Neverallow app open access to /dev/ashmem

Apps are no longer allowed open access to /dev/ashmem, unless they
target API level < Q.

Bug: 113362644
Test: device boots, Chrome, instant apps work
Change-Id: I1cff08f26159fbf48a42afa7cfa08eafa1936f42
diff --git a/private/isolated_app.te b/private/isolated_app.te
index 8a0f96b..f51ccc9 100644
--- a/private/isolated_app.te
+++ b/private/isolated_app.te
@@ -64,6 +64,8 @@
 # debuggable.
 can_profile_heap(isolated_app)
 
+allow isolated_app ashmem_device:chr_file { getattr read write ioctl };
+
 #####
 ##### Neverallow
 #####