# HWC allow surfaceflinger secmem_device:chr_file rw_file_perms; allow surfaceflinger sysfs:file { getattr open read };