across Binder transactions for zero-copy bulk file transfers.
  • ✓
    Caller Authentication & UID Enforcement: Validated Binder.getCallingUid() and getCallingPid() against package signatures before granting cryptographic operations.
  • ✓
    Developer SDK Abstraction: Created a lightweight client library wrapping AIDL Binder interfaces into clean idiomatic Kotlin/Java async APIs (CompletableFuture / Coroutines).