View Issue Details

IDProjectCategoryView StatusLast Update
0001714T99X171.00 SKB EagleSW Issuepublic2023-06-13 18:27
Reporter(ALTech) Younkwang Jung Assigned To(ALTech) Younkwang Jung Due Date2023-05-25 18:55
PriorityhighSeveritys4-minorReproducibilityalways
Status closedResolutionnot fixable 
Summary0001714: [Smart3][ATV10][ATV12] Request review of how to recover pairing information after downgrading to OS12->OS10
DescriptionHi Kerwin

Recently downgraded to OS12 -> OS10.
When downgraded, the data partition is initialized and the RCU pairing information disappears.
So it is observed that the VoC(RCU) is increased because the RCU pairing information disappears.

SKB wants to apply the solution to this case in advance because this could happen again in the future.
So SKB asked the three manufacturers(FXN/INTEK/INNOPIA) for implementation methods to solve this issue.

https://jira.skbroadband.com/browse/BPM-18626
SKB will decide on the implementation guidelines after checking the implementation methods.

The solution suggested by SKB is to back up the following two files(pairing info) on ATV12 and recover them on ATV10.
  /data/misc/bluedroid/bt_config.bak
  /data/misc/bluedroid/bt_config.conf

1) Please let me know where to back up and how to recover it.
   (Detailed explanation is required.)
2) Please let me know if there is a better way other than the above method.

Please let me know if you have any questions.

Thank you.
YK.Jung
TagsNo tags attached.
Attach Tags

Users monitoring this issue

User List (ALTech) JunGyu Kim , (ALTech) SY Yoon

Activities

(ALTech) Younkwang Jung

2023-05-11 16:12

developer   ~0013100

Hi Kerwin

SKB offers the following opinions.

1) OS12 (UI537)
   Backup Bluetooth pairing information using SOS remote commands
   (/data/misc/bluedroid → /btv_home/config/bluedroid)
   
   This behavior has permission issues and requires permission related modifications
   - Change group permissions for /data/misc/bluedroid directory|file to bluetooth → system
     You can change it in the init.rc (system/core/rootdir/init.rc) file.
     
     Need to fix related Sepolicy issue below
     ======================================================
     [ 73.597232] type=1400 audit(1683543143.540:480): avc: denied { read } for comm="sh" name="bluedroid" dev="mmcblk0p23" ino=144006 scontext=u:r:qsm_server:s0 tcontext=u:object_r:bluetooth_data_file:s0 tclass=dir permissive=0
     [ 73.614633] type=1400 audit(1683543143.540:480): avc: denied { read } for comm="sh" name="bluedroid" dev="mmcblk0p23" ino=144006 scontext=u:r:qsm_server:s0 tcontext=u:object_r:bluetooth_data_file:s0 tclass=dir permissive=0 [ 73.614666] type=1400 audit(1683543143.560:481): avc: denied { search } for comm="cp" name="bluedroid" dev="mmcblk0p23" ino=144006 scontext=u:r:qsm_server:s0 tcontext=u:object_r:bluetooth_data_file:s0 tclass=dir permissive=0
     [ 73.620125] init: Untracked pid 4199 exited with status 1
     [ 73.625967] type=1400 audit(1683543143.560:481): avc: denied { search } for comm="cp" name="bluedroid" dev="mmcblk0p23" ino=144006 scontext=u:r:qsm_server:s0 tcontext=u:object_r:bluetooth_data_file:s0 tclass=dir permissive=0
     [ 73.625995] type=1400 audit(1683543143.570:482): avc: denied { sys_ptrace } for comm="ps" capability=19 scontext=u:r:qsm_server:s0 tcontext=u:r:qsm_server:s0 tclass=capability permissive=0
     ======================================================

2) OS10 (UI536)
   if "/btv_home/config/blueroid" directory exists at boot time
         Restore Bluetooth pairing information ("/btv_home/config/bluedroid" → "/data/misc/bluedroid")
         remove "/btv_home/config/bluedroid"
      restart bluetooth server "killall com.android.bluetooth"
   
Please let me know if you have any other opinions.

Thank you.
YK.Jung

(ALTech) Younkwang Jung

2023-05-15 07:36

developer   ~0013112

Hi Kerwin

SKB is now asking for feedback on this function.
Please update your opinion after reviewing the contents.

In addition, please review the information about changing Bluetooth pairing Loading PATH from "/data/misc/bluedroid" to "/btv_home/config/bluedroid".
How to implement this change and what are the risks

Thank you
YK.Jung

(SW) Kerwin Chen

2023-05-15 09:39

developer   ~0013116

Hi YK,

1. Sepolicy issue on OS12
=> I think it should be modified by SPTEK. The rules should be the same for FXN/INTEK/INNOPIA models.
Based on our experience, there may be other 'avc denied' errors after you solve the first error.
Without test environment, we can't solve all errors by ourselves.

#============= qsm_server ==============
allow qsm_server bluetooth_data_file:dir { read search };
allow qsm_server self:capability sys_ptrace;

2. Restore BT pairing config files on OS10
=> Instead of killing "com.android.bluetooth", we think it is better to restart Bluetooth service.
But it needs time to check the relationship with BT stack.
We will update status on 5/17.

Thank you !

(ALTech) Younkwang Jung

2023-05-15 09:50

developer   ~0013118

Hi Kerwin

To explain the situation again
I'm not saying to implement this right now.
Various methods are under discussion.
I need a feedback on whether this opinion is good or bad or if there is another opinion.

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-05-17 15:16

developer   ~0013162

Hi Kerwin

Please update the progress.

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-05-18 08:27

developer   ~0013171

Hi Kerwin

Please update the progress.
I have to report to SKB

Thank you
YK.Jung

(SW) Kerwin Chen

2023-05-18 09:08

developer   ~0013172

Hi YK,

First, the format is a liitle dirrerent between ATV10 and atv12.
You can refer to attached picture to get details.
This means we may need to implement a function to translate the bt_config.conf file to make it work well.

Second, bt_config.conf will be generated after Bluetooth restarts.
We also need to modify this part.

Finally, Android may encrypt 'bt_config.conf' in the future to enhance security.
We have to not apply such kind of change.
But we can't make sure it is will be blocked by xTS test cases.

Thank you !
image.png (123,248 bytes)   
image.png (123,248 bytes)   

(ALTech) Younkwang Jung

2023-05-18 10:49

developer   ~0013176

Hi Kerwin

I'd like to get more details to actually implement this function.
Please tell us about ATV 12/ATV10's processing flow.
Other manufacturers are conducting implementation and testing with feedback from each manufacturer
But we still haven't offered an opinion on how to implement it

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-05-18 17:16

developer   ~0013181

Hi Kerwin

first , I would like to make a proposal to SKB like this.
========================================================================
[Bt paring information rule ]
1) When the user performs a factory default directly: Delete BT pared information
2) When the data structure in bt_config.conf is changed to a low version: Delete BT paired information
    - Need to manage version of bt_config.conf
      Additional consideration is required (*) on how to manage the file creation version
3) Keep BT paired information when data is automatically initialized
   - Data initialization when changing to a security low version: Keep BT pairing information
   - OS12 -> Maintaining when downgrading to OS10: Maintaining BT paring information
        => An example ) bt_config.conf file is created in OS 10 --> OS12 --> OS10
   - However, in the case of 2), Delete BT pared information due to a change in data structure

The point here is to manage the version of bt_config.conf.
====================================================================================

after the overall rule should be set , the details should be implemented.
so I'm going to update the details next time at JIRA

Please check and give me your opinion.

Thanks you
YK.Jung

(SW) Kerwin Chen

2023-05-19 09:23

developer   ~0013184

Hi YK,

I don't get your point very well.
To avoid misunderstanding, could you give a flow for the proposal ?
Thank you !

(ALTech) Younkwang Jung

2023-05-19 11:13

developer   ~0013185

Hi Kerwin

The meeting with SKB has just been completed.
One of the things discussed at the meeting was this task.

Currently, SKB is making an implementation flow for this function and will send it to us when it is completed.
(That is the method proposed by INTEK. )

Then you can proceed with the implementation flow as received from SKB

I will forward it to you when I receive the information.

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-05-22 07:34

developer   ~0013189

Hi Kerwin

SKB has not yet decided how to implement it.
Therefore, SKB requested to review whether it can be implemented as follows.
https://jira.skbroadband.com/browse/BPM-18627

- Implemented to maintain BT information only when downgrading to OS12 → OS10
- Modifications only apply to OS12
  (OS10 should not be changed)
- Do not move BT config to /btv_home/config/blueroid

* When updating FW to OS12-> OS10, is it possible to implement it in OS12 as below?
1) Backup BT config information
2) Data partition initialization complete
3) Recover backup data
4) Verify BT pairing information is maintained normally after update to OS10 is completed

if it is possible to implement, please proceed with the test
and let us know why it is impossible if it is impossible to implement
Please give me feedback by today.

And Please let me know if you have any questions.

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-05-22 12:36

developer   ~0013197

Hi Kerwin

Even if this task is not completely resolved, I should report the progress to SKB.
If it is impossible to implement it as it is, SKB and each manufacturers must find a different solution
So please update the progress every day.

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-05-30 08:21

developer   ~0013255

Hi Kerwin

SKB want to hear all three manufacturers' opinions on how to implement it because there may be differences in the implementation method of each manufacturer.
So SKB is asking us to check whether it can be implemented or not (About https://mantis.cnsbg.foxconn.com/vaas/view.php?id=1714#c13189 )

INTEK informed SKB that it is impossible to implement SKB's request.
(Failure occurred during the GoogleTest after implementation, so it cannot be implemented in that way.)

So please check whether it is possible or not to implement the above information on FXN as well.
- If it's impossible, we have to explain why it's impossible
- If it's possible, how can we implement it

Thank you
YK.Jung

(ALTech) Younkwang Jung

2023-06-07 08:18

developer   ~0013294

Hi Kerwin

Please update the progress.

Thank you
YK.Jung

(SW) Kerwin Chen

2023-06-07 09:44

developer   ~0013298

Hi YK,

After FXN internal discussion, there was a similar issue before which was needed to remove files in recovery mode.
(https://mantis.cnsbg.foxconn.com/vaas/view.php?id=1441#c9933)

At that time, we were blocked at SELINUX in recovery mode.
Therefore, we think it is also not possilbe to move files in recovery mode for this issue.

Thank you !

(ALTech) Younkwang Jung

2023-06-09 08:00

developer   ~0013322

Hi Kerwin

I can't report to SKB with this content.
It should be explained in detail.
That is , what did you do for this function and for some reason, the failure occurred, so this function is impossible

Please check this again.

FYI, I captured the contents of INTEK.
https://jira.skbroadband.com/browse/BPM-18627

Thank you
YK.Jung
image-2.png (116,172 bytes)   
image-2.png (116,172 bytes)   

(SW) Kerwin Chen

2023-06-09 16:39

developer   ~0013324

Hi YK,

Based on SKB's requirement, ATV10 should not be changed.
What we can modify is 'recovery on ATV12'.

In oder to add permission for recovery, we also add SELINUX rules in recovery.te.
The result is the same as Intek's.
It is blocked at 'never allows' limitation.

=========== build errors ===================================
16:28:10 ninja failed with: exit status 1
[ 95% 8741/9198] build out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows
FAILED: out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows
/bin/bash -c "(ASAN_OPTIONS=detect_leaks=0 out/host/linux-x86/bin/checkpolicy -M -c 30 -o out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows.tmp out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/policy.conf ) && (out/host/linux-x86/bin/sepolicy-analyze out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows.tmp neverallow -w -f out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/policy_2.conf || ( echo \"\" 1>&2; echo \"sepolicy-analyze failed. This is most likely due to the use\" 1>&2; echo \"of an expanded attribute in a neverallow assertion. Please fix\" 1>&2; echo \"the policy.\" 1>&2; exit 1 ) ) && (touch out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows.tmp ) && (mv out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows.tmp out/target/product/BFX-AT100/obj/FAKE/sepolicy_neverallows_intermediates/sepolicy_neverallows )"
libsepol.report_failure: neverallow on line 157 of system/sepolicy/public/recovery.te (or line 29668 of policy.conf) violated by allow recovery bluetooth_data_file:file { write append };
libsepol.check_assertions: 1 neverallow failures occurred
Error while expanding policy
[ 95% 8749/9198] build out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy
FAILED: out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy
/bin/bash -c "(ASAN_OPTIONS=detect_leaks=0 out/host/linux-x86/bin/checkpolicy -M -c 30 -o out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.tmp out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.recovery.conf ) && (out/host/linux-x86/bin/sepolicy-analyze out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.tmp permissive > out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.permissivedomains ) && (if [ \"userdebug\" = \"user\" -a -s out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.permissivedomains ]; then echo \"==========\" 1>&2; echo \"ERROR: permissive domains not allowed in user builds\" 1>&2; echo \"List of invalid domains:\" 1>&2; cat out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.permissivedomains 1>&2; exit 1; fi ) && (mv out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy.tmp out/target/product/BFX-AT100/obj/ETC/sepolicy.recovery_intermediates/sepolicy )"
libsepol.report_failure: neverallow on line 157 of system/sepolicy/public/recovery.te (or line 30217 of policy.conf) violated by allow recovery bluetooth_data_file:file { write append };
libsepol.check_assertions: 1 neverallow failures occurred
Error while expanding policy
ninja: build stopped: subcommand failed.

(ALTech) Younkwang Jung

2023-06-13 18:27

developer   ~0013361

Hi Kerwin

This JIRA issue was closed because it was impossible to implement.
I will close this ticket

Thank you
YK.Jung

Issue History

Date Modified Username Field Change
2023-05-08 17:59 (ALTech) Younkwang Jung New Issue
2023-05-08 17:59 (ALTech) Younkwang Jung Status new => assigned
2023-05-08 17:59 (ALTech) Younkwang Jung Assigned To => (SW) Kerwin Chen
2023-05-08 17:59 (ALTech) Younkwang Jung Issue Monitored: (ALTech) SY Yoon
2023-05-08 17:59 (ALTech) Younkwang Jung Issue Monitored: (ALTech) JunGyu Kim
2023-05-11 16:12 (ALTech) Younkwang Jung Note Added: 0013100
2023-05-15 07:36 (ALTech) Younkwang Jung Note Added: 0013112
2023-05-15 09:39 (SW) Kerwin Chen Note Added: 0013116
2023-05-15 09:50 (ALTech) Younkwang Jung Note Added: 0013118
2023-05-17 15:16 (ALTech) Younkwang Jung Note Added: 0013162
2023-05-18 08:27 (ALTech) Younkwang Jung Note Added: 0013171
2023-05-18 09:08 (SW) Kerwin Chen Note Added: 0013172
2023-05-18 09:08 (SW) Kerwin Chen File Added: image.png
2023-05-18 09:09 (SW) Kerwin Chen Assigned To (SW) Kerwin Chen => (ALTech) Younkwang Jung
2023-05-18 09:09 (SW) Kerwin Chen Status assigned => acknowledged
2023-05-18 10:49 (ALTech) Younkwang Jung Note Added: 0013176
2023-05-18 17:16 (ALTech) Younkwang Jung Note Added: 0013181
2023-05-19 09:23 (SW) Kerwin Chen Note Added: 0013184
2023-05-19 11:13 (ALTech) Younkwang Jung Note Added: 0013185
2023-05-22 07:34 (ALTech) Younkwang Jung Note Added: 0013189
2023-05-22 12:21 (ALTech) Younkwang Jung Assigned To (ALTech) Younkwang Jung =>
2023-05-22 12:30 (ALTech) Younkwang Jung Priority normal => high
2023-05-22 12:30 (ALTech) Younkwang Jung Due Date 2023-05-12 18:55 => 2023-05-25 18:55
2023-05-22 12:36 (ALTech) Younkwang Jung Note Added: 0013197
2023-05-30 08:21 (ALTech) Younkwang Jung Note Added: 0013255
2023-06-07 08:18 (ALTech) Younkwang Jung Note Added: 0013294
2023-06-07 09:44 (SW) Kerwin Chen Note Added: 0013298
2023-06-09 08:00 (ALTech) Younkwang Jung Note Added: 0013322
2023-06-09 08:00 (ALTech) Younkwang Jung File Added: image-2.png
2023-06-09 16:39 (SW) Kerwin Chen Note Added: 0013324
2023-06-13 18:27 (ALTech) Younkwang Jung Note Added: 0013361
2023-06-13 18:27 (ALTech) Younkwang Jung Assigned To => (ALTech) Younkwang Jung
2023-06-13 18:27 (ALTech) Younkwang Jung Status acknowledged => closed
2023-06-13 18:27 (ALTech) Younkwang Jung Resolution open => not fixable