You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让system_app设置vendor_default_prop或mtk_hal_camera读取system_prop?

问题:SystemApp设置persist属性并让mtk_hal_camera读取的SEPolicy权限问题

我尝试让system_app设置persist属性,同时让mtk_hal_camera进程读取该属性,两种尝试均失败:

尝试1:使用system属性(persist.sys.foo)

  • 现象:system_app设置该属性成功,但mtk_hal_camera读取时触发SELinux权限拒绝,报错如下:
09-30 15:04:09.248  7781  7781 W HwBinder:7781_2: type=1400
audit(0.0:520169): avc: denied { read } for
name="u:object_r:system_prop:s0" dev="tmpfs" ino=385
scontext=u:r:mtk_hal_camera:s0 tcontext=u:object_r:system_prop:s0
tclass=file permissive=0
  • 尝试修复:在device/mediatek/sepolicy/custom/module/camera/non_plat/mtk_hal_camera.te中添加SEPolicy规则:
allow mtk_hal_camera system_prop:file { read };
  • 编译错误:
2023-10-16 11:16:29 neverallow check failed at
out_vnd_hal/target/product/mgvi_64_nfc_armv82/obj/ETC/plat_sepolicy.cil_intermediates/plat_sepolicy.cil:22518
from system/sepolicy/private/property.te:150 2023-10-16 11:16:29
(neverallow base_typeattr_733 base_typeattr_743 (file (ioctl read
write create setattr lock relabelfrom append unlink link rename open
watch watch_mount watch_sb watch_with_perm watch_reads))) 2023-10-16
11:16:29  2023-10-16 11:16:29 allow at
out_vnd_hal/target/product/mgvi_64_nfc_armv82/obj/ETC/vendor_sepolicy.cil_intermediates/vendor_sepolicy.cil:12983
2023-10-16 11:16:29 (allow mtk_hal_camera system_prop_31_0 (file
(read)))

尝试2:使用vendor属性(persist.vendor.camera.foo)

  • 现象:mtk_hal_camera读取该属性成功,但system_app设置时触发SELinux权限拒绝,报错如下:
2023-10-01 19:45:35.156 1-1/? W//system/bin/init: type=1107
audit(0.0:6250): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0
msg='avc: denied { set } for
property=persist.vendor.camera.foo pid=13714
uid=1000 gid=1000 scontext=u:r:system_app:s0
tcontext=u:object_r:vendor_default_prop:s0 tclass=property_service
permissive=0'
  • 尝试修复:在device/mediatek/sepolicy/custom/module/camera/non_plat/system_app.te中添加SEPolicy规则:
allow system_app vendor_default_prop:file { write };
  • 编译错误:
2023-10-14 22:31:31 libsepol.report_failure: neverallow on line 507 of
system/sepolicy/public/domain.te (or line 12716 of policy.conf)
violated by allow system_app vendor_default_prop:file { write };
2023-10-14 22:31:32 libsepol.check_assertions: 1 neverallow failures
occurred

内容的提问来源于stack exchange,提问作者zhangxaochen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 09:57:33