diff --git a/private/priv_app.te b/private/priv_app.te index 9909e067ddf9a4aef11b33e89d6ecbe47d5c90cc..ec52d5691d14c8db1a826a4fafc0c5cd446ea516 100644 --- a/private/priv_app.te +++ b/private/priv_app.te @@ -122,11 +122,14 @@ allow priv_app traced:fd use; allow priv_app traced_tmpfs:file { read write getattr map }; unix_socket_connect(priv_app, traced_producer, traced) -# suppress denials when safetynet scans /system +# suppress denials for non-API accesses. dontaudit priv_app exec_type:file getattr; dontaudit priv_app device:dir read; dontaudit priv_app proc_interrupts:file read; dontaudit priv_app proc_modules:file read; +dontaudit priv_app proc_version:file read; +dontaudit priv_app wifi_prop:file read; +dontaudit priv_app net_dns_prop:file read; # allow privileged apps to use UDP sockets provided by the system server but not # modify them other than to connect