diff --git a/public/vendor_init.te b/public/vendor_init.te
index 9b537c10f977e0a0702d6b8f4edf6fb7716c4868..941303c4a74c49b9fc8ccafea36c957fdf277a5e 100644
--- a/public/vendor_init.te
+++ b/public/vendor_init.te
@@ -57,7 +57,7 @@ allow vendor_init {
   -unlabeled
   -vendor_file_type
   -vold_metadata_file
-}:file { create getattr open read write setattr relabelfrom unlink };
+}:file { create getattr open read write setattr relabelfrom unlink map };
 
 allow vendor_init {
   file_type
@@ -104,7 +104,7 @@ allow vendor_init {
   -proc_uid_time_in_state
   -proc_uid_concurrent_active_time
   -proc_uid_concurrent_policy_time
-}:file { open read setattr };
+}:file { open read setattr map };
 
 allow vendor_init {
   fs_type
@@ -146,7 +146,7 @@ allow vendor_init self:process { setfscreate };
 r_dir_file(vendor_init, vendor_file_type)
 
 # Vendor init can read properties
-allow vendor_init serialno_prop:file { getattr open read };
+allow vendor_init serialno_prop:file { getattr open read map };
 
 # Vendor init can perform operations on trusted and security Extended Attributes
 allow vendor_init self:global_capability_class_set sys_admin;