You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AOSP11 SELinux neverallow拦截编译 如何为指定app单独配置授权

操作方案

问题背景

  • 需为3个特定平台签名应用授予sysfs访问权限,直接对通用platform_app域配置open权限时触发SELinux neverallow规则拦截,仅配置getattr权限可正常通过编译
  • 触发拦截的原规则:
allow platform_app sysfs:file { getattr open };
  • 构建报错日志:
libsepol.report_failure: neverallow on line 1121 of system/sepolicy/public/domain.te (or line 12579 of policy.conf) violated by allow platform_app sysfs:file { open };
  • 前期抓取的AVC拒绝日志(当时拦截权限为read):
06-10 21:00:33.020  2022  2022 W DefaultDispatch: type=1400 audit(0.0:16): avc: denied { read } for name="devices" dev="sysfs" ino=8471 scontext=u:r:platform_app:s0:c512,c768 tcontext=u:object_r:sysfs:s0 tclass=dir permissive=0 app=com.myapp.htgl
  • 核心要求:将规则中泛化的platform_app替换为仅指向指定目标应用的专属域,绕过neverallow限制完成授权,先完成单应用测试再适配全部3个应用

具体操作步骤

1. 为目标应用定义专属SELinux域

不能直接给通用platform_app域配置敏感权限,需为每个目标应用单独定义专属域,在项目自定义sepolicy目录(通常路径为device/<厂商名>/<机型名>/sepolicy/)下新建规则文件,以测试应用com.myapp.htgl为例:

# 定义专属域,继承platform_app的基础权限
type myapp_htgl, domain;
app_domain(myapp_htgl)
platform_app_domain(myapp_htgl)

3个应用需分别定义3个独立专属域,例如myapp_htgl、myapp_second、myapp_third,每个域单独做上述声明即可。

2. 绑定应用包名与专属域

在同sepolicy目录下的seapp_contexts文件中添加映射规则,将目标应用包名和上一步定义的专属域绑定,平台签名应用需匹配seinfo=platform标识:

user=platform_app seinfo=platform name=com.myapp.htgl domain=myapp_htgl type=app_data_file levelFrom=all

3个应用对应添加3行映射规则,分别替换为对应包名和专属域即可。

3. 为专属域配置所需sysfs权限

此时给专属域授权不会触发针对整个platform_app域的neverallow限制,在对应规则文件中添加实际需要的权限,注意之前AVC日志显示被拦截的是sysfs目录类权限,不要遗漏:

# 按实际AVC日志补全权限,示例包含目录和文件的访问权限
allow myapp_htgl sysfs:dir { read open getattr search };
allow myapp_htgl sysfs:file { read open getattr };

4. 编译验证

编译包含sepolicy的对应分区镜像(通常为boot或system分区),刷入设备后测试应用访问逻辑,通过adb logcat | grep avc抓取剩余拒绝日志按需补全权限即可。剩余2个应用按相同流程配置专属域、绑定包名、单独授权即可,禁止直接给platform_app全域配置sysfs的open类权限。


内容的提问来源于stack exchange,提问作者Yeayer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 03:42:17