Merge "auditallow gpu_device execute access"
diff --git a/system_server.te b/system_server.te
index 6737783..39a19e9 100644
--- a/system_server.te
+++ b/system_server.te
@@ -351,9 +351,6 @@
allow system_server fscklogs:dir { write remove_name };
allow system_server fscklogs:file unlink;
-# For SELinuxPolicyInstallReceiver
-selinux_manage_policy(system_server)
-
# logd access, system_server inherit logd write socket
# (urge is to deprecate this long term)
allow system_server zygote:unix_dgram_socket write;
diff --git a/te_macros b/te_macros
index e455e63..1936ffb 100644
--- a/te_macros
+++ b/te_macros
@@ -248,18 +248,6 @@
')
#####################################
-# selinux_manage_policy(domain)
-# Ability to manage policy files and
-# trigger runtime reload.
-define(`selinux_manage_policy', `
-security_access_policy($1)
-allow $1 security_file:dir create_dir_perms;
-allow $1 security_file:file create_file_perms;
-allow $1 security_file:lnk_file { create rename unlink };
-set_prop($1, security_prop)
-')
-
-#####################################
# mmac_manage_policy(domain)
# Ability to manage mmac policy files,
# trigger runtime reload, change