sepolicy: Add rules for xcap

Change-Id: I19c1f971b08e8d08f9c44d33b8036a267eee1e99
diff --git a/basic/non_plat/file_contexts b/basic/non_plat/file_contexts
index 79e24b0..eb50d26 100644
--- a/basic/non_plat/file_contexts
+++ b/basic/non_plat/file_contexts
@@ -687,6 +687,7 @@
 /(vendor|system/vendor)/bin/xgff_test  u:object_r:xgff_test_native_exec:s0
 
 /(vendor|system/vendor)/bin/ccci_fsd u:object_r:ccci_fsd_exec:s0
+/(vendor|system/vendor)/bin/xcap     u:object_r:xcap_exec:s0
 
 /(vendor|system/vendor)/bin/biosensord_nvram                                                u:object_r:biosensord_nvram_exec:s0
 /(vendor|system/vendor)/bin/hw/android\.hardware\.bluetooth@1\.[0|1]-service-mediatek       u:object_r:mtk_hal_bluetooth_exec:s0
diff --git a/basic/non_plat/xcap.te b/basic/non_plat/xcap.te
new file mode 100644
index 0000000..c8a8e0a
--- /dev/null
+++ b/basic/non_plat/xcap.te
@@ -0,0 +1,7 @@
+type xcap, domain;
+type xcap_exec, exec_type, file_type, vendor_file_type;
+
+init_daemon_domain(xcap)
+
+allow xcap ccci_device:chr_file rw_file_perms;
+allow xcap self:capability sys_admin;