@Jamie,
do you think we should whitelist /**/OVMF.Fd, whitelist /usr/share/qemu/**, or are you suggesting something different (in comments #16 and #8)?
@Jamie,
do you think we should whitelist /**/OVMF.Fd, whitelist /usr/share/qemu/**, or are you suggesting something different (in comments #16 and #8)?