Pull Request已成功合入, 合并人@openharmony_ci
(感谢 河蟹能吃吗 的贡献)感谢提交 Pull Requests !此PR未通过DCO校验。
校验失败可能原因:
1. 未签署“DCO协议”(开发者原创声明协议),在线签署、查看签署状态。
2. Commits 中未包含 Signed-off-by信息,参考FAQ处理。
修复上述问题后,在PR的评论框输入“check dco” ,单击”评论”,系统将再次进行DCO校验。
当前检测到如下Commits 未包含Signed-off-by信息:
Thanks for submitting a pull request. This pull request has not passed the DCO check.
Possible causes:
1. You have not signed the Developer Certificate of Origin (DCO). Sign the DCO and check DCO status.
2. The commits do not contain the Signed-off-by information. To resolve this issue, see FAQs.
After resolving the preceding issues, enter check dco in the comment box of this pull request and click Comment. The system will check DCO status again.
The following commits do not contain the Signed-off-by information:


您好,Committer @JerryH1011 @JiDong-CS1 @hehehe-li @chennian ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。
Hello, Committer @JerryH1011 @JiDong-CS1 @hehehe-li @chennian . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.


关联的issue:[#5285]
修改描述(修改功能描述,规格变更说明):
print_isolate_hap增加应用目录rename权限
策略合入自检
SELinux 策略提交自检报告(2026-09-30)
扫描范围:PR #8300 的完整策略净差异,基线为
ef559e41b77c252dd467bfc57e9b0abd19aaae38,检视提交为47a86aa288441513afb807a0ece7048145d75686。diff 性质:新增权限。仅新增独立 rename 规则、脱敏 AVC 注释及前后空行;既有目录、文件授权规则保持不变。
涉及策略文件:1 个 新增规则行:1 条
调用技能:ohos-dev-seharmony-policy-review,版本 2.2.0;技能来源提交为
8b23c3560b8143f3cd74ee15a6f10b98ec85d9f4。运行技能的scripts/scan.py ef559e41b77c252dd467bfc57e9b0abd19aaae38..47a86aa288441513afb807a0ece7048145d75686,退出码 0,并完成语义核对。结论:没有 FAIL 或 SUGGESTION;保留 1 项 S15 WARNING,需责任田确认授权范围。以下行号均对应
sepolicy/ohos_policy/print/print_service/system/print_isolate_hap.te。<redacted-package>,新增行未命中敏感词sepolicy/ohos_policy/print/print_service/system/allow print_isolate_hap normal_app_data:dir { rename };,需打印/应用安全责任田确认两个数据类型的授权范围及具体主体类型的适用约定# avc:格式被识别;rename、print_isolate_hap、dir 均对应,宏包含 AVC 的 appdat;permissive=0 保留AVC 依据与脱敏说明
完整包名替换为
<redacted-package>,保留目录结构及 AVC 的权限、主体、客体、对象类别、permissive 和其余日志字段。# avc:与#avc:均受技能支持。ROM 增量估算
该结果是技能按源码行计算的估算,不是镜像测量。
需评审决策(WARNING 需确认,结论回填后再合入)
allow print_isolate_hap normal_app_data:dir { rename };→ 打印/应用安全责任田确认范围。sepolicy/base/public/glb_scontext.te:14中宏展开为{ normal_hap_data_file appdat },因此仅对这两个类型新增目录 rename。AVC 直接证明 appdat 的拒绝场景,另一类型由宏及策略一致性要求覆盖,不应描述为已有该类型的实测 AVC。本地根目录及 sepolicy/AGENTS.md 要求应用策略使用属性,而技能 S15 允许应用子集使用具体类型;需确认打印隔离主体的适用约定,不能自行将授权扩大到全部应用。验证边界
git diff --check通过;技能扫描及新增规则的 AVC 对应、宏展开、空行分隔均已核对。既有权限规则未修改。此前技能自身的空差异回归用例失败:用例实际残留类型文件移动;本次扫描输入为已核对的非空 PR 差异,该自检失败不能表述为全部技能回归通过。本次检视未执行完整 OpenHarmony 策略编译或设备测试,不据此声称 CI、编译后的全部 neverallow 校验或设备验证已通过。门禁结果应以对应提交的实际检查结果为准。