platform_system_sepolicy/private/crash_dump.te
Jeff Vander Stoep 08aa715966 crash_dump: disallow ptrace of TCB components
Remove permissions and add neverallow assertion.

(cherry picked from commit f1554f1588)

Bug: 110107376
Test: kill -6 <components excluded from ptrace>
Change-Id: I2dc872f5c02749fbaf8ca6bc7e3e38404151442c
2018-08-28 08:28:25 -07:00

26 lines
393 B
Text

typeattribute crash_dump coredomain;
allow crash_dump {
domain
-bpfloader
-crash_dump
-init
-kernel
-keystore
-logd
-ueventd
-vendor_init
-vold
}:process { ptrace signal sigchld sigstop sigkill };
neverallow crash_dump {
bpfloader
init
kernel
keystore
logd
userdebug_or_eng(`-logd')
ueventd
vendor_init
vold
}:process { ptrace signal sigstop sigkill };