You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AOSP中init.target.rc配置的service未执行问题排查求助

问题:SDM710设备AOSP init服务无法启动

配置的init服务内容

service dispBridge /system/bin/test.sh
    seclabel u:r:init:s0
    user root
    group root
    oneshot
    disabled
    write /dev/kmsg "dispBridgeServiceStartedTest onBootTest"

on boot
    chown system system /sys/class/leds/red/blink
    chown system system /sys/class/leds/green/blink
    chown system system /sys/class/leds/blue/blink
    write /dev/kmsg "onBootTest1"
    start dispBridge
    write /dev/kmsg "onBootTest2"

现象

  • 期望:on boot阶段执行dispBridge服务,内核日志中能看到dispBridgeServiceStartedTest onBootTest
  • 实际:仅输出onBootTest1和onBootTest2,服务未执行;手动执行start dispBridge后,服务退出状态码为127

已尝试操作

  • 在BoardConfig.mk中设置androidboot.selinux=permissive
  • 为服务配置seclabel u:r:init:s0
  • 尝试设置androidboot.selinux=disabled,服务仍未运行

相关日志

手动启动服务的dmesg日志

[  271.108234] init: Received control message 'start' for 'dispBridge' from pid: 2606 (start dispBridge)
[  271.109119] init: starting service 'dispBridge'...
[  271.132498] init: Service 'dispBridge' (pid 2607) exited with status 127
[ 3069.662302] init: Received control message 'start' for 'dispBridge' from pid: 5640 (start dispBridge)
[ 3069.662771] init: starting service 'dispBridge'...
[ 3069.716114] init: Service 'dispBridge' (pid 5641) exited with status 127

SELinux拒绝日志

[  271.122590] type=1400 audit(1730388931.839:21): avc: denied { entrypoint } for pid=2607 comm="init" path="/system/bin/test.sh" dev="dm-0" ino=1215 scontext=u:r:shell:s0 tcontext=u:object_r:system_file:s0 tclass=file permissive=0
[ 3069.693749] type=1400 audit(1730388931.839:21): avc: denied { entrypoint } for pid=2607 comm="init" path="/system/bin/test.sh" dev="dm-0" ino=1215 scontext=u:r:shell:s0 tcontext=u:object_r:system_file:s0 tclass=file permissive=0
[ 3069.694039] type=1400 audit(1730391730.409:22): avc: denied { entrypoint } for pid=5641 comm="init" path="/system/bin/test.sh" dev="dm-0" ino=1215 scontext=u:r:shell:s0 tcontext=u:object_r:system_file:s0 tclass=file permissive=0

文件安全上下文

执行ls -Z /system/bin/test.sh输出:

u:object_r:system_file:s0 /system/bin/test.sh

解决方向指引

  1. 修复脚本执行权限

    • 检查/system/bin/test.sh是否有可执行权限:执行ls -l /system/bin/test.sh,确认权限位包含x(如-rwxr-xr-x)。
    • 若权限缺失,在AOSP编译脚本中配置:例如在Android.mk中设置LOCAL_MODULE_CLASS := EXECUTABLES,或打包时添加chmod +x指令。
  2. 修正SELinux策略配置

    • 日志显示服务启动时上下文为u:r:shell:s0,而非配置的u:r:init:s0,说明seclabel未生效。需创建自定义SELinux域:
      • 在设备SELinux策略目录(如device/qcom/sdm710/sepolicy)新建dispbridge.te:
        type dispbridge, domain;
        type dispbridge_exec, exec_type, file_type;
        
        init_daemon_domain(dispbridge)
        allow dispbridge system_file:file entrypoint;
        
      • 在file_contexts中添加:
        /system/bin/test.sh u:object_r:dispbridge_exec:s0
        
      • 修改init服务的seclabel为u:r:dispbridge:s0,重新编译策略并打包镜像。
  3. 排查脚本本身问题

    • 手动执行/system/bin/test.sh,检查是否能正常运行:确认脚本开头有正确的shebang(如#!/system/bin/sh),排查语法错误或依赖缺失。
  4. 确认init配置文件有效性

    • 确保init.target.rc被系统正确加载,部分设备需将服务配置到特定rc文件(如init.sdm710.rc)而非通用的init.target.rc。

内容的提问来源于stack exchange,提问作者chinhan99

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 19:30:59