servicemanager: allow to read VINTF files in recovery.
Test: manual
Bug: 206888109
Change-Id: I2b7f0f33c27beb0d4401d1d697fdc58e7c62986f
diff --git a/public/servicemanager.te b/public/servicemanager.te
index 12004da..a812338 100644
--- a/public/servicemanager.te
+++ b/public/servicemanager.te
@@ -31,7 +31,10 @@
# Check SELinux permissions.
selinux_check_access(servicemanager)
-# In recovery, log to kmsg.
recovery_only(`
+ # In recovery, log to kmsg.
allow servicemanager kmsg_device:chr_file rw_file_perms;
+
+ # Read VINTF files.
+ r_dir_file(servicemanager, rootfs)
')