Merge "Allow CAP_SYS_NICE for crosvm" into main
diff --git a/private/crosvm.te b/private/crosvm.te
index 4f99e8c..6ad3727 100644
--- a/private/crosvm.te
+++ b/private/crosvm.te
@@ -51,6 +51,9 @@
   dontaudit crosvm self:capability ipc_lock;
 ')
 
+# Allow crosvm to tune for performance.
+allow crosvm self:global_capability_class_set sys_nice;
+
 # Let crosvm access its control socket as created by VS.
 #   read, write, getattr: listener socket polling
 #   accept: listener socket accepting new connection