diff --git a/private/crash_dump.te b/private/crash_dump.te index 9bc7cf6ba..45d57222d 100644 --- a/private/crash_dump.te +++ b/private/crash_dump.te @@ -109,6 +109,8 @@ dontaudit crash_dump { dontaudit crash_dump system_data_file:{ lnk_file file } read; dontaudit crash_dump property_type:file read; +get_prop(crash_dump, misctrl_prop) + ### ### neverallow assertions ### diff --git a/private/property.te b/private/property.te index 994594d5f..4ce2d54ad 100644 --- a/private/property.te +++ b/private/property.te @@ -231,6 +231,7 @@ neverallow { -init -dumpstate -misctrl + -crash_dump userdebug_or_eng(`-su') } misctrl_prop:file no_rw_file_perms; neverallow {