Activation paths
Start through Root, wireless ADB, static TCP, a copied shell command, or an app-provided external bridge.
Start through Root, wireless ADB, a manual shell command, or an external authorization bridge. Then use Binder or your own UserService without turning the library into a general-purpose privilege broker.