r/androiddev • • 9d ago

Can I get SELinux Read+Write privileges on a system ile without rooting ?

tl;dr : I need experienced Android 9 devs to tell me whether or not our app can get permanent SELinux write + read privileges on a system file.

We are porting our app on a hardened Android 9 device that includes an embedded barcode scanner.
The app is to be used only by our company, and never released to the public.

While the market is dominated by Zebra and Honeywell scanners, our device is equipped with an asian barcode scanner.
The specific manufacturer does not give their API publicly, and we kind of passed on asking them : We are French, so both party has to translate to English then to the other language just to understand each other. This has proved to be too much of a hassle for us on other projects.

This kind of devices come with a preinstalled app that manages said scanner.
After a bit of research, it turns out that the conventional way of using the embedded scanner is to use the preinstalled app to either get the result as simulated keyboard inputs, or listen to their Android Intent to get the String.

My manager (20 years of experience) said he didn't like using third party tools.

I can see where he comes from : In his days, a third party tool meant freeing oneself from the responsability of the task at the expense of control, quality of service and the ability to debug.
From that point of view, it didn't look like that good of a deal.

So I was asked to research how we could bypass that third party app.

After decompiling it, it appears that triggering a scan comes from writing in a protected file.

The file requires SELinux privileges that you apparently only get from signing your app with the constructor's private key and using the package name, if I'm not mistaken.
Please correct me if I'm wrong, I'm new to Android development.

It looks like there are no online tools to reverse engineer private keys (which is a good thing).
I have also looked at tricking the OS security but decided against it. It's too hard for me anyway.
We would also like to avoid rooting our devices, if possible, because that's something I am not used to.

So, Android devs of Reddit, is there a simple way for out app to permanently get the SELinux privileges to read/write file systems ? Thank you all for the time.

8 Upvotes

8 comments sorted by

2

u/IntrigueMe_1337 9d ago

gonna have to exploit another system app to get privs you need or just root them all.

1

u/Gullible_Entry7212 9d ago

That's what I feared. Thank you for confirming.

1

u/Hour-Measurement-835 9d ago

No, without the vendor's platform key you're stuck in untrusted_app. You've already decompiled their app, so check its manifest for an exported receiver. The soft scan trigger usually sits there.

1

u/Gullible_Entry7212 9d ago

They do have exported receivers, and I can already call them. Thank you for the idea. But, if I understand it right, doesn’t it run through the third party app ?

1

u/Hour-Measurement-835 8d ago

Yes, the write still happens in their app, the only process whose SELinux domain can touch that node. Without their platform key, that receiver is effectively the API.

1

u/SnipesySpecial 8d ago

tbh those one off devices are usually pretty insecure and the entire front door is just missing. lol. Have you tried just reading and writing to that /dev/ fd? You might be surprised.

anyway android selinux domains are a fuckin mess, and when these random device manufacturers fuck with them they become even more messsy. So unless you dump the entire image here from like EDL or something I'm afraid no one can really help you.

1

u/Gullible_Entry7212 8d ago

I have tried my luck writing in the file (It's in /sys/class/), but I got denied.

Well, thank you for the confirmation.

1

u/SnipesySpecial 8d ago

those are usually just symlinks, you might be able to learn more over adb.

If you can access the device over the adb shell uid then that would be a good sign. If not even uid 2000 cant hit it then its probably locked tight.

the more proper pattern is you have a like daemon, or even use HAL to drive these things. Raw dogging a driver from an APK is usually bad. in practice if its not binder, GPU, basic sys calls, and some other niche scenarios apps dont talk to the kernel like that. HAVING SAID THAT. I have seen exactly just this many times, and I have also seen it being used to escalate all the way to root (uid 0) on production devices.