I am working on porting/configuring Android 9.0 for a custom device.
The device is based on the PICO-IMX8MM system-on-module by TechNexion. The device does not have USB ports available to the end-user, only ethernet. In order to enable the end-user to develop Android applications on this device, I would like adb over ethernet to be enabled by default.
I have added the following to the init.rc script (which resides on the device at /vendor/etc/init/hw/init.freescale.rc):
on boot
# Enable adb over ethernet
setprop service.adb.tcp.port 5555
When I set SELinux to "permissive" mode, I can see (via getprop | grep adb) that the property is correctly set, and indeed the device is discoverable on the network (via adb devices).
However when I set SELinux to "enforcing" mode, the property is not set. I suspect that the vendor init script is not allowed to set the service.adb.tcp.port property.
The property context of the property is:
service.adb.tcp.port u:object_r:shell_prop:s0
I don't know about SELinux configuration files, I only roughly understand the concepts.
How can I configure the SELinux policy to allow the vendor init script to set the property service.adb.tcp.port ?