2017-02-10 00:15:11 +01:00
|
|
|
# bufferhubd
|
|
|
|
type bufferhubd, domain, mlstrustedsubject;
|
|
|
|
type bufferhubd_exec, exec_type, file_type;
|
|
|
|
|
2017-03-22 17:16:49 +01:00
|
|
|
hal_client_domain(bufferhubd, hal_graphics_allocator)
|
|
|
|
|
2017-02-10 00:15:11 +01:00
|
|
|
pdx_server(bufferhubd)
|
|
|
|
use_pdx(bufferhubd, performanced)
|
|
|
|
|
|
|
|
# Access the GPU.
|
|
|
|
allow bufferhubd gpu_device:chr_file rw_file_perms;
|
|
|
|
|
|
|
|
# Access /dev/ion
|
|
|
|
allow bufferhubd ion_device:chr_file r_file_perms;
|
2017-03-10 03:44:07 +01:00
|
|
|
|
|
|
|
# Receive sync fence FDs from mediacodec. Note that mediacodec never directly
|
|
|
|
# connects to bufferhubd via PDX. Instead, a VR app acts as a bridge between
|
|
|
|
# those two: it talks to mediacodec via Binder and talks to bufferhubd via PDX.
|
|
|
|
# Thus, there is no need to use use_pdx macro.
|
|
|
|
allow bufferhubd mediacodec:fd use;
|