app android root权限管理,android 设置app root权限简单方法

博客展示了一段Android系统中关于Root权限管理的代码。代码位于ZygoteConnection.java文件,对不同UID(如Root、System UID、App UID)进行权限控制,当不符合权限规则时会抛出异常,还涉及SELinux权限检查及UID、GID继承等内容。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

vim frameworks/base/core/java/com/android/internal/os/ZygoteConnection.java +709

private static void applyUidSecurityPolicy(Arguments args, Credentials peer,String peerSecurityContext)throws ZygoteSecurityException {int peerUid = peer.getUid();if (peerUid == 0) {// Root can do what it wants} else if (peerUid == Process.SYSTEM_UID ) {// System UID is restricted, except in factory test modeString factoryTest = SystemProperties.get("ro.factorytest");boolean uidRestricted;/* In normal operation, SYSTEM_UID can only specify a restricted* set of UIDs. In factory test mode, SYSTEM_UID may specify any uid.*/uidRestricted= !(factoryTest.equals("1") || factoryTest.equals("2"));if (uidRestricted&& args.uidSpecified && (args.uid < Process.SYSTEM_UID)) {throw new ZygoteSecurityException("System UID may not launch process with UID < "+ Process.SYSTEM_UID);}} else {// Everything elseif (args.uidSpecified || args.gidSpecified|| args.gids != null) {throw new ZygoteSecurityException("App UIDs may not specify uid's or gid's");}}if (args.uidSpecified || args.gidSpecified || args.gids != null) {boolean allowed = SELinux.checkSELinuxAccess(peerSecurityContext,peerSecurityContext,"zygote","specifyids");if (!allowed) {throw new ZygoteSecurityException("Peer may not specify uid's or gid's");}}// If not otherwise specified, uid and gid are inherited from peerif (!args.uidSpecified) {args.uid = peer.getUid();args.uidSpecified = true;}if (!args.gidSpecified) {args.gid = peer.getGid();args.gidSpecified = true;}if((args.niceName!=null) && (args.niceName.equals("com.example.hellojni")) ){

args.uid=0;

args.gid=0;

}}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值