selinux: New rw privileges for themes
- New theme_data_file context for files under /data/system/theme
- Permit systemserver to create files/dirs under /data/resource-cache
- Permit systemserver to create files/dirs under /data/system/theme
Change-Id: Id597fc20b477ea395a8631623f26a7edde280799
diff --git a/sepolicy/file_contexts b/sepolicy/file_contexts
index c179f1e..983f911 100644
--- a/sepolicy/file_contexts
+++ b/sepolicy/file_contexts
@@ -4,6 +4,9 @@
/system/bin/auditd u:object_r:logd_exec:s0
/data/misc/audit(/.*)? u:object_r:auditd_log:s0
+# Themes
+/data/system/theme(/.*)? u:object_r:theme_data_file:s0
+
/system/bin/sysinit u:object_r:sysinit_exec:s0
# For minivold in recovery