Allow VS to read vendor cfg for assignable devices
Bug: 297313212
Test: add /vendor/etc/avf/assignable_devices.xml and run vm info
Change-Id: I602be057b118ac68a59e6c4f5f7fce17685cd7ae
diff --git a/private/virtualizationservice.te b/private/virtualizationservice.te
index 14662fa..c11fac5 100644
--- a/private/virtualizationservice.te
+++ b/private/virtualizationservice.te
@@ -66,6 +66,9 @@
# Allow virtualizationservice to access VM DTBO via a file created by virtualizationmanager.
allow virtualizationservice virtualizationmanager:fd use;
+# Allow virtualizationservice to access vendor_configs_file to get the list of assignable devices.
+r_dir_file(virtualizationservice, vendor_configs_file)
+
neverallow {
domain
-init