never allow untrusted apps accessing debugfs_tracing

debugfs_tracing can only be accessed by tracing tools provided by the
platform.

Bug: 172028429
Test: boot with no relevant log showing up
Change-Id: I412dd51a1b268061c5a972488b8bc4a0ee456601
diff --git a/private/system_app.te b/private/system_app.te
index 53c31c2..a61b946 100644
--- a/private/system_app.te
+++ b/private/system_app.te
@@ -116,6 +116,9 @@
   vr_hwc_service
 }:service_manager find;
 
+# suppress denials caused by debugfs_tracing
+dontaudit system_app debugfs_tracing:file rw_file_perms;
+
 allow system_app keystore:keystore_key {
     get_state
     get