Ignore access to /proc/pagetypeinfo for Settings
avc: denied { read } for comm="pool-3-thread-6" name="pagetypeinfo"
dev="proc" ino=4026531857 scontext=u:r:system_app:s0
tcontext=u:object_r:proc_pagetypeinfo:s0 tclass=file permissive=0
Bug: 312375728
Test: m selinux_policy
Change-Id: Ic2946e181d3a0af65a6ebe093ef7f257c75a1c22
diff --git a/private/system_app.te b/private/system_app.te
index 06b0feb..055c9f9 100644
--- a/private/system_app.te
+++ b/private/system_app.te
@@ -118,7 +118,8 @@
# suppress denials caused by debugfs_tracing
dontaudit system_app debugfs_tracing:file rw_file_perms;
-# Ignore access to zram when Debug.getMemInfo is called.
+# Ignore access to memory properties for Settings.
+dontaudit system_app proc_pagetypeinfo:file r_file_perms;
dontaudit system_app sysfs_zram:dir search;
allow system_app keystore:keystore2_key {