AnsweredAssumed Answered

selinux denies the /system/bin/sh permission

Question asked by verma on Feb 19, 2018
Latest reply on Apr 21, 2018 by shalan yang

Hi,

 

I am booting AndroidN7.1.2 freescale release on sabrsd board.
If I am flashing the build binaries(boot-imx6q.img etc.) using "fsl-sdcard-partition.sh". I am successfully getting the console.

 

I have partitioned my sd-card as below to use the "uImage" and "uramdisk":
mmcblk2: p1 p2 p3 < p5 p6 p7 p8 > p4

where p1(boot vfat),p2(recovery vfat), p4(data ext4) are primary partitions
& p5(system), p6(cache), p7(device), p8(misc) are logical ext4 paritions.

But I am failing to get the console as permission is denied "init: cannot execve('/system/bin/sh'): Permission denied".


content of fstab.freescale file is below:
==============================================
/devices/soc0/soc.1/2100000.aips-bus/219c000.usdhc/mmc_host /mnt/media_rw/extsd vfat defaults voldmanaged=extsd:auto
/devices/soc0/soc.1/2100000.aips-bus/2184200.usb/ci_hdrc.1 /mnt/media_rw/udisk vfat defaults voldmanaged=udisk:auto

/dev/block/mmcblk2p5 /system ext4 ro,barrier=1 wait
/dev/block/mmcblk2p4 /data ext4 nosuid,nodev,nodiratime,noatime,nomblk_io_submit,noauto_da_alloc,errors=panic wait,encryptable=/dev/block/mmcblk2p9
/dev/block/mmcblk2p6 /cache ext4 nosuid,nodev,nomblk_io_submit wait
/dev/block/mmcblk2p7 /device ext4 ro,nosuid,nodev wait
/dev/block/mmcblk2p1 /boot vfat defaults defaults
/dev/block/mmcblk2p2 /recovery vfat defaults defaults
/dev/block/mmcblk2p8 /misc emmc defaults defaults


log:
=====
init: init first stage started!
SELinux: Permission validate_trans in class security not defined in policy.
SELinux: Class cap_userns not defined in policy.
SELinux: Class cap2_userns not defined in policy.
SELinux: the above unknown classes and permissions will be denied
audit: type=1403 audit(67.630:2): policy loaded auid=4294967295 ses=4294967295
audit: type=1404 audit(67.640:3): enforcing=1 old_enforcing=0 auid=4294967295 ses=4294967295
init: (Initializing SELinux enforcing took 0.18s.)
init: init second stage started!
init: Running restorecon...
init: waitpid failed: No child processes
init: (Loading properties from /default.prop took 0.00s.)
init: (Parsing /init.environ.rc took 0.00s.)
init: (Parsing /init.usb.rc took 0.00s.)
init: (Parsing init.freescale.usb.rc took 0.00s.)
init: (Parsing init.freescale.i.MX6Q.rc took 0.00s.)
init: (Parsing init.freescale.sd.rc took 0.00s.)
init: (Parsing /init.freescale.rc took 0.02s.)
ueventd: ueventd started!
ueventd: Coldboot took 0.35s.
Console: switching to colour dummy device 80x30
watchdogd: started (interval 10, margin 20)!
EXT4-fs (mmcblk2p5): mounted filesystem with ordered data mode. Opts: barrier=1
EXT4-fs (mmcblk2p4): Ignoring removed nomblk_io_submit option
EXT4-fs (mmcblk2p4): recovery complete
EXT4-fs (mmcblk2p4): mounted filesystem with ordered data mode. Opts: nomblk_io_submit,noauto_da_alloc,errors=panic
EXT4-fs (mmcblk2p6): Ignoring removed nomblk_io_submit option
EXT4-fs (mmcblk2p6): recovery complete
EXT4-fs (mmcblk2p6): mounted filesystem with ordered data mode. Opts: nomblk_io_submit
EXT4-fs (mmcblk2p7): mounted filesystem with ordered data mode. Opts: (null)
FAT-fs (mmcblk2p1): Volume was not properly unmounted. Some data may be corrupt. Please run fsck.
file system registered
using random self ethernet address
using random host ethernet address
audit: type=1400 audit(68.530:4): avc: denied { execute } for pid=235 comm="init" name="vdc" dev="mmcblk2p5" ino=397 scontext=u:r:i
nit:s0 tcontext=u:object_r:unlabeled:s0 tclass=file permissive=0
rfkill: BT RF going to : off
binder: 236:236 transaction failed 29189, size 0-0
audit: type=1400 audit(68.580:5): avc: denied { execute } for pid=237 comm="init" name="sh" dev="mmcblk2p5" ino=254 scontext=u:r:in
it:s0 tcontext=u:object_r:unlabeled:s0 tclass=file permissive=0
audit: type=1400 audit(68.620:6): avc: denied { execute } for pid=239 comm="init" name="magd" dev="mmcblk2p5" ino=149 scontext=u:r:
init:s0 tcontext=u:object_r:unlabeled:s0 tclass=file permissive=0
read descriptors
read strings
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
init: Starting service 'console'...
audit: type=1400 audit(73.660:7): avc: denied { execute } for pid=243 comm="init" name="sh" dev="mmcblk2p5" ino=254 scontext=u:r:in
it:s0 tcontext=u:object_r:unlabeled:s0 tclass=file permissive=0
init: cannot execve('/system/bin/sh'): Permission denied
init: Service 'console' (pid 243) exited with status 127
init: Service 'console' (pid 243) killing any children in process group
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0
binder: 236:236 transaction failed 29189, size 0-0

 

Please help me.

 

thanks,

Praveen

Outcomes