OLD | NEW |
1 ;; | 1 ;; |
2 ;; Copyright (c) 2010 The Chromium Authors. All rights reserved. | 2 ;; Copyright (c) 2010 The Chromium Authors. All rights reserved. |
3 ;; Use of this source code is governed by a BSD-style license that can be | 3 ;; Use of this source code is governed by a BSD-style license that can be |
4 ;; found in the LICENSE file. | 4 ;; found in the LICENSE file. |
5 ;; | 5 ;; |
6 | 6 |
7 ; *** The contents of chrome/common/common.sb are implicitly included here. *** | 7 ; *** The contents of chrome/common/common.sb are implicitly included here. *** |
8 | 8 |
9 ; The GPU process opens a shared memory file to communicate with the renderer. | 9 ; The GPU process opens a shared memory file to communicate with the renderer. |
10 ; This is backed by a file in /var/folders. | 10 ; This is backed by a file in /var/folders. |
11 ; TODO(thakis): Let the browser allocated the pipe and hand the handles to | 11 ; TODO(thakis): Let the browser allocated the pipe and hand the handles to |
12 ; renderer and GPU process and remove this: http://crbug.com/65344 | 12 ; renderer and GPU process and remove this: http://crbug.com/65344 |
13 (allow file-read* file-write* (regex "^/(private/)?(tmp|var)(/|$)")) | 13 (allow file-read* file-write* (regex "^/(private/)?(tmp|var)(/|$)")) |
14 | 14 |
15 ; Allow communication between the GPU process and the UI server. | 15 ; Allow communication between the GPU process and the UI server. |
16 (allow mach-lookup (global-name "com.apple.tsm.uiserver")) | 16 (allow mach-lookup (global-name "com.apple.tsm.uiserver")) |
17 | 17 |
18 (allow file-read-metadata (literal "/")) | 18 (allow file-read-metadata (literal "/")) |
OLD | NEW |