kernel-4.17.0-0.rc6.git3.1.fc29.src.rpm misses the following debug options: CONFIG_ACPI_DEBUGGER=y ACPI_DEBUGGER_USER=m They are critical for debugging ACPI related issues.
This effectively gives userspace arbitrary read/write of the kernel, so it needs to be disabled when lockdown is enabled.
I do think this is a good idea but it looks like there would be more work, including packaging the userspace tools (unless they are packaged elsewhere?). None of this is overly difficult, it just needs to happen.