1allow surfaceflinger self:process execmem;
2allow surfaceflinger ashmem_device:chr_file execute;
3allow surfaceflinger gpu_device:chr_file { ioctl open read write map };
4allow surfaceflinger self:vsock_socket create_socket_perms_no_ioctl;
5allow surfaceflinger hal_graphics_allocator_default:vsock_socket { read write getattr };
6