1 allow tee tee_data_file:dir create_dir_perms; 2 allow tee self:capability { setuid setgid sys_rawio }; 3 allow tee block_device:dir search; 4 allow tee rpmb_block_device:blk_file rw_file_perms; 5