Set sepolicy for creating TAP interfaces in vmnic of AVF
Bug: 340376951
Test: Presubmit
Change-Id: I2948698a1738d441768d77da611d5e8dd3eb3c5b
diff --git a/private/virtualizationmanager.te b/private/virtualizationmanager.te
index 3aaff5b..72cc0a6 100644
--- a/private/virtualizationmanager.te
+++ b/private/virtualizationmanager.te
@@ -116,3 +116,9 @@
# virtualizationmanager holds references to bound devices, returned from vfio_handler
binder_call(virtualizationmanager, vfio_handler)
')
+
+is_flag_enabled(RELEASE_AVF_ENABLE_NETWORK, `
+ # Allow virtualizationmanager to deal with file descriptors of TAP interfaces.
+ allow virtualizationmanager tun_device:chr_file rw_file_perms;
+ allow virtualizationmanager vmnic:fd use;
+')