crosvm/seccomp/x86_64/gpu_render_server.policy
Chia-I Wu b86f7f6110 gpu: allow syslog from the render server
BUG=b:177267762
TEST=run vk and gl apps on volteer

Change-Id: I6fe2ce831eb671fedd1c0aa749066c41d181d152
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/3335301
Reviewed-by: Daniel Verkamp <dverkamp@chromium.org>
Tested-by: kokoro <noreply+kokoro@google.com>
Reviewed-by: Chirantan Ekbote <chirantan@chromium.org>
Commit-Queue: Chia-I Wu <olv@google.com>
2021-12-14 16:54:22 +00:00

15 lines
488 B
Text

# Copyright 2021 The Chromium OS Authors. All rights reserved.
# Use of this source code is governed by a BSD-style license that can be
# found in the LICENSE file.
@include /usr/share/policy/crosvm/gpu_common.policy
# allow fork() and waitid()
clone: 1
waitid: 1
# allow SOCK_STREAM and SOCK_DGRAM (syslog)
socket: arg0 == AF_UNIX && arg2 == 0
# allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC)
socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0