Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    Strengthen ptrace neverallow rules · 095fbea5
    Nick Kralevich authored
    Add additional compile time constraints on the ability to ptrace various
    sensitive domains.
    
    llkd: remove some domains which llkd should never ptrace, even on
    debuggable builds, such as kernel threads and init.
    
    crash_dump neverallows: Remove the ptrace neverallow checks because
    it duplicates other neverallow assertions spread throughout the policy.
    
    Test: policy compiles and device boots
    Change-Id: Ia4240d1ce7143b983bb048e046bb4729d0af5a6e
    095fbea5