Allow vmlauncher_app to create ptys to communicate with shell
* Allow vmlauncher_app to create pty/pts
* Allow vmlauncher_app to change permission of created pts
* Allow shell to read/write vmlauncher_app pts
adb shell can open and communicate with vmlauncher_app via the pts
device. VM console would be available on the pts.
Bug: 335362012
Test: adb shell -t microcom /dev/pts/0
Test: No new avc denials in logcat
Change-Id: If630235b486bf5ffffb45aeac3e29438029edb04
diff --git a/private/shell.te b/private/shell.te
index dbdd132..263db8c 100644
--- a/private/shell.te
+++ b/private/shell.te
@@ -430,6 +430,12 @@
# Allow reads (but not writes) of the MGLRU state
allow shell sysfs_lru_gen_enabled:file r_file_perms;
+# Allow communicating with the VM terminal.
+userdebug_or_eng(`
+ allow shell vmlauncher_app_devpts:chr_file rw_file_perms;
+ allowxperm shell vmlauncher_app_devpts:chr_file ioctl unpriv_tty_ioctls;
+')
+
# Allow access to ion memory allocation device.
allow shell ion_device:chr_file rw_file_perms;