/data/misc/pawletcache(/.*)? u:object_r:pawletcache_policy_file:s0 # OEM/vendor-baked default policy — see vendor-config/README.md. No custom # type/label needed: this falls under AOSP's default /vendor/etc(/.*)? -> # vendor_configs_file file_contexts pattern, and every domain already has # blanket read access to vendor_configs_file (system/sepolicy/private/ # domain.te). A custom vendor_file_type subtype here would trip the # coredomain-can't-read-/vendor neverallow, since it isn't in that rule's # exception list the way vendor_configs_file is.