sepolicy: Allow permissive backuptools and recovery on user builds

Change-Id: I0e06e12bb7b42ee6b6543b8427b6586058fe0f46

Change-Id: I8c6530d685de6e7abdb035d2c30e568c08724510

Change-Id: I4638daeef580346fdcc86595430d1b910c3e34ec

Change-Id: I0b2614759098f0f908725acbf065b1b3bc6014e3

Change-Id: I5c4bff3d8531aafe15f09bc8e6c569effa2325e9
diff --git a/build/soong/policy.go b/build/soong/policy.go
index 7b2122c..7412df8 100644
--- a/build/soong/policy.go
+++ b/build/soong/policy.go
@@ -552,6 +552,8 @@
 			cmd.Text(" || true; }") // no match doesn't fail the cmd
 		}
 		cmd.Text(" > ").Output(permissiveDomains)
+		rule.Command().Text("sed").FlagWithArg("-i ", "'/backuptool/d'").Input(permissiveDomains)
+		rule.Command().Text("sed").FlagWithArg("-i ", "'/recovery/d'").Input(permissiveDomains)
 		rule.Temporary(permissiveDomains)
 
 		msg := `==========\n` +