Overview
Modern anti-root detection suites (such as the detection routines in LSPosed/DirtySepolicy, Momo, and advanced financial security SDKs) no longer rely merely on searching for su binaries or checking which paths. Instead, they spawn an unprivileged App-Zygote child process and query the kernel’s SELinux virtual filesystem (/sys/fs/selinux/) directly.
Because root frameworks (such as Magisk, KernelSU, and APatch) inject custom domain rules into the live kernel sepolicy to allow superuser daemons to run, an App-Zygote can probe whether non-stock contexts exist or verify whether policy reload sequence counters (seqno) have incremented. If any anomalies are found, the app classifies the device as compromised.
Developed by flipphoneguy, DirtySepolicy Bypass is a specialized Zygisk module engineered to blindfold these SELinux probing techniques at the native libc system call boundary.
Probing Vectors Defeated
DirtySepolicy Bypass systematically neutralizes all four core detection vectors implemented by DirtySepolicy v2.2 and derivative detectors:
1. contextExists() Probes
Detectors write arbitrary security contexts to /sys/fs/selinux/context or query /proc/self/attr/current to see if root-injected types (like magisk, kernelsu, or su) exist in the active policy dictionary. The module intercepts these writes and returns EINVAL (invalid argument), mimicking standard stock behavior.
2. Direct Kernel checkSELinuxAccess()
Advanced detectors resolve class and permission identifiers directly from /sys/fs/selinux/class/ and submit binary permission queries to /sys/fs/selinux/access, intentionally bypassing user-space libselinux.so. DirtySepolicy Bypass hooks raw openat, read, and write syscalls to intercept these low-level queries and return strictly stock policy verdicts.
3. Policy Reload & Sequence Counter Monitoring (readStatus())
When Magisk or KernelSU injects rules at boot, the kernel increments its internal policyload counter in /sys/fs/selinux/status. Detectors compare this counter against expected stock baseline values. The module presents a virtualized, static status structure that masks all runtime policy mutations.
4. Indirect Stock-Context Probes
Detectors test allow rules between stock Android contexts (such as rootfs → tmpfs:associate) that only exist because a root framework modified the rule graph. DirtySepolicy Bypass intercepts these indirect queries, returning stock denials.
Installation & Setup
- Verify that Zygisk is enabled in Magisk or KernelSU.
- Download the
DirtySepolicy_Bypass.zipfrom GitHub. - Flash the module in your root manager.
- Reboot the smartphone.
- Launch your detection test suite (such as DirtySepolicy test apps or Momo); all SELinux probe checks will pass cleanly.
