Decoupling sepolicy Development from AOSP: A Faster Workflow for Android Automotive
Imran Khan, Balasubramanian Achuthan, Gopinath Srinivasan, Arun Vasudevan · 2024
The automotive industry’s embrace of Android for in-vehicle infotainment and navigation systems necessitates robust security measures. SELinux (Security-Enhanced Linux), a mandatory access control (MAC) system integrated within the Android kernel, plays a critical role in achieving this objective. By enforcing granular security policies, SELinux restricts access to system resources and data for processes and applications, mitigating potential vulnerabilities and minimizing the impact of malicious software. However, developing and debugging se-policies within the traditional Android Open-Source Project (AOSP) environment presents a significant bottleneck for developers. The current process entails a tedious iterative process involving log collection, analysis of Access Violation Control (AVC) denials, policy modifications, rebuilding the system, flashing the updated image onto the target device, and finally, retesting functionality. This loop for each iteration significantly hinders development efficiency. This research delves into exploring alternative approaches to optimize se-policy development in the context of automotive Android. The focus lies on potentially decoupling the se-policy creation and testing. This decoupling has the potential to streamline the development workflow, leading to faster development cycles and improved developer productivity.