llkd: Add stack symbol checking
llkd needs the ptrace capabilities and dac override to monitor for
live lock conditions on the stack dumps.
Test: compile
Bug: 33808187
Change-Id: Ibc1e4cc10395fa9685c4ef0ca214daf212a5e126
diff --git a/private/crash_dump.te b/private/crash_dump.te
index a50740e..aabff29 100644
--- a/private/crash_dump.te
+++ b/private/crash_dump.te
@@ -7,17 +7,23 @@
-init
-kernel
-keystore
+ -llkd
-logd
-ueventd
-vendor_init
-vold
}:process { ptrace signal sigchld sigstop sigkill };
+userdebug_or_eng(`
+ allow crash_dump { llkd logd }:process { ptrace signal sigchld sigstop sigkill };
+')
neverallow crash_dump {
bpfloader
init
kernel
keystore
+ llkd
+ userdebug_or_eng(`-llkd')
logd
userdebug_or_eng(`-logd')
ueventd