2018-08-20 15:11:42 +00:00
|
|
|
# Copyright 2018 The Chromium OS Authors. All rights reserved.
|
|
|
|
# Use of this source code is governed by a BSD-style license that can be
|
|
|
|
# found in the LICENSE file.
|
|
|
|
|
2019-02-01 00:55:59 +00:00
|
|
|
@include /usr/share/policy/crosvm/common_device.policy
|
|
|
|
|
|
|
|
connect: 1
|
|
|
|
fcntl: arg1 == F_DUPFD_CLOEXEC
|
2018-08-20 15:11:42 +00:00
|
|
|
fstat: 1
|
2019-02-01 00:55:59 +00:00
|
|
|
# Used to set of size new memfd.
|
|
|
|
ftruncate: 1
|
|
|
|
getdents: 1
|
2018-08-20 15:11:42 +00:00
|
|
|
geteuid: 1
|
2019-02-01 00:55:59 +00:00
|
|
|
getrandom: 1
|
2018-08-20 15:11:42 +00:00
|
|
|
getuid: 1
|
2019-02-01 00:55:59 +00:00
|
|
|
ioctl: arg1 == FIONBIO || arg1 == FIOCLEX || arg1 == 0x40086200 || arg1 & 0x6400
|
|
|
|
lseek: 1
|
|
|
|
lstat: 1
|
2018-08-20 15:11:42 +00:00
|
|
|
# Used for sharing memory with wayland. arg1 == MFD_CLOEXEC|MFD_ALLOW_SEALING
|
|
|
|
memfd_create: arg1 == 3
|
2019-02-01 00:55:59 +00:00
|
|
|
mmap: arg2 == PROT_READ|PROT_WRITE || arg2 == PROT_NONE || arg2 == PROT_READ|PROT_EXEC
|
|
|
|
mprotect: arg2 == PROT_READ|PROT_WRITE || arg2 == PROT_NONE || arg2 == PROT_READ
|
|
|
|
open: 1
|
|
|
|
openat: 1
|
|
|
|
readlink: 1
|
|
|
|
recvmsg: 1
|
|
|
|
sendmsg: 1
|
|
|
|
socket: arg0 == 1 && arg1 == 0x80001 && arg2 == 0
|
|
|
|
stat: 1
|