Merge "Allow tee to access mnt_vendor_file" am: 435c1e8e7d am: ab07ab083b am: d787fc54a9
Original change: https://android-review.googlesource.com/c/device/google/redbull-sepolicy/+/1884509
Change-Id: I17591138873c716f421ff6f6a0fdaf1c4245bcbe
diff --git a/redbull-sepolicy.mk b/redbull-sepolicy.mk
index ccfd550..7dbdf9a 100644
--- a/redbull-sepolicy.mk
+++ b/redbull-sepolicy.mk
@@ -12,3 +12,6 @@
# Pixel-wide sepolicy
BOARD_SEPOLICY_DIRS += hardware/google/pixel-sepolicy/wifi_sniffer
BOARD_VENDOR_SEPOLICY_DIRS += hardware/google/pixel-sepolicy/powerstats
+
+# system_ext
+SYSTEM_EXT_PRIVATE_SEPOLICY_DIRS += device/google/redbull-sepolicy/system_ext/private
diff --git a/system_ext/private/platform_app.te b/system_ext/private/platform_app.te
new file mode 100644
index 0000000..10d6bba
--- /dev/null
+++ b/system_ext/private/platform_app.te
@@ -0,0 +1,2 @@
+# allow systemui to set boot animation colors
+set_prop(platform_app, bootanim_system_prop);
diff --git a/system_ext/private/property_contexts b/system_ext/private/property_contexts
new file mode 100644
index 0000000..abcdd41
--- /dev/null
+++ b/system_ext/private/property_contexts
@@ -0,0 +1,5 @@
+# Boot animation dynamic colors
+persist.bootanim.color1 u:object_r:bootanim_system_prop:s0 exact int
+persist.bootanim.color2 u:object_r:bootanim_system_prop:s0 exact int
+persist.bootanim.color3 u:object_r:bootanim_system_prop:s0 exact int
+persist.bootanim.color4 u:object_r:bootanim_system_prop:s0 exact int
diff --git a/vendor/google/hbmsvmanager_app.te b/vendor/google/hbmsvmanager_app.te
index 4bac4d1..d33136f 100644
--- a/vendor/google/hbmsvmanager_app.te
+++ b/vendor/google/hbmsvmanager_app.te
@@ -2,6 +2,7 @@
app_domain(hbmsvmanager_app);
hal_client_domain(hbmsvmanager_app, hal_light)
+hal_client_domain(hbmsvmanager_app, hal_qspmhal)
allow hbmsvmanager_app hal_pixel_display_service:service_manager find;
binder_call(hbmsvmanager_app, hal_graphics_composer_default)