Skip to content

Commit

Permalink
Add missing crash_dump policy for minijail inside Android container
Browse files Browse the repository at this point in the history
  • Loading branch information
Flohack74 committed Jan 23, 2021
1 parent bb7b781 commit a3cff0e
Show file tree
Hide file tree
Showing 2 changed files with 40 additions and 0 deletions.
2 changes: 2 additions & 0 deletions device.mk
Original file line number Diff line number Diff line change
Expand Up @@ -681,3 +681,5 @@ PRODUCT_COPY_FILES += \
miniafservice \
uinput-fpc-key-disable

PRODUCT_COPY_FILES += \
device/google/wahoo/seccomp_policy/crash_dump.arm.policy:system/etc/seccomp_policy/crash_dump.arm.policy
38 changes: 38 additions & 0 deletions seccomp_policy/crash_dump.arm.policy
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
read: 1
write: 1
exit: 1
rt_sigreturn: 1
sigreturn: 1
exit_group: 1
clock_gettime: 1
gettimeofday: 1
futex: 1
getrandom: 1
getpid: 1
gettid: 1
ppoll: 1
pipe2: 1
openat: 1
dup: 1
close: 1
lseek: 1
getdents64: 1
faccessat: 1
recvmsg: 1
process_vm_readv: 1
tgkill: 1
rt_sigprocmask: 1
rt_sigaction: 1
rt_tgsigqueueinfo: 1
prctl: arg0 == PR_GET_NO_NEW_PRIVS || arg0 == 0x53564d41
madvise: 1
mprotect: arg2 in 0x1|0x2
munmap: 1
getuid32: 1
fstat64: 1
mmap2: arg2 in 0x1|0x2
geteuid32: 1
getgid32: 1
getegid32: 1
getgroups32: 1

0 comments on commit a3cff0e

Please sign in to comment.