type DR-daemon, domain; type DR-daemon_exec, exec_type, file_type; init_daemon_domain(DR-daemon) domain_trans(init, rootfs, DR-daemon) allow DR-daemon radio_data_file:sock_file unlink; allow DR-daemon self:capability setuid; allow DR-daemon serial_device:chr_file { read write ioctl open }; allow DR-daemon system_data_file:dir { write remove_name }; allow DR-daemon system_data_file:dir add_name; allow DR-daemon system_data_file:sock_file create;