diff --git a/private/dexoptanalyzer.te b/private/dexoptanalyzer.te index db81d0dad..1c23f5727 100644 --- a/private/dexoptanalyzer.te +++ b/private/dexoptanalyzer.te @@ -21,6 +21,10 @@ allow dexoptanalyzer installd:fd use; # package manager. allow dexoptanalyzer app_data_file:dir { getattr search }; allow dexoptanalyzer app_data_file:file r_file_perms; +# dexoptanalyzer calls access(2) with W_OK flag on app data. We can use the +# "dontaudit...audit_access" policy line to suppress the audit access without +# suppressing denial on actual access. +dontaudit dexoptanalyzer app_data_file:dir audit_access; # Allow testing /data/user/0 which symlinks to /data/data allow dexoptanalyzer system_data_file:lnk_file { getattr };