type init-insmod-sh, domain; type init-insmod-sh_exec, vendor_file_type, exec_type, file_type; init_daemon_domain(init-insmod-sh) allow init-insmod-sh self:capability sys_module; allow init-insmod-sh vendor_kernel_modules:system module_load; allow init-insmod-sh vendor_toolbox_exec:file execute_no_trans; allow init-insmod-sh self:capability sys_nice; allow init-insmod-sh kernel:process setsched; set_prop(init-insmod-sh, vendor_device_prop) dontaudit init-insmod-sh proc_cmdline:file r_file_perms; allow init-insmod-sh debugfs_mgm:dir search; allow init-insmod-sh vendor_regmap_debugfs:dir search;