Sepolicy: Add base runtime APEX postinstall policies

Add art_apex_postinstall domain that is allowed to move
precreated AoT artifacts from /data/ota.

Bug: 125474642
Test: m
Change-Id: Id674e202737155a4ee31187f096d1dd655001fdd
diff --git a/apex/com.android.runtime.debug-file_contexts b/apex/com.android.runtime.debug-file_contexts
index 059b52a..592975d 100644
--- a/apex/com.android.runtime.debug-file_contexts
+++ b/apex/com.android.runtime.debug-file_contexts
@@ -1,11 +1,12 @@
 #############################
 # System files
 #
-(/.*)?                        u:object_r:system_file:s0
-/bin/dex2oat(d)?              u:object_r:dex2oat_exec:s0
-/bin/dexoptanalyzer(d)?       u:object_r:dexoptanalyzer_exec:s0
-/bin/profman(d)?              u:object_r:profman_exec:s0
-/bin/linker(64)?              u:object_r:system_linker_exec:s0
-/lib(64)?(/.*)?               u:object_r:system_lib_file:s0
-/etc/tz(/.*)?                 u:object_r:system_zoneinfo_file:s0
-/bin/art_preinstall_hook(.*)? u:object_r:art_apex_preinstall_exec:s0
+(/.*)?                         u:object_r:system_file:s0
+/bin/dex2oat(d)?               u:object_r:dex2oat_exec:s0
+/bin/dexoptanalyzer(d)?        u:object_r:dexoptanalyzer_exec:s0
+/bin/profman(d)?               u:object_r:profman_exec:s0
+/bin/linker(64)?               u:object_r:system_linker_exec:s0
+/lib(64)?(/.*)?                u:object_r:system_lib_file:s0
+/etc/tz(/.*)?                  u:object_r:system_zoneinfo_file:s0
+/bin/art_preinstall_hook(.*)?  u:object_r:art_apex_preinstall_exec:s0
+/bin/art_postinstall_hook(.*)? u:object_r:art_apex_postinstall_exec:s0