From 1919000c897ccf0f88a5584faf3a2efc1a7a3c30 Mon Sep 17 00:00:00 2001 From: Sebastien RAILLET Date: Wed, 22 Sep 2021 16:54:31 +0200 Subject: dlt-daemon: create sockets using "android way" * Before this commit, dlt-daemon sockets were created inside /data/local/tmp. This works but have many drawbacks: - /data/local/tmp isn't always a tmpfs depending of the android system you have. Means sockets are potentially created on a filesystem which binds to a real device - as the sockets are created by the dlt-daemon itself, this prevent the usage of specific SELinux labels / contexts as they will inherit the label / context from its parent location (e.g the ones from /data/local/tmp). This prevent a fine control of the SELinux label / context that you would like to apply on them * This commit adapts the dlt-daemon in such way: - application and control sockets are now created inside /dev/socket which is the standard path for sockets on android - these sockets are now created by init (see dlt-daemon.rc) and their fds are recovered by dlt-daemon through a specific android API (dlt_daemon_unix_android_get_socket). If the fds can't be recovered, we fallback to the previous mechanism by creating by ourself the sockets (even if this will prevent SELinux label / context on this socket) - all these modifications have been put under compilation flag for android Signed-off-by: Sebastien RAILLET --- src/daemon/dlt-daemon.rc | 2 ++ 1 file changed, 2 insertions(+) (limited to 'src/daemon/dlt-daemon.rc') diff --git a/src/daemon/dlt-daemon.rc b/src/daemon/dlt-daemon.rc index c4e3884..6491081 100644 --- a/src/daemon/dlt-daemon.rc +++ b/src/daemon/dlt-daemon.rc @@ -2,4 +2,6 @@ service dlt-daemon /vendor/bin/dlt-daemon class late_start user root group root + socket dlt stream 666 root root + socket dlt-ctrl.sock stream 660 root root disabled -- cgit v1.2.1