Restrict isolated_app's /sys access

isolated_app is strictly limited on the files in /sys which can be
accessed.

Test: policy compiles.
Change-Id: I9f3c00a98cd8c08a3968d8e565bf56b4670a780f
1 file changed