You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android系统守护进程添加失败:SELinux entry_point权限拒绝问题

SELinux配置系统守护进程时entry_point权限问题排查与解决

问题背景

尝试添加系统级非vendor守护进程,相关配置如下:

init.rc配置

service start_md /system/bin/start_md
   class core
   user root
   seclabel u:r:start_md:s0

start_md.te配置

type start_md, domain;
type start_md_exec, exec_type, file_type, system_file_type;
typeattribute start_md coredomain;
init_daemon_domain(start_md)

file_contexts配置

/system/bin/start_md           u:object_r:start_md_exec:s0

已在compat 33.0.cli中添加属性,但始终遇到AVC拒绝报错:start_md 对 system_file 的 entry_point 权限被拒绝。根据审计提示添加规则:

allow start_md system_file:file entry_point;

编译时触发public/domain.te第415行的neverallow规则报错:

neverallow * { file_type -exec_type -postinstall_file }:file entrypoint;

原因分析

虽然start_md_exec已标记为exec_type,但报错指向system_file的entry_point权限问题,核心原因有两种可能:

  1. 目标可执行文件上下文未生效:/system/bin/start_md的实际SELinux上下文未被正确设置为start_md_exec,导致init启动进程时,尝试访问的是默认system_file类型的文件,触发neverallow规则。
  2. 守护进程内部执行了未授权文件:start_md程序/脚本在运行过程中,尝试调用了其他属于system_file类型但未标记为exec_type的二进制文件,触发权限检查。

解决方案

方案1:验证并修复文件上下文

  1. 设备上执行ls -Z /system/bin/start_md,检查输出是否为u:object_r:start_md_exec:s0。
  2. 如果上下文不符,说明file_contexts配置未正确编译到SEPolicy中,或文件未被重新标记:
    • 确保file_contexts文件被包含在SEPolicy编译路径中;
    • 重新编译SEPolicy并刷入设备,或执行restorecon -v /system/bin/start_md强制应用上下文。

方案2:检查守护进程的执行逻辑

  1. 排查start_md的代码或脚本,确认是否调用了其他二进制文件(如/system/bin下的工具)。
  2. 对被调用的文件,在file_contexts中添加对应exec_type的上下文标记,例如:
    /system/bin/xxx           u:object_r:xxx_exec:s0
    
    同时在对应的.te文件中定义类型:
    type xxx_exec, exec_type, file_type, system_file_type;
    
    确保被调用文件符合neverallow规则的要求(属于exec_type或postinstall_file)。

额外注意

init_daemon_domain(start_md)宏已经包含了start_md域对start_md_exec类型文件的entry_point权限,无需手动添加额外allow规则。强行添加针对system_file的allow规则会直接违反neverallow限制,这是SELinux的安全设计,不能绕过。

内容的提问来源于stack exchange,提问作者John Smith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 22:05:30