From 6233848f78613c788dc64900c5431bb552e76c20 Mon Sep 17 00:00:00 2001 From: Jeff Vander Stoep <jeffv@google.com> Date: Fri, 20 Oct 2017 13:35:42 -0700 Subject: [PATCH] priv_app: move logspam suppression to core policy No sign of these denials getting cleaned up, so supress them in core policy. Test: build Change-Id: I0320425cb72cbd15cef0762090899491338d4f7c --- private/priv_app.te | 3 +++ 1 file changed, 3 insertions(+) diff --git a/private/priv_app.te b/private/priv_app.te index 60fb41109..f4cfc1736 100644 --- a/private/priv_app.te +++ b/private/priv_app.te @@ -114,6 +114,9 @@ read_runtime_log_tags(priv_app) # suppress denials when safetynet scans /system dontaudit priv_app exec_type:file getattr; +dontaudit priv_app device:dir read; +dontaudit priv_app proc_interrupts:file read; +dontaudit priv_app proc_modules:file read; ### ### neverallow rules -- GitLab