allow untrusted_app unlabeled:file getattr; allow untrusted_app efs_file:dir getattr; allow untrusted_app kernel:system module_request; allow untrusted_app log_device:dir search;