Skip to content
Snippets Groups Projects
Commit 943d7ed5 authored by Josh Gao's avatar Josh Gao
Browse files

crash_dump: dontaudit CAP_SYS_PTRACE denial.

Bug: http://b/34853272
Test: debuggerd -b `pidof zygote`
Change-Id: I0b18117754e77cfa94cf0b95aff32edb578b1a95
parent 4d140237
No related branches found
No related tags found
No related merge requests found
...@@ -8,6 +8,11 @@ allow crash_dump { ...@@ -8,6 +8,11 @@ allow crash_dump {
-keystore -keystore
-logd -logd
}:process { ptrace signal sigchld sigstop sigkill }; }:process { ptrace signal sigchld sigstop sigkill };
# crash_dump might inherit CAP_SYS_PTRACE from a privileged process,
# which will result in an audit log even when it's allowed to trace.
dontaudit crash_dump self:capability { sys_ptrace };
userdebug_or_eng(` userdebug_or_eng(`
allow crash_dump logd:process { ptrace signal sigchld sigstop sigkill }; allow crash_dump logd:process { ptrace signal sigchld sigstop sigkill };
') ')
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment