--------------------------- external/sepolicy/app.te ---------------------------
index 40de074..a939a92 100644
@@ -349,7 +349,7 @@ neverallow appdomain efs_file:dir_file_class_set write;
neverallow { appdomain -shell } efs_file:dir_file_class_set read;
# Write to various pseudo file systems.
-neverallow { appdomain -bluetooth -nfc }
+neverallow { appdomain -bluetooth -nfc -system_app}
sysfs:dir_file_class_set write;
neverallow appdomain
proc:dir_file_class_set write;
index 40de074..a939a92 100644
@@ -349,7 +349,7 @@ neverallow appdomain efs_file:dir_file_class_set write;
neverallow { appdomain -shell } efs_file:dir_file_class_set read;
# Write to various pseudo file systems.
-neverallow { appdomain -bluetooth -nfc }
+neverallow { appdomain -bluetooth -nfc -system_app}
sysfs:dir_file_class_set write;
neverallow appdomain
proc:dir_file_class_set write;