diff --git a/public/app.te b/public/app.te index 64bb839c19c5cbc7f8f0714e351a7121fa2afa76..bc4ad611ef5695b450791bbea000dbfc913f6eab 100644 --- a/public/app.te +++ b/public/app.te @@ -87,7 +87,7 @@ allow appdomain oemfs:file rx_file_perms; # Execute the shell or other system executables. allow { appdomain -ephemeral_app -untrusted_v2_app } shell_exec:file rx_file_perms; allow { appdomain -ephemeral_app -untrusted_v2_app } toolbox_exec:file rx_file_perms; -allow { appdomain -ephemeral_app -untrusted_v2_app } system_file:file x_file_perms; +allow { appdomain -untrusted_v2_app } system_file:file x_file_perms; not_full_treble(`allow { appdomain -ephemeral_app -untrusted_v2_app } vendor_file:file x_file_perms;') # Renderscript needs the ability to read directories on /system