sepolicy: allow mm-pp-daemon to use binders in user variant

Binder calls from mm-pp-daemon were only allowed in userdebug
variants and were not allowed in user variant builds. Now
allowing these binder calls from mm-pp-daemon to system server
and surfaceflinger. Also allowing diag to access tempfs.

Change-Id: Ia90489ff63d62e0514666be5734fde0a3662a8a2
1 file changed