summary refs log tree commit diff
path: root/seccomp
diff options
context:
space:
mode:
Diffstat (limited to 'seccomp')
-rw-r--r--seccomp/x86_64/vfio_device.policy10
1 files changed, 10 insertions, 0 deletions
diff --git a/seccomp/x86_64/vfio_device.policy b/seccomp/x86_64/vfio_device.policy
new file mode 100644
index 0000000..8dd5961
--- /dev/null
+++ b/seccomp/x86_64/vfio_device.policy
@@ -0,0 +1,10 @@
+# Copyright 2019 The Chromium OS Authors. All rights reserved.
+# Use of this source code is governed by a BSD-style license that can be
+# found in the LICENSE file.
+@include /usr/share/policy/crosvm/common_device.policy
+
+# VFIO_DEVICE_SET_IRQS, VFIO_IOMMU_MAP/UNMAP_DMA
+ioctl: arg1 == 0x3B6E || arg1 == 0x3B71 || arg1 == 0x3B72
+readlink: 1
+pread64: 1
+pwrite64: 1