typeattribute crash_dump coredomain; allow crash_dump { domain -apexd -bpfloader -crash_dump -init -kernel -keystore -llkd -logd -ueventd -vendor_init -vold }:process { ptrace signal sigchld sigstop sigkill }; userdebug_or_eng(` allow crash_dump { llkd logd }:process { ptrace signal sigchld sigstop sigkill }; ') ### ### neverallow assertions ### # ptrace neverallow assertions are spread throughout the other policy # files, so we avoid adding redundant assertions here neverallow crash_dump { bpfloader init kernel keystore llkd userdebug_or_eng(`-llkd') logd userdebug_or_eng(`-logd') ueventd vendor_init vold }:process { signal sigstop sigkill }; neverallow crash_dump self:process ptrace;