The custom pawletcache_vendor_config_file type/label tripped Treble's coredomain-can't-read-/vendor neverallow, since a hand-rolled vendor_file_type subtype isn't in that rule's exception list. Dropping the override lets /vendor/etc/pawletcache fall under AOSP's default vendor_configs_file labeling, which every domain already has blanket read access to.