Getting root on OnePlus 15 from an untrusted app

What happened
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
Summary assembled by rule from the sources below