Neverallow app open access to /dev/ashmem

Apps are no longer allowed open access to /dev/ashmem, unless they
target API level < Q.

Bug: 113362644
Test: device boots, Chrome, instant apps work
Change-Id: I1cff08f26159fbf48a42afa7cfa08eafa1936f42
diff --git a/private/ephemeral_app.te b/private/ephemeral_app.te
index 05f41db..0c89d09 100644
--- a/private/ephemeral_app.te
+++ b/private/ephemeral_app.te
@@ -65,6 +65,8 @@
 allow ephemeral_app system_server:udp_socket {
         connect getattr read recvfrom sendto write getopt setopt };
 
+allow ephemeral_app ashmem_device:chr_file { getattr read write ioctl };
+
 ###
 ### neverallow rules
 ###