diff --git a/private/dexoptanalyzer.te b/private/dexoptanalyzer.te index db81d0dad0f826de8a8a8294440ac38284e3ca76..1c23f572745c84e0aabb16a4dc812cb1827b1bf1 100644 --- a/private/dexoptanalyzer.te +++ b/private/dexoptanalyzer.te @@ -21,6 +21,10 @@ allow dexoptanalyzer installd:fd use; # package manager. allow dexoptanalyzer app_data_file:dir { getattr search }; allow dexoptanalyzer app_data_file:file r_file_perms; +# dexoptanalyzer calls access(2) with W_OK flag on app data. We can use the +# "dontaudit...audit_access" policy line to suppress the audit access without +# suppressing denial on actual access. +dontaudit dexoptanalyzer app_data_file:dir audit_access; # Allow testing /data/user/0 which symlinks to /data/data allow dexoptanalyzer system_data_file:lnk_file { getattr };