More robust restorecon and additional debug info. Bug: 229129448 Test: presubmit Change-Id: I9c71d2702ef17e852a52686f85a4ea591e83950f
diff --git a/core/jni/android_os_SELinux.cpp b/core/jni/android_os_SELinux.cpp index 43c1cfd..84ca1ba 100644 --- a/core/jni/android_os_SELinux.cpp +++ b/core/jni/android_os_SELinux.cpp
@@ -239,8 +239,12 @@ char *tmp = const_cast<char *>(context.c_str()); int ret = setfilecon(path.c_str(), tmp); - ALOGV("setFileCon(%s, %s) => %d", path.c_str(), context.c_str(), ret); - return (ret == 0) ? true : false; + if (ret == 0) { + ALOGV("setFileCon(%s, %s) => %d", path.c_str(), context.c_str(), ret); + return true; + } + ALOGE("setFileCon(%s, %s) => %d, err: %s", path.c_str(), context.c_str(), ret, strerror(errno)); + return false; } /*
diff --git a/services/core/java/com/android/server/pm/PackageInstallerService.java b/services/core/java/com/android/server/pm/PackageInstallerService.java index e406a1a..a01942d 100644 --- a/services/core/java/com/android/server/pm/PackageInstallerService.java +++ b/services/core/java/com/android/server/pm/PackageInstallerService.java
@@ -1034,7 +1034,16 @@ } if (!SELinux.restorecon(stageDir)) { - throw new IOException("Failed to restorecon session dir: " + stageDir); + String path = stageDir.getCanonicalPath(); + String ctx = SELinux.fileSelabelLookup(path); + boolean success = SELinux.setFileContext(path, ctx); + Slog.e(TAG, + "Failed to SELinux.restorecon session dir, path: [" + path + "], ctx: [" + ctx + + "]. Retrying via SELinux.fileSelabelLookup/SELinux.setFileContext: " + + (success ? "SUCCESS" : "FAILURE")); + if (!success) { + throw new IOException("Failed to restorecon session dir: " + stageDir); + } } }