Support BEGIN_PHYSICAL_DEVICE_ONLY tag

Cuttlefish sets PRODUCT_REQUIRES_INSECURE_EXECMEM_FOR_SWIFTSHADER to
true. This grants a dangerous permission to system_server, which must
never be granted on physical device.

This neverallow assertion is marked as supported on physical devices
only.

Bug: 406890511
Bug: 410133240
Test: atest CtsSecurityHostTestCases:android.security.cts.SELinuxNeverallowRulesTest
Flag: TEST_ONLY
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:308f7f53cd105e0aee99e1d51dad0f92ed64ad6d)
Merged-In: I861b35e7e0f13fa9459a8ebe61a0e4ff30840a99
Change-Id: I861b35e7e0f13fa9459a8ebe61a0e4ff30840a99
1 file changed