seccomp: allow inotify for shader caching on x86_64

new mesa runtime shader cache loading feature utilizes inotify_init1(),
inotify_add_watch() and inotify_rm_watch

See: https://gitlab.freedesktop.org/mesa/mesa/-/commit/3b69b67545b678da2970654b9490cc3902cdf738

BUG=b:235392416
TEST=vmc launch borealis

Change-Id: I96a9cc11f8ab80e4da8dd0f0b23c7af9f50abf96
Reviewed-on: https://chromium-review.googlesource.com/c/crosvm/crosvm/+/4165870
Reviewed-by: Dennis Kempin <denniskempin@google.com>
Commit-Queue: Juston Li <justonli@google.com>
Reviewed-by: Daniel Verkamp <dverkamp@chromium.org>
diff --git a/seccomp/x86_64/gpu_common.policy b/seccomp/x86_64/gpu_common.policy
index a702f05..b749e33 100644
--- a/seccomp/x86_64/gpu_common.policy
+++ b/seccomp/x86_64/gpu_common.policy
@@ -94,6 +94,9 @@
 
 # Rules for Mesa's shader binary cache.
 flock: 1
+inotify_add_watch: 1
+inotify_init1: 1
+inotify_rm_watch: 1
 mkdir: 1
 newfstatat: 1
 rename: 1