View Issue Details

IDProjectCategoryView StatusLast Update
0001045T99X171.00 SKB EagleSW Issuepublic2021-12-23 16:32
Reporter(ALTech) Jason ParkAssigned To(ALTech) Jason ParkDue Date
PrioritynormalSeveritys2-severeReproducibilityhave not tried
Status closedResolutionfixed 
Summary0001045: [BFX_AT100] Please support DSCP.sh on BFX_AT100 OR BFX_UH200.
DescriptionHi kerwin.

we receive some request from SKB about QOS (DSCP 46).
SPtek also applied a method as below on BFX_AT100 of Andorid 10. so they guide a same method to TVstorm.
but tvstorm can't apply it don't find some folder for execute dscp.sh.

please support to make below folder (?)

/system/bin/iptables-wrapper-1.0
/system/bin/netutils-wrapper-1.0

according to Sptek's explanation, it don't have an authority to change iptables in Selinux enforcing status. it only have an authority in init and netd.
so for solving this item, iptables-wrapper-1.0 as hide strucetur is served from Andorid O.
iptables-wrapper is refer to netutil_wrapper 's link.

https://source.android.com/devices/architecture/hidl/network-stack?hl=en


below comment is SPtek guide to TVstorm.
-----------------------------------------------------------------------------------------------------------------------------
dscp.sh
#!/vendor/bin/sh

if [ -f /btv_home/config/dscp46_server_list ]; then
           while read line
           do
                     /system/bin/iptables-wrapper-1.0 -w -t mangle -A oem_mangle_post -d $line -j DSCP --set-dscp 46
           done < /btv_home/config/dscp46_server_list

    /system/bin/iptables-wrapper-1.0 -w 5 -A oem_mangle_post -t mangle -p tcp --dport 6060 -j DSCP --set-dscp 46
           /system/bin/iptables-wrapper-1.0 -w 5 -A oem_mangle_post -t mangle -p tcp --dport 30606 -j DSCP --set-dscp 46
           /system/bin/iptables-wrapper-1.0 -w 5 -A oem_mangle_post -t mangle -p tcp --dport 30607 -j DSCP --set-dscp 46
fi

setprop vendor.skb.dscp.completed 1

dscp46.te
#============= dscp46 ==============
type dscp46, domain;
type dscp46_exec, exec_type, vendor_file_type, file_type;

# domain macros
init_daemon_domain(dscp46)
domain_auto_trans(dscp46, netutils_wrapper_exec, netutils_wrapper)

allow dscp46 btv_home_file:dir *;
allow dscp46 btv_home_file:file { ioctl read write open create getattr setattr lock relabelfrom relabelto append unlink link rename quotaon mounton };
allow dscp46 btv_home_file:filesystem *;
allow dscp46 btv_home_file:fd *;
allow dscp46 btv_home_file:fifo_file { create open read write append unlink getattr setattr rename ioctl rw_file_perms };
allow dscp46 btv_home_file:lnk_file { create open read write append link unlink getattr setattr rename ioctl relabelfrom relabelto };
allow dscp46 btv_home_file:process *;

allow dscp46 vendor_shell_exec:file rx_file_perms;
allow dscp46 vendor_toolbox_exec:file rx_file_perms;
allow dscp46 sysfs:file { open read };
allow dscp46 sysfs_net:dir search;
allow dscp46 vendor_file:file execute_no_trans;

netutils_wrapper.te
#============= netutils_wrapper ==============
allow netutils_wrapper btv_home_file:dir *;
allow netutils_wrapper btv_home_file:file { ioctl read write open create getattr setattr lock relabelfrom relabelto append unlink link rename quotaon mounton };
allow netutils_wrapper btv_home_file:filesystem *;
allow netutils_wrapper btv_home_file:fd *;
allow netutils_wrapper btv_home_file:fifo_file { create open read write append unlink getattr setattr rename ioctl rw_file_perms };
allow netutils_wrapper btv_home_file:lnk_file { create open read write append link unlink getattr setattr rename ioctl relabelfrom relabelto };
allow netutils_wrapper btv_home_file:process *;

allow netutils_wrapper dscp46:fd { use };
allow netutils_wrapper node:udp_socket { node_bind };
allow netutils_wrapper dnsproxyd_socket:sock_file { write };
allow netutils_wrapper port:udp_socket { name_bind };
allow netutils_wrapper netd:unix_stream_socket { connectto read write};

file_context
/vendor/bin/dscp.sh u:object_r:dscp46_exec:s0

after boot completed, it is proceed to do dscp.sh.
if don't receive Network, it happen neverallow denied of hostname.
so when up eth0, and after receiving IP, It have to set a rule or have to set it after succeed for checkNetwork
Boot completed 이후 dscp.sh 가 동작하도록 처리

init.skb.rc
on property:vendor.skb.dscp.run=1
    start dscp

service dscp /vendor/bin/dscp.sh
    class core
   disabled
    oneshot









TagsNo tags attached.
Attach Tags

Users monitoring this issue

User List There are no users monitoring this issue.

Activities

(SW) Kerwin Chen

2020-12-09 09:07

developer   ~0005361

Hi Jason,

We can support to include "netutils-wrapper-1.0" on BFX_UH200 Android P.
The rest DSCP configurations will be done by TVStorm, right ?
Please help to confirm it.
Thanks!

(ALTech) Jason Park

2020-12-09 09:34

developer   ~0005365

hi kerwin

if we create it , TVstorm will try to execute dscp.sh via /system/bin/iptables-wrapper-1.0 , /system/bin/netutils-wrapper-1.0.
you only create two folder(?) or only /system/bin/netutils-wrapper-1.0 ? if create it, where branch can do it ?
please let me know it.

(SW) Kerwin Chen

2020-12-09 09:43

developer   ~0005366

Hi Jason,

We plan to work on new UI522 AOSP branch.
Please ask SKB to create new branch so that we can start to work on this feature.
Thanks!

(ALTech) Jason Park

2020-12-15 12:41

developer   ~0005464

hi kerwin

please merge to UI522 AOSP branch about this issue.

(SW) Kerwin Chen

2020-12-15 14:11

developer   ~0005466

Hi Jason,

It is already included on UI522 branch by yesterday.

(ALTech) Jason Park

2021-01-05 09:54

developer   ~0005697

hi kerwin.

per talking.. tvsorm want to support to make dscp.sh. please let me know you can support this.

below comment is SPtek guide to TVstorm.
 -----------------------------------------------------------------------------------------------------------------------------
 dscp.sh

(SW) Kerwin Chen

2021-01-05 10:10

developer   ~0005699

Hi Jason,

We can support to commit "dscp.sh" file from Smart3 BTF project.
However, you can see there are several "*.te" and "file_context" files to solve SELinux policy violation issues.
The SELinux rule violations happens only when system execute commands.
So I think it should be handled by caller (TVStorm's program).
Please clarity the responsibility.
Thanks !

(ALTech) Jason Park

2021-01-05 11:13

developer   ~0005703

Last edited: 2021-01-05 13:02

hi kerwin.

you mean is dscp.sh , dscp46.te, netutils_wrapper.te , file_context.. after bring those from BTF project, input it in UHD4.
What is a problem ?
Please bring it first. and commit to UHD4 bitbucket.
please refer to an attached mail. you can see guide from SPTK.

(SW) Kerwin Chen

2021-01-05 15:00

developer   ~0005713

Hi Jason,

Current, we can't build image due to SELinux policy violations.
The errors happen after I add "dscp.te" file.
You can refer to attached log.

BTW, I think there will be other errors while executing the script.
dscp_build_error.txt (7,016 bytes)   
FAILED: out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy 
/bin/bash -c "(ASAN_OPTIONS=detect_leaks=0 out/host/linux-x86/bin/checkpolicy -M -c 		30 -o out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.tmp out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.recovery.conf ) && (out/host/linux-x86/bin/sepolicy-analyze out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.tmp permissive > out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.permissivedomains ) && (if [ \"userdebug\" = \"user\" -a -s out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.permissivedomains ]; then 		echo \"==========\" 1>&2; 		echo \"ERROR: permissive domains not allowed in user builds\" 1>&2; 		echo \"List of invalid domains:\" 1>&2; 		cat out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.permissivedomains 1>&2; 	exit 1; 		fi ) && (mv out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.tmp out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy )"
libsepol.report_failure: neverallow on line 63 of vendor/tvstorm/sepolicy/crash_dump.te (or line 48279 of policy.conf) violated by allow dscp46 btv_home_file:process { fork transition sigchld sigkill sigstop signull signal ptrace getsched setsched getsession getpgid setpgid getcap setcap share getattr setexec setfscreate noatsecure siginh setrlimit rlimitinh dyntransition setcurrent execmem execstack execheap setkeycreate setsockcreate getrlimit };
libsepol.report_failure: neverallow on line 59 of vendor/tvstorm/sepolicy/crash_dump.te (or line 48201 of policy.conf) violated by allow dscp46 btv_home_file:lnk_file { ioctl read write create getattr setattr relabelfrom relabelto append unlink link rename open };
libsepol.report_failure: neverallow on line 55 of vendor/tvstorm/sepolicy/crash_dump.te (or line 48123 of policy.conf) violated by allow dscp46 btv_home_file:fifo_file { ioctl read write create getattr setattr lock append map unlink rename open };
libsepol.report_failure: neverallow on line 51 of vendor/tvstorm/sepolicy/crash_dump.te (or line 48045 of policy.conf) violated by allow dscp46 btv_home_file:filesystem { mount remount unmount getattr relabelfrom relabelto associate quotamod quotaget };
libsepol.report_failure: neverallow on line 47 of vendor/tvstorm/sepolicy/crash_dump.te (or line 47967 of policy.conf) violated by allow dscp46 btv_home_file:file { ioctl read write create getattr setattr lock relabelfrom relabelto append unlink link rename quotaon mounton open };
libsepol.report_failure: neverallow on line 43 of vendor/tvstorm/sepolicy/crash_dump.te (or line 47889 of policy.conf) violated by allow dscp46 btv_home_file:dir { ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton add_name remove_name reparent search rmdir open audit_access execmod };
libsepol.check_assertions: 6 neverallow failures occurred
Error while expanding policy
out/host/linux-x86/bin/checkpolicy:  loading policy configuration from out/target/product/BFX-UH200/obj/ETC/sepolicy.recovery_intermediates/sepolicy.recovery.conf
[ 73% 2886/3945] build out/target/product/BFX-UH200/obj/ETC/sepolicy_neverallows_intermediates/sepolicy_neverallows
FAILED: out/target/product/BFX-UH200/obj/ETC/sepolicy_neverallows_intermediates/sepolicy_neverallows 
/bin/bash -c "(rm -f out/target/product/BFX-UH200/obj/ETC/sepolicy_neverallows_intermediates/sepolicy_neverallows ) && (ASAN_OPTIONS=detect_leaks=0 out/host/linux-x86/bin/checkpolicy -M -c 		30 -o out/target/product/BFX-UH200/obj/ETC/sepolicy_neverallows_intermediates/sepolicy_neverallows out/target/product/BFX-UH200/obj/ETC/sepolicy_neverallows_intermediates/policy.conf )"
libsepol.report_failure: neverallow on line 63 of vendor/tvstorm/sepolicy/crash_dump.te (or line 46383 of policy.conf) violated by allow dscp46 btv_home_file:process { fork transition sigchld sigkill sigstop signull signal ptrace getsched setsched getsession getpgid setpgid getcap setcap share getattr setexec setfscreate noatsecure siginh setrlimit rlimitinh dyntransition setcurrent execmem execstack execheap setkeycreate setsockcreate getrlimit };
libsepol.report_failure: neverallow on line 59 of vendor/tvstorm/sepolicy/crash_dump.te (or line 46305 of policy.conf) violated by allow dscp46 btv_home_file:lnk_file { ioctl read write create getattr setattr relabelfrom relabelto append unlink link rename open };
libsepol.report_failure: neverallow on line 55 of vendor/tvstorm/sepolicy/crash_dump.te (or line 46227 of policy.conf) violated by allow dscp46 btv_home_file:fifo_file { ioctl read write create getattr setattr lock append map unlink rename open };
libsepol.report_failure: neverallow on line 51 of vendor/tvstorm/sepolicy/crash_dump.te (or line 46149 of policy.conf) violated by allow dscp46 btv_home_file:filesystem { mount remount unmount getattr relabelfrom relabelto associate quotamod quotaget };
libsepol.report_failure: neverallow on line 47 of vendor/tvstorm/sepolicy/crash_dump.te (or line 46071 of policy.conf) violated by allow dscp46 btv_home_file:file { ioctl read write create getattr setattr lock relabelfrom relabelto append unlink link rename quotaon mounton open };
libsepol.report_failure: neverallow on line 43 of vendor/tvstorm/sepolicy/crash_dump.te (or line 45993 of policy.conf) violated by allow dscp46 btv_home_file:dir { ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton add_name remove_name reparent search rmdir open audit_access execmod };
libsepol.report_failure: neverallow on line 866 of system/sepolicy/public/domain.te (or line 10984 of policy.conf) violated by allow dscp46 btv_home_file:dir { ioctl read write create getattr setattr lock relabelfrom relabelto append map unlink link rename execute quotaon mounton add_name remove_name reparent search rmdir open audit_access execmod };
libsepol.report_failure: neverallow on line 839 of system/sepolicy/public/domain.te (or line 10933 of policy.conf) violated by allow dscp46 btv_home_file:file { create setattr lock relabelfrom relabelto unlink link rename quotaon mounton open };
libsepol.report_failure: neverallow on line 839 of system/sepolicy/public/domain.te (or line 10933 of policy.conf) violated by allow dscp46 btv_home_file:fifo_file { create setattr lock map unlink rename open };
libsepol.report_failure: neverallow on line 839 of system/sepolicy/public/domain.te (or line 10933 of policy.conf) violated by allow dscp46 btv_home_file:lnk_file { create setattr relabelfrom relabelto unlink link rename open };
libsepol.check_assertions: 10 neverallow failures occurred
Error while expanding policy
out/host/linux-x86/bin/checkpolicy:  loading policy configuration from out/target/product/BFX-UH200/obj/ETC/sepolicy_neverallows_intermediates/policy.conf
dscp_build_error.txt (7,016 bytes)   

(ALTech) Jason Park

2021-01-05 15:23

developer   ~0005715

hi kerwin

it is noted.. now we have a meeting with skb manager.. so I reported your suffering to him.
so he will receive some guide from SPtek. and skb manager will confirm who has an owner ship about this item. assign to tvstorm or fxn..

(ALTech) Jason Park

2021-01-07 13:29

developer   ~0005749

hi kerwin

as your explanation, TVStomrm will investigate about selinux issue. however, an owner of this issue is FXN. This is assigned by SKB manager.
please see a guide from SPtek's . tvstorm only is checking regarding selinux problem as below.
so we need to solve this issue. UHD4 BMT is on going to do now. so this issue also need to solve it soon.
if need it, we need to open via mail with TVstorm. if need it, please send a mail to me . I will connect with TVstom guy.

-------------------------------------
To Tvstorm
Netutils-wrapper is based on HIDL, It only is worked on Vendor. this script can't include system. (/system/bin) --> as see an attached file, tvstorm try to execute in system.
please .sh have to include /vendor/bin. and property also have to use for vendor property


To Fxn.

the build error on 5713 is related to an authority of BTV_HOME . it need for reading dscp46_server_list from /btv_home/config.

allow dscp46 btv_home_file:dir *;
allow dscp46 btv_home_file:file { ioctl read write open create getattr setattr lock relabelfrom relabelto append unlink link rename quotaon mounton };
allow dscp46 btv_home_file:filesystem *;
allow dscp46 btv_home_file:fd *;
allow dscp46 btv_home_file:fifo_file { create open read write append unlink getattr setattr rename ioctl rw_file_perms };
allow dscp46 btv_home_file:lnk_file { create open read write append link unlink getattr setattr rename ioctl relabelfrom relabelto };
allow dscp46 btv_home_file:process *;
allow dscp46 btv_home_file:dir *;
allow dscp46 btv_home_file:file { ioctl read write open create getattr setattr lock relabelfrom relabelto append unlink link rename quotaon mounton };
allow dscp46 btv_home_file:filesystem *;
allow dscp46 btv_home_file:fd *;
allow dscp46 btv_home_file:fifo_file { create open read write append unlink getattr setattr rename ioctl rw_file_perms };
allow dscp46 btv_home_file:lnk_file { create open read write append link unlink getattr setattr rename ioctl relabelfrom relabelto };
allow dscp46 btv_home_file:process *;

when access to btv_home_file,, it happen nevelallow… it maybe it is setting as neverallow of btv_home in domain.te.
so it guess tvstom have to solve for this authority.
tvstorm_execute.png (6,725 bytes)   
tvstorm_execute.png (6,725 bytes)   

(ALTech) Jason Park

2021-01-08 10:35

developer   ~0005756

hi kerwin.

tvstorm fixed regarding selinux issue. but still don't work for descp.sh.
please check it.

(ALTech) Jason Park

2021-01-11 10:58

developer   ~0005800

hi kerwin
we have to change fw during UHD4 BMT.
a current schedule is finished at 1/15. so please support it as early.

(ALTech) Jason Park

2021-01-12 08:58

developer   ~0005815

hi kewin

please update your target date .

(SW) Kerwin Chen

2021-01-12 11:24

developer   ~0005820

Hi Jason,

I add DSCP kernel config this morning and commit to BitBucket already.
However, there still SELinux rules denied while running dscp.sh script.
Please ask TVStorm to fix it and try if it is ok or not.
Thanks !

(ALTech) Jason Park

2021-01-13 09:57

developer   ~0005832

HI Kerwin

although I saw your comment on skb jira, I don't catch a current status.
please let me know when does we finish it. as talked before, we have to inform our target date to skb manager for changing New fw for BMT.

(SW) Kerwin Chen

2021-01-13 14:04

developer   ~0005836

Hi Jason,

I don't know who should run 'dscp' service after STB is boot completedly.
Current, there are no rules added even 'sys.boot_completed' is set to 1.
TVStorm says once the property is set to 1, IPTABLE rules will be added.
But the result is not.

I need to set 'vendor.skb.dscp.run' to 1 to make IPTABLE rules being added.
Please discuss it with TVStorm or SKB manager.

P.S. You can use v17.522.06 to verify the result.
IPTABLE rules can be listed by "iptables -t mangle -L" command.

Thanks !

(ALTech) Jason Park

2021-01-20 10:41

developer   ~0005911

hi kerwin

I checked with using "iptables -t mangle -L" command. it is similar to Smart3 in android q.
but we need to check whether if it is working or not via SKB BMT.

Issue History

Date Modified Username Field Change
2020-12-07 15:21 (ALTech) Jason Park New Issue
2020-12-07 15:23 (ALTech) Jason Park Status new => assigned
2020-12-07 15:23 (ALTech) Jason Park Description Updated
2020-12-07 15:23 (ALTech) Jason Park Assigned To => (SW) Kerwin Chen
2020-12-07 15:23 (ALTech) Jason Park Status assigned => new
2020-12-07 15:23 (ALTech) Jason Park Status new => assigned
2020-12-09 09:07 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2020-12-09 09:07 (SW) Kerwin Chen Status assigned => feedback
2020-12-09 09:07 (SW) Kerwin Chen Note Added: 0005361
2020-12-09 09:34 (ALTech) Jason Park Note Added: 0005365
2020-12-09 09:34 (ALTech) Jason Park Assigned To (ALTech) Jason Park => (SW) Kerwin Chen
2020-12-09 09:34 (ALTech) Jason Park Status feedback => assigned
2020-12-09 09:43 (SW) Kerwin Chen Note Added: 0005366
2020-12-09 09:43 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2020-12-09 09:43 (SW) Kerwin Chen Status assigned => feedback
2020-12-15 12:41 (ALTech) Jason Park Note Added: 0005464
2020-12-15 14:00 (ALTech) Jason Park Assigned To (ALTech) Jason Park => (SW) Kerwin Chen
2020-12-15 14:00 (ALTech) Jason Park Status feedback => assigned
2020-12-15 14:11 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2020-12-15 14:11 (SW) Kerwin Chen Status assigned => confirmed
2020-12-15 14:11 (SW) Kerwin Chen Note Added: 0005466
2021-01-05 09:54 (ALTech) Jason Park Note Added: 0005697
2021-01-05 09:54 (ALTech) Jason Park Assigned To (ALTech) Jason Park => (SW) Kerwin Chen
2021-01-05 09:54 (ALTech) Jason Park Status confirmed => assigned
2021-01-05 10:10 (SW) Kerwin Chen Note Added: 0005699
2021-01-05 10:10 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2021-01-05 10:10 (SW) Kerwin Chen Status assigned => feedback
2021-01-05 11:13 (ALTech) Jason Park File Added: RE dscp apply guide in Android p .msg
2021-01-05 11:13 (ALTech) Jason Park Note Added: 0005703
2021-01-05 11:13 (ALTech) Jason Park Assigned To (ALTech) Jason Park => (SW) Kerwin Chen
2021-01-05 11:13 (ALTech) Jason Park Status feedback => assigned
2021-01-05 11:19 (ALTech) Jason Park Note Edited: 0005703
2021-01-05 13:02 (ALTech) Jason Park Note Edited: 0005703
2021-01-05 15:00 (SW) Kerwin Chen File Added: dscp_build_error.txt
2021-01-05 15:00 (SW) Kerwin Chen Note Added: 0005713
2021-01-05 15:01 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2021-01-05 15:01 (SW) Kerwin Chen Status assigned => feedback
2021-01-05 15:23 (ALTech) Jason Park Note Added: 0005715
2021-01-07 13:29 (ALTech) Jason Park File Added: tvstorm_execute.png
2021-01-07 13:29 (ALTech) Jason Park Note Added: 0005749
2021-01-07 13:29 (ALTech) Jason Park Assigned To (ALTech) Jason Park => (SW) Kerwin Chen
2021-01-07 13:29 (ALTech) Jason Park Status feedback => assigned
2021-01-08 10:35 (ALTech) Jason Park Note Added: 0005756
2021-01-11 10:58 (ALTech) Jason Park Note Added: 0005800
2021-01-12 08:58 (ALTech) Jason Park Note Added: 0005815
2021-01-12 11:24 (SW) Kerwin Chen Note Added: 0005820
2021-01-12 11:24 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2021-01-12 11:24 (SW) Kerwin Chen Status assigned => feedback
2021-01-13 09:57 (ALTech) Jason Park Note Added: 0005832
2021-01-13 09:57 (ALTech) Jason Park Assigned To (ALTech) Jason Park => (SW) Kerwin Chen
2021-01-13 09:57 (ALTech) Jason Park Status feedback => assigned
2021-01-13 14:04 (SW) Kerwin Chen Note Added: 0005836
2021-01-13 14:04 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Jason Park
2021-01-13 14:04 (SW) Kerwin Chen Status assigned => feedback
2021-01-20 10:41 (ALTech) Jason Park Note Added: 0005911
2021-12-23 16:32 (SW) Jacky Chiang Status feedback => closed
2021-12-23 16:32 (SW) Jacky Chiang Resolution open => fixed