Merge "app: move appdomain to public policy"
diff --git a/private/compat/26.0/26.0.ignore.cil b/private/compat/26.0/26.0.ignore.cil
index 136041d..790133e 100644
--- a/private/compat/26.0/26.0.ignore.cil
+++ b/private/compat/26.0/26.0.ignore.cil
@@ -6,6 +6,7 @@
   ( adbd_exec
     bootloader_boot_reason_prop
     broadcastradio_service
+    crossprofileapps_service
     e2fs
     e2fs_exec
     hal_broadcastradio_hwservice
diff --git a/private/service_contexts b/private/service_contexts
index 6a8843f..10d8d09 100644
--- a/private/service_contexts
+++ b/private/service_contexts
@@ -32,6 +32,7 @@
 country_detector                          u:object_r:country_detector_service:s0
 coverage                                  u:object_r:coverage_service:s0
 cpuinfo                                   u:object_r:cpuinfo_service:s0
+crossprofileapps                          u:object_r:crossprofileapps_service:s0
 dbinfo                                    u:object_r:dbinfo_service:s0
 device_policy                             u:object_r:device_policy_service:s0
 device_identifiers                        u:object_r:device_identifiers_service:s0
diff --git a/public/init.te b/public/init.te
index 3a2d667..450afd8 100644
--- a/public/init.te
+++ b/public/init.te
@@ -214,7 +214,7 @@
   -contextmount_type
   -proc
   -sdcard_type
-  -sysfs
+  -sysfs_type
   -rootfs
 }:file { open read setattr };
 allow init { fs_type -contextmount_type -sdcard_type -rootfs }:dir  { open read setattr search };
@@ -304,6 +304,10 @@
   sysfs_zram
 }:file w_file_perms;
 
+allow init {
+  sysfs_dt_firmware_android
+}:file r_file_perms;
+
 # init chmod/chown access to /sys files.
 allow init {
   sysfs_android_usb
@@ -312,6 +316,8 @@
   sysfs_leds
   sysfs_lowmemorykiller
   sysfs_power
+  sysfs_vibrator
+  sysfs_wake_lock
 }:file setattr;
 
 # Set usermodehelpers.
diff --git a/public/service.te b/public/service.te
index b421c97..e48d4b7 100644
--- a/public/service.te
+++ b/public/service.te
@@ -48,6 +48,7 @@
 type cameraproxy_service, system_server_service, service_manager_type;
 type clipboard_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
 type contexthub_service, app_api_service,  system_server_service, service_manager_type;
+type crossprofileapps_service, app_api_service, system_server_service, service_manager_type;
 type IProxyService_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
 type commontime_management_service, system_server_service, service_manager_type;
 type companion_device_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;