Allow More Apps to Recv UDP Sockets from SystemServer

This gives the privilege to system apps, platform apps,
ephemeral apps, and privileged apps to receive a
UDP socket from the system server. This is being added
for supporting UDP Encapsulation sockets for IPsec, which
must be provided by the system.

This is an analogous change to a previous change that
permitted these sockets for untrusted_apps:
0f75a62e2c4fb1b6ef8db6f2e5c10ff29f95322d

Bug: 70389346
Test: IpSecManagerTest, System app verified with SL4A
Change-Id: Iec07e97012e0eab92a95fae9818f80f183325c31
diff --git a/private/priv_app.te b/private/priv_app.te
index 92bfc57..9909e06 100644
--- a/private/priv_app.te
+++ b/private/priv_app.te
@@ -128,6 +128,10 @@
 dontaudit priv_app proc_interrupts:file read;
 dontaudit priv_app proc_modules:file read;
 
+# allow privileged apps to use UDP sockets provided by the system server but not
+# modify them other than to connect
+allow priv_app system_server:udp_socket { connect getattr read recvfrom sendto write };
+
 ###
 ### neverallow rules
 ###