xref: /aosp_15_r20/external/crosvm/jail/seccomp/arm/video_device.policy (revision bb4ee6a4ae7042d18b07a98463b9c8b875e44b39)
1*bb4ee6a4SAndroid Build Coastguard Worker# Copyright 2020 The ChromiumOS Authors
2*bb4ee6a4SAndroid Build Coastguard Worker# Use of this source code is governed by a BSD-style license that can be
3*bb4ee6a4SAndroid Build Coastguard Worker# found in the LICENSE file.
4*bb4ee6a4SAndroid Build Coastguard Worker
5*bb4ee6a4SAndroid Build Coastguard Worker@include /usr/share/policy/crosvm/common_device.policy
6*bb4ee6a4SAndroid Build Coastguard Worker
7*bb4ee6a4SAndroid Build Coastguard Worker# Syscalls specific to video devices.
8*bb4ee6a4SAndroid Build Coastguard Workeraccess: 1
9*bb4ee6a4SAndroid Build Coastguard Workerclock_getres: 1
10*bb4ee6a4SAndroid Build Coastguard Workerclock_getres_time64: 1
11*bb4ee6a4SAndroid Build Coastguard Workerconnect: 1
12*bb4ee6a4SAndroid Build Coastguard Workerfstatfs64: 1
13*bb4ee6a4SAndroid Build Coastguard Workerfstatfs: 1
14*bb4ee6a4SAndroid Build Coastguard Workergetegid32: 1
15*bb4ee6a4SAndroid Build Coastguard Workergeteuid32: 1
16*bb4ee6a4SAndroid Build Coastguard Workergetgid32: 1
17*bb4ee6a4SAndroid Build Coastguard Workergetrandom: 1
18*bb4ee6a4SAndroid Build Coastguard Workergetresgid32: 1
19*bb4ee6a4SAndroid Build Coastguard Workergetresuid32: 1
20*bb4ee6a4SAndroid Build Coastguard Workergetsockname: 1
21*bb4ee6a4SAndroid Build Coastguard Workergetuid32: 1
22*bb4ee6a4SAndroid Build Coastguard Worker# ioctl: arg1 == DRM_IOCTL_*
23*bb4ee6a4SAndroid Build Coastguard Workerioctl: arg1 & 0x6400
24*bb4ee6a4SAndroid Build Coastguard Workeropenat: 1
25*bb4ee6a4SAndroid Build Coastguard Workersend: 1
26*bb4ee6a4SAndroid Build Coastguard Workersetpriority: 1
27*bb4ee6a4SAndroid Build Coastguard Workersocket: arg0 == AF_UNIX
28*bb4ee6a4SAndroid Build Coastguard Workersocketpair: arg0 == AF_UNIX
29*bb4ee6a4SAndroid Build Coastguard Workerstatx: 1
30*bb4ee6a4SAndroid Build Coastguard Workerstat64: 1
31*bb4ee6a4SAndroid Build Coastguard Workerprctl: arg0 == PR_SET_NAME
32