3 ms·
The isolation seems mostly defined by this SELinux policy: https://github.com/android/platform_system_core/blob/lollipop-mr1-release/rootdir/init.rc#L564 https:
by semenko 11y ago
The isolation seems mostly defined by this SELinux policy: https://github.com/android/platform_system_core/blob/lollipop-mr1-release/rootdir/init.rc#L564 https://github.com/android/platform_system_core/blob/lollipo...
service media /system/bin/mediaserver
class main
user media
group audio camera inet net_bt net_bt_admin net_bw_acct drmrpc mediadrm
ioprio rt 4
You'd need another exploit to elevate from SELinux (and I think send MSSes for a self-propagating worm). Though given Android's abysmal patching, most Android kernels are also terribly outdated...
- vezzy-fnord 11y agoThat's not an SELinux policy? That's just a service statement for Android's init, defining the process' supplementary groups. There is no explicit seclabel I can deduce.
- scintill76 11y agoThe policy is linked. The service definition was probably quoted to show other aspects of its isolation and privileges, but the comment is not written very clearly.
- semenko 11y agoWhoops, yep -- definitely wasn't that clear. As pointed out below, the policy is linked to: https://android.googlesource.com/platform/external/sepolicy/+/master/mediaserver.te https://android.googlesource.com/platform/external/sepolicy/...
- scintill76 11y agoI could have sworn I read in the OP a few minutes ago, that mediaserver runs as "system" on some devices, which would probably be worse. I'm not finding it now, so maybe it was edited or I'm mis-remembering. Anyway, vendor customization diverging from AOSP makes it hard to say.
- pacquiao882 11y agoYou are correct. It runs with system and graphics privileges on many devices. It is a native service started at system init and is automatically restarted if it crashes.