module systemd-rfkill 1.0; require { type selinux_config_t; type systemd_rfkill_t; class capability net_admin; class dir search; } #============= systemd_rfkill_t ============== allow systemd_rfkill_t self:capability net_admin; allow systemd_rfkill_t selinux_config_t:dir search;