You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

更新Android 9 SELinux策略解决系统应用OTA更新配置编译报错问题

错误根因

编译失败的核心原因是SELinux权限语法错误:remove_name是仅属于目录(dir类)的权限,用于控制是否允许从对应目录下删除文件/子目录条目,文件(file类)本身不存在该权限,你错误将其加到了cache_recovery_file:file的权限列表中,触发了checkpolicy的语法校验失败。

修正方案

1. 修正system_app.te中的错误配置

找到原配置中这两行:

allow system_app cache_recovery_file:dir { search write add_name remove_name };
allow system_app cache_recovery_file:file { create write open remove_name getattr setattr };

删除file类权限列表中的remove_name,如果需要支持删除uncrypt_file文件,补充file类的unlink权限即可,修正后如下:

# 允许system_app操作cache_recovery_file目录下的文件
allow system_app cache_recovery_file:dir { search write add_name remove_name };
allow system_app cache_recovery_file:file { create write open getattr setattr unlink };

2. 补充init域缺失的权限

你提供的avc日志中还有一条init域的dac_read_search权限拒绝,该权限需要加在init.te配置文件中,不要写到system_app.te里:

allow init self:capability dac_read_search;

3. 冗余配置清理

你当前的system_app.te里重复定义了两次allow system_app net_radio_prop:property_service { set };,可以删除其中一条避免冗余。

验证方法

修改完成后不需要全编译AOSP,可单独编译SEPolicy模块快速验证配置正确性,执行命令:

mmm external/sepolicy device/seco/imx6dq/sepolicy -j$(nproc)

如果编译无报错,再全编译固件即可。

内容的提问来源于stack exchange,提问作者Garry McKee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 19:45:04