You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android向/mnt/vendor/persist/写数据遇SELinux拦截,如何配置过CTS?

问题

需要在Android系统的/mnt/vendor/persist/目录下保存数据,使用radio域配置SELinux权限时被系统neverallow规则拦截。尝试添加的规则如下:

allow radio mnt_vendor_file:dir {search getattr read write add_name remove_name};
allow radio mnt_vendor_file:file {getattr read write create open unlink};

但出现以下错误:

libsepol.report_failure: neverallow on line 96 of device/qcom/sepolicy/qva/vendor/monaco/system_server.te (or line 101816 of policy.conf) violated by allow radio mnt_vendor_file:file { read write create getattr unlink open };
libsepol.report_failure: neverallow on line 96 of device/qcom/sepolicy/qva/vendor/monaco/system_server.te (or line 101816 of policy.conf) violated by allow radio mnt_vendor_file:dir { read write getattr add_name remove_name search };
libsepol.report_failure: neverallow on line 1378 of system/sepolicy/public/domain.te (or line 14256 of policy.conf) violated by allow radio mnt_vendor_file:dir { read write getattr add_name remove_name search };
libsepol.check_assertions: 3 neverallow failures occurred
Error while expanding policy

请问如何配置SELinux以实现在该目录保存数据并通过CTS?

解决方案
  • 为目标目录创建专属SELinux类型
    直接复用mnt_vendor_file会触发系统通用的neverallow规则,建议在/mnt/vendor/persist/下创建专属子目录(如/mnt/vendor/persist/radio_data/),并为其定义专属SELinux类型:

    1. 在vendor侧sepolicy文件中添加类型定义:
      type radio_persist_data_dir, fs_type, vendor_file_type;
      type radio_persist_data_file, fs_type, vendor_file_type;
      
    2. 在对应的file_contexts文件(如device/qcom/sepolicy/qva/vendor/file_contexts)中添加路径与类型的映射:
      /mnt/vendor/persist/radio_data(/.*)?    u:object_r:radio_persist_data_dir:s0
      /mnt/vendor/persist/radio_data/.*       u:object_r:radio_persist_data_file:s0
      
  • 配置radio域的专属权限
    替换原有规则,添加针对新类型的权限配置:

    allow radio radio_persist_data_dir:dir { search getattr read write add_name remove_name };
    allow radio radio_persist_data_file:file { getattr read write create open unlink };
    
  • 确保CTS合规

    • 新类型必须继承vendor_file_type,符合vendor分区的权限规范
    • 遵循最小权限原则,仅给radio域开放必要的操作权限
    • 禁止修改系统公共sepolicy(如system/sepolicy/public/domain.te)中的neverallow规则,此类修改会直接导致CTS测试失败

内容的提问来源于stack exchange,提问作者qiang zhang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 13:33:36