Android Java服务连接Vendor HAL Unix Socket遇SEPolicy限制求解决方案
我有一个创建Unix Socket的Vendor HAL,还有一个尝试连接该Socket的Java服务。Java服务无法连接,原因是SEPolicy违规,审计日志如下:
05-31 02:50:29.494 2598 2598 W testservice: type=1400 audit(0.0:159): avc: denied { connectto } for path=006F6E657761792E736F636B65745F737276 scontext=u:r:system_app:s0 tcontext=u:r:hal_test:s0 tclass=unix_stream_socket permissive=0
根据audit2allow的建议,尝试添加SEPolicy规则:
allow system_app hal_test:unix_stream_socket connectto;
但Android编译失败,报错:
libsepol.check_assertions: 1 neverallow failures occurred
相关的neverallow规则定义在system/sepolicy/public/domain.te中:
# On full TREBLE devices, socket communications between core components and vendor components are # not permitted. # Most general rules first, more specific rules below. # Core domains are not permitted to initiate communications to vendor domain sockets. # We are not restricting the use of already established sockets because it is fine for a process # to obtain an already established socket via some public/official/stable API and then exchange # data with its peer over that socket. The wire format in this scenario is dicatated by the API # and thus does not break the core-vendor separation. full_treble_only(` neverallow_establish_socket_comms({ coredomain -init -adbd }, { domain -coredomain -socket_between_core_and_vendor_violators }); ')
现咨询:是否存在合规方式让Java服务使用该由Vendor HAL创建的Unix Socket?
在Full Treble架构下,核心域(如system_app)主动发起连接到Vendor域Socket的操作被neverallow规则明确禁止,直接添加allow规则会触发编译失败。以下是几种合规实现方案:
方案1:反转连接发起方
核心域允许接收Vendor域的连接请求,反过来操作即可规避限制:
- 由Java服务(
system_app)先创建Unix Socket并监听 - 让Vendor HAL主动发起连接到这个Socket
- 添加对应的SEPolicy规则允许Vendor域连接到核心域的Socket:
allow hal_test system_app:unix_stream_socket connectto;
该方案符合Treble设计逻辑——核心域被动接收Vendor域连接时,通信接口由核心域管控,不会破坏核心-Vendor分离原则。
方案2:使用官方跨域通信API
优先采用Android官方定义的跨核心-Vendor通信机制,这类机制天然符合SEPolicy规则:
- HIDL/AIDL接口:Treble架构推荐的标准跨域通信方式,无需额外修改权限
- Binder IPC:通过标准Binder实现进程间通信,核心与Vendor之间的Binder交互有成熟的权限管控
方案3:将Java服务迁移至Vendor分区
如果Java服务不依赖核心系统组件,可将其编译到Vendor分区,使其运行在Vendor域(如vendor_app类型)。此时同属Vendor域的HAL和Java服务间的Socket通信不会触发跨域neverallow限制,只需添加域内SEPolicy规则即可。
注意事项
不要修改neverallow规则或把域加入socket_between_core_and_vendor_violators,这会破坏Treble核心分离原则,导致设备失去兼容性与安全性,无法通过CTS认证。
内容的提问来源于stack exchange,提问作者Yuri

