[PATCH] virt-aa-helper: Allow RO access to /usr/share/edk2-ovmf