private: hal_widevine_system: support private storage
- mediadrm_system_data_file file type
- make it private to hal_widevine_system
Bug: 371777025
Test: lunch qemu_trusty_arm64-trunk_staging-userdebug
Change-Id: I5bd28eb4f2eaa44bb0b5a934b7919d2b959ec098
diff --git a/private/hal_widevine_system.te b/private/hal_widevine_system.te
index 2623249..a9cae31 100644
--- a/private/hal_widevine_system.te
+++ b/private/hal_widevine_system.te
@@ -8,3 +8,7 @@
get_prop(hal_widevine_system, drm_config_prop)
get_prop(hal_widevine_system, trusty_widevine_vm_sys_prop)
+
+allow hal_widevine_system mediadrm_system_data_file:dir { create search add_name rw_dir_perms };
+allow hal_widevine_system mediadrm_system_data_file:file { getattr create open read write };
+