Android系统守护进程添加失败:SELinux entry_point权限拒绝问题
SELinux配置系统守护进程时entry_point权限问题排查与解决
问题背景
尝试添加系统级非vendor守护进程,相关配置如下:
init.rc配置
service start_md /system/bin/start_md class core user root seclabel u:r:start_md:s0
start_md.te配置
type start_md, domain; type start_md_exec, exec_type, file_type, system_file_type; typeattribute start_md coredomain; init_daemon_domain(start_md)
file_contexts配置
/system/bin/start_md u:object_r:start_md_exec:s0
已在compat 33.0.cli中添加属性,但始终遇到AVC拒绝报错:start_md 对 system_file 的 entry_point 权限被拒绝。根据审计提示添加规则:
allow start_md system_file:file entry_point;
编译时触发public/domain.te第415行的neverallow规则报错:
neverallow * { file_type -exec_type -postinstall_file }:file entrypoint;
原因分析
虽然start_md_exec已标记为exec_type,但报错指向system_file的entry_point权限问题,核心原因有两种可能:
- 目标可执行文件上下文未生效:
/system/bin/start_md的实际SELinux上下文未被正确设置为start_md_exec,导致init启动进程时,尝试访问的是默认system_file类型的文件,触发neverallow规则。 - 守护进程内部执行了未授权文件:
start_md程序/脚本在运行过程中,尝试调用了其他属于system_file类型但未标记为exec_type的二进制文件,触发权限检查。
解决方案
方案1:验证并修复文件上下文
- 设备上执行
ls -Z /system/bin/start_md,检查输出是否为u:object_r:start_md_exec:s0。 - 如果上下文不符,说明file_contexts配置未正确编译到SEPolicy中,或文件未被重新标记:
- 确保file_contexts文件被包含在SEPolicy编译路径中;
- 重新编译SEPolicy并刷入设备,或执行
restorecon -v /system/bin/start_md强制应用上下文。
方案2:检查守护进程的执行逻辑
- 排查
start_md的代码或脚本,确认是否调用了其他二进制文件(如/system/bin下的工具)。 - 对被调用的文件,在file_contexts中添加对应exec_type的上下文标记,例如:
同时在对应的/system/bin/xxx u:object_r:xxx_exec:s0.te文件中定义类型:
确保被调用文件符合neverallow规则的要求(属于type xxx_exec, exec_type, file_type, system_file_type;exec_type或postinstall_file)。
额外注意
init_daemon_domain(start_md)宏已经包含了start_md域对start_md_exec类型文件的entry_point权限,无需手动添加额外allow规则。强行添加针对system_file的allow规则会直接违反neverallow限制,这是SELinux的安全设计,不能绕过。
内容的提问来源于stack exchange,提问作者John Smith
相关产品推荐
相关产品推荐

