Merge "Allow tee to access mnt_vendor_file" am: 435c1e8e7d am: ab07ab083b am: d787fc54a9

Original change: https://android-review.googlesource.com/c/device/google/redbull-sepolicy/+/1884509

Change-Id: I17591138873c716f421ff6f6a0fdaf1c4245bcbe
diff --git a/redbull-sepolicy.mk b/redbull-sepolicy.mk
index ccfd550..7dbdf9a 100644
--- a/redbull-sepolicy.mk
+++ b/redbull-sepolicy.mk
@@ -12,3 +12,6 @@
 # Pixel-wide sepolicy
 BOARD_SEPOLICY_DIRS += hardware/google/pixel-sepolicy/wifi_sniffer
 BOARD_VENDOR_SEPOLICY_DIRS += hardware/google/pixel-sepolicy/powerstats
+
+# system_ext
+SYSTEM_EXT_PRIVATE_SEPOLICY_DIRS += device/google/redbull-sepolicy/system_ext/private
diff --git a/system_ext/private/platform_app.te b/system_ext/private/platform_app.te
new file mode 100644
index 0000000..10d6bba
--- /dev/null
+++ b/system_ext/private/platform_app.te
@@ -0,0 +1,2 @@
+# allow systemui to set boot animation colors
+set_prop(platform_app, bootanim_system_prop);
diff --git a/system_ext/private/property_contexts b/system_ext/private/property_contexts
new file mode 100644
index 0000000..abcdd41
--- /dev/null
+++ b/system_ext/private/property_contexts
@@ -0,0 +1,5 @@
+# Boot animation dynamic colors
+persist.bootanim.color1     u:object_r:bootanim_system_prop:s0     exact    int
+persist.bootanim.color2     u:object_r:bootanim_system_prop:s0     exact    int
+persist.bootanim.color3     u:object_r:bootanim_system_prop:s0     exact    int
+persist.bootanim.color4     u:object_r:bootanim_system_prop:s0     exact    int
diff --git a/vendor/google/hbmsvmanager_app.te b/vendor/google/hbmsvmanager_app.te
index 4bac4d1..d33136f 100644
--- a/vendor/google/hbmsvmanager_app.te
+++ b/vendor/google/hbmsvmanager_app.te
@@ -2,6 +2,7 @@
 
 app_domain(hbmsvmanager_app);
 hal_client_domain(hbmsvmanager_app, hal_light)
+hal_client_domain(hbmsvmanager_app, hal_qspmhal)
 
 allow hbmsvmanager_app hal_pixel_display_service:service_manager find;
 binder_call(hbmsvmanager_app, hal_graphics_composer_default)