2017-02-09 15:15:11 -08:00
|
|
|
# bufferhubd
|
|
|
|
type bufferhubd, domain, mlstrustedsubject;
|
2018-09-27 10:21:37 -07:00
|
|
|
type bufferhubd_exec, system_file_type, exec_type, file_type;
|
2017-02-09 15:15:11 -08:00
|
|
|
|
2017-03-22 09:16:49 -07:00
|
|
|
hal_client_domain(bufferhubd, hal_graphics_allocator)
|
|
|
|
|
2018-09-17 17:06:19 -07:00
|
|
|
# TODO(b/112338294): remove these after migrate to Binder
|
2017-05-01 13:01:44 -07:00
|
|
|
pdx_server(bufferhubd, bufferhub_client)
|
|
|
|
pdx_client(bufferhubd, performance_client)
|
2017-02-09 15:15:11 -08:00
|
|
|
|
|
|
|
# Access the GPU.
|
|
|
|
allow bufferhubd gpu_device:chr_file rw_file_perms;
|
|
|
|
|
|
|
|
# Access /dev/ion
|
|
|
|
allow bufferhubd ion_device:chr_file r_file_perms;
|
2017-03-09 18:44:07 -08:00
|
|
|
|
2018-05-25 16:23:37 -07:00
|
|
|
# Receive sync fence FDs from hal_omx_server. Note that hal_omx_server never directly
|
2017-03-09 18:44:07 -08:00
|
|
|
# connects to bufferhubd via PDX. Instead, a VR app acts as a bridge between
|
2018-05-25 16:23:37 -07:00
|
|
|
# those two: it talks to hal_omx_server via Binder and talks to bufferhubd via PDX.
|
2017-05-01 13:01:44 -07:00
|
|
|
# Thus, there is no need to use pdx_client macro.
|
2018-05-25 16:23:37 -07:00
|
|
|
allow bufferhubd hal_omx_server:fd use;
|
2019-04-30 05:09:28 -07:00
|
|
|
|
|
|
|
# Codec2 is similar to OMX
|
|
|
|
allow bufferhubd hal_codec2_server:fd use;
|
|
|
|
|