Neverallow app open access to /dev/ashmem
Apps are no longer allowed open access to /dev/ashmem, unless they
target API level < Q.
Bug: 113362644
Test: device boots, Chrome, instant apps work
Change-Id: I1cff08f26159fbf48a42afa7cfa08eafa1936f42
diff --git a/private/isolated_app.te b/private/isolated_app.te
index 8a0f96b..f51ccc9 100644
--- a/private/isolated_app.te
+++ b/private/isolated_app.te
@@ -64,6 +64,8 @@
# debuggable.
can_profile_heap(isolated_app)
+allow isolated_app ashmem_device:chr_file { getattr read write ioctl };
+
#####
##### Neverallow
#####