Merge "Block crash_dump from no_crash_dump_domain"
diff --git a/microdroid/system/private/crash_dump.te b/microdroid/system/private/crash_dump.te
index a636e9c..61dfa0b 100644
--- a/microdroid/system/private/crash_dump.te
+++ b/microdroid/system/private/crash_dump.te
@@ -57,6 +57,7 @@
-init
-kernel
-logd
+ -no_crash_dump_domain
-ueventd
-vendor_init
}:process { ptrace signal sigchld sigstop sigkill };
@@ -67,3 +68,5 @@
logd
}:process { ptrace signal sigchld sigstop sigkill };
')
+
+neverallow crash_dump no_crash_dump_domain:process ptrace;