Merge "Allow vmlauncher_app to create ptys to communicate with shell" into main
diff --git a/private/shell.te b/private/shell.te
index dbdd132..263db8c 100644
--- a/private/shell.te
+++ b/private/shell.te
@@ -430,6 +430,12 @@
# Allow reads (but not writes) of the MGLRU state
allow shell sysfs_lru_gen_enabled:file r_file_perms;
+# Allow communicating with the VM terminal.
+userdebug_or_eng(`
+ allow shell vmlauncher_app_devpts:chr_file rw_file_perms;
+ allowxperm shell vmlauncher_app_devpts:chr_file ioctl unpriv_tty_ioctls;
+')
+
# Allow access to ion memory allocation device.
allow shell ion_device:chr_file rw_file_perms;
diff --git a/private/vmlauncher_app.te b/private/vmlauncher_app.te
index dcc4f55..f0f372b 100644
--- a/private/vmlauncher_app.te
+++ b/private/vmlauncher_app.te
@@ -16,3 +16,10 @@
allow vmlauncher_app virtualizationservice:binder call;
allow vmlauncher_app crosvm:binder { call transfer };
')
+
+userdebug_or_eng(`
+ # Create pty/pts and connect it to the guest terminal.
+ create_pty(vmlauncher_app)
+ # Allow other processes to access the pts.
+ allow vmlauncher_app vmlauncher_app_devpts:chr_file setattr;
+')