blob: 4286547045d25ab86e17efa0d478d5e2a095b216 [file] [log] [blame]
# Only allow gpu ioctl commands that have been demonstrated to be necessary.
allowxperm { appdomain -isolated_app } gpu_device:chr_file
ioctl { gpu_ioctls unpriv_tty_ioctls };
allow appdomain sysfs_soc:dir search;
allow appdomain sysfs_soc:file r_file_perms;