Add mmd selinux policies
This adds minimum selinux policies to unblock these functions which are
already submitted:
* The init service launchs mmd as a native daemon by mmd.rc.
* mmd exposes binder API.
EXCEPTION_NO_FUZZER in build/soong/service_fuzzer_bindings.go is allowed
for Rust products.
Bug: 375432644
Bug: 370509309
Test: confirmed mmd is launched after: adb shell aflags enable \
android.mmd.flags.mmd_enabled; adb reboot
Change-Id: Ibd3e68e5aea83b3bc4a01e9dcf00be2daf2466c1
diff --git a/private/service.te b/private/service.te
index bb24fd4..c12c1a0 100644
--- a/private/service.te
+++ b/private/service.te
@@ -16,6 +16,7 @@
type logcat_service, system_server_service, service_manager_type;
type logd_service, service_manager_type;
type mediatuner_service, app_api_service, service_manager_type;
+type mmd_service, service_manager_type;
type on_device_intelligence_service, app_api_service, system_server_service, service_manager_type, isolated_compute_allowed_service;
type profcollectd_service, service_manager_type;
type protolog_configuration_service, app_api_service, system_api_service, system_server_service, service_manager_type;