1 2 3
allow zygote input_device:dir r_dir_perms; allow zygote input_device:chr_file rw_file_perms; allow zygote self:capability sys_nice;