Rework neverallow for /data execute permission

Previously appdomains allowed to execute off of /data
where whitelisted. This had the unfortunate side effect of
disallowing the creation of device specific app domains
with fewer permissions than untrusted_app. Instead grant
all apps a neverallow exemption and blacklist specific app
domains that should still abide by the restriction.

This allows devices to add new app domains that need
/data execute permission without conflicting with this rule.

Bug: 26906711

(cherry picked from commit c5266df925169b959977d3fa03b4b369253db837)

Change-Id: I4adb58e8c8b35122d6295db58cedaa355cdd3924
2 files changed