Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    dumpstate: assert no process ptrace · 6bae84a5
    Nick Kralevich authored
    dumpstate has CAP_SYS_PTRACE solely for the purpose of reading sensitive
    /proc/PID files, not for using ptrace attach. Add an assert to ensure
    that's the case.
    
    Test: policy compiles.
    Change-Id: I975308fae3f8e9a039b9efdc0e9605192b405ce7
    6bae84a5